Babuk is a ransomware family first identified in January 2021 following attacks against large enterprises. The Babuk operation targeted organizations in sectors including manufacturing, transportation, construction, materials, and legal services. Its encryptors were built for Windows, VMware ESXi, and network-attached-storage environments, enabling impact against endpoints, servers, and virtualized infrastructure. Babuk encrypts victim data in parallel, creates ransom notes, terminates processes that may obstruct encryption, deletes Volume Shadow Copies, stops VSS-related activity, and clears the Recycle Bin to hinder recovery. It can enumerate running processes and network shares. Babuk source code was leaked in 2021 and has subsequently been reused in ransomware builders and derivative ESXi-focused encryptors deployed by multiple unrelated actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In at least one case, the campaign has led to the deployment of a Babuk-derived ransomware.
QUIRSO have since mapped a sprawling global campaign that compromised 361 unique IP addresses across 47 countries, culminating in the deployment of Babuk-derived ransomware directly onto ESXi hypervisors.
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | A Hive ransomware affiliate has been targeting Microsoft Exchange servers vulnerable to ProxyShell security issues... ProxyShell is a set of three vulnerabilities in the Microsoft Exchange Server that allow remote code execution without authentication on vulnerable deployments. The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | The flaws have been used by multiple threat actors, including ransomware like Conti, BlackByte, Babuk, Cuba, and LockFile, after exploits became available.
The initial downloader is a modified EfsPotato exploit to target proxyshell and PetitPotam vulnerabilities. | EfsPotato is an exploit that attempts to escalate the process privileges using a vulnerability in the Encrypted File System (CVE-2021-36942). | Cisco Talos recently discovered a malicious campaign deploying variants of the Babuk ransomware predominantly affecting users in the U.S.
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | The flaws have been used by multiple threat actors, including ransomware like Conti, BlackByte, Babuk, Cuba, and LockFile, after exploits became available.
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | The flaws have been used by multiple threat actors, including ransomware like Conti, BlackByte, Babuk, Cuba, and LockFile, after exploits became available.
According to a Coveware report, Babuk ransomware is also targeting SonicWall VPNs likely vulnerable to CVE-2020-5135 exploits. This vulnerability was patched in October 2020 but it is still "heavily abused by ransomware groups today" per Coveware. | According to a Coveware report, Babuk ransomware is also targeting SonicWall VPNs likely vulnerable to CVE-2020-5135 exploits.
The version of Velociraptor observed in this incident was outdated (version 0.73.4.0) and exposed to a privilege escalation vulnerability (CVE-2025-6264), which may have been leveraged for persistence as this vulnerability can lead to arbitrary command execution and endpoint takeover.
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
...threat actors have been observed weaponizing a vulnerable version of Bitrix for initial access, followed by using the Zerologon flaw to escalate privileges.
26 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attackers initially relied exclusively on tools pulled from public GitHub repositories along with leaked Babuk and LockBit ransomware builders.
As of February 8, further analysis could indicate the malware might be a variant of the Babuk ransomware. Babuk source code was leaked in 2021 and utilized in previous ESXi ransomware attacks.
Head Mare is a hacktivist group that targets Russian and Belarusian organizations; the group has been active since at least 2023 and has previously used LockBit and Babuk ransomware to encrypt victims’ systems, according to Kaspersky.
Indictments returned in New Jersey and the District of Columbia allege that Matveev was involved in a conspiracy to distribute ransomware from three different strains or affiliate groups, including Babuk, Hive and LockBit.
Babuk Ransomware v3 Overview This is a short report for the latest Babuk ransomware sample. This sample is marked as version 3 based on the run-once mutex string.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
Scheduled jobs downloaded tools, ran shell commands and used temporary folders for staging.
Its purpose is to delete the ransom Note “ How to Restore Your Files.txt ” ... it deletes using the “ DeleteFileW ” the file
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
Babuk and Rook use EnumDependentServicesA API to retrieve the name and status of each service that depends on the specified service before terminating. They enumerate all services in the system and stop all of those which exist in a hardcoded list in the malware.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
After inventory discovery, the attackers created local administrator accounts on ESXi hosts
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
APT1 listed connected network shares. APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$. APT41 used the net share command as part of network reconnaissance.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
The helper script stopped running virtual machines, launched the encryptor against VMFS volumes... The payload used a Babuk-derived encryptor
The helper script stopped running virtual machines... and removed the VMware high-availability agent.
114 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
180 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family whose leaked builder was used by Toy Ghouls in earlier activity.
Ransomware whose leaked builder was previously used by Toy Ghouls.
Widely available ransomware mentioned as software that some pro-Ukrainian groups have stopped using in favor of custom malware.
Ransomware previously used by Head Mare in earlier operations to encrypt victim systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.