Skip to main content
Mallory
MalwareRansomwareUsed by 17 actorsExploits 3 CVEs

Babuk

Also known asBabykVasa Locker

Babuk, also referred to as Babyk and Babuk Locker, is a ransomware family and ransomware-as-a-service operation that emerged at the beginning of 2021. It targeted businesses in double-extortion attacks, combining file encryption with threats to leak stolen data, and was also cited as an early adopter of encryption-less extortion-only attacks. Babuk is known to target Windows systems, and leaked Babuk materials included Windows, VMware ESXi, and NAS encryptors. Reported capabilities include stopping antivirus services on compromised hosts and deleting shadow volumes using the command "vssadmin.exe delete shadows /all /quiet" to inhibit recovery. Babuk gained significant attention after the April 2021 attack on the Washington, D.C. Metropolitan Police Department, in which stolen police documents were later published online. The operation announced an affiliate program around late December 2020 and early January 2021. In September 2021, Babuk’s source code was leaked, including ESXi, NAS, and Windows encryptors and some victim-specific decryptors. That leak enabled extensive reuse by other threat actors and led to numerous derivative ransomware families and ESXi/Linux encryptors, complicating attribution. Content also links Babuk activity and development/deployment to Russian national Mikhail Pavlovich Matveev in U.S. law-enforcement reporting, and separate reporting ties Babuk personas and infrastructure to aliases including Boriselcin and Orange in the broader ransomware ecosystem.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

3 CVES
CVE-2025-6264Privilege escalation in Rapid7 Velociraptor Admin.Client.UpdateClientConfig artifactExploited in the wild

CVE‑2025‑6264 — Rapid7 Velociraptor Remote Code Execution... Exploitation Status: Actively exploited in ransomware campaigns.

via cyberthronethecyberthrone.in
CVE-2024-37085VMware ESXi Active Directory Integration Authentication Bypass

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

via microsoft security blogmicrosoft.com
CVE-2020-1472ZerologonExploited in the wild

...threat actors have been observed weaponizing a vulnerable version of Bitrix for initial access, followed by using the Zerologon flaw to escalate privileges.

via the hacker newsthehackernews.com
THREAT ACTORS

Groups observed using it

17 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Conti

Authorities say Matveev played a major role in the development and deployment of the Hive, LockBit and Babuk ransomware variants...

via techcrunch com securitytechcrunch.com
Boriselcin

On Dec. 31, 2020, they announced the creation of the Babuk ransomware affiliate program... On January 1, 2021, a new user “Babuk” registered on the crime forum Verified... “We run an affiliate program,” Babuk explained in their introductory post on Verified.

via krebs on securitykrebsonsecurity.com
Wazawaka

On Dec. 31, 2020, they announced the creation of the Babuk ransomware affiliate program... On January 1, 2021, a new user “Babuk” registered on the crime forum Verified... “We run an affiliate program,” Babuk explained in their introductory post on Verified.

via krebs on securitykrebsonsecurity.com
Orange

On Dec. 31, 2020, they announced the creation of the Babuk ransomware affiliate program... On January 1, 2021, a new user “Babuk” registered on the crime forum Verified... “We run an affiliate program,” Babuk explained in their introductory post on Verified.

via krebs on securitykrebsonsecurity.com
Storm-2603

Storm-2603 (Gold Salem) deployed ransomware, including Warlock, LockBit, and Babuk, targeting multiple sectors across agriculture, government, energy and natural resources, and telecommunications in the LAC and Asia-Pacific (APAC) regions.

via recorded future blogrecordedfuture.com
Bearlyfy

The hacking group was first documented by F6 in September 2025 as leveraging encryptors associated with LockBit 3 (Black) and Babuk.

via the hacker newsthehackernews.com
Warlock

Warlock has employed multiple different encryptors over time, ranging from custom ones to variants based on Babyk...

via eset welivesecurity blogwelivesecurity.com
warlock_group

The Warlock Group (aka Storm-2603) is a ransomware gang attributed to Chinese threat actors who utilize the leaked LockBit Windows and Babuk VMware ESXi encryptors in attacks.

via bleeping computerbleepingcomputer.com
Crypt Ghouls

"On Linux systems, Crypt Ghouls deploys Babuk, a ransomware strain designed to target ESXi servers..."

via security online infosecurityonline.info
Storm-1175

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

via microsoft security blogmicrosoft.com
Storm-0506

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

via microsoft security blogmicrosoft.com
Scattered Spider

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

via microsoft security blogmicrosoft.com
Bl00Dy

...used open-source and leaked builders from other operators, including LockBit, Babuk and Conti.

via cyjax blogcyjax.com
Indrik Spider

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

via microsoft security blogmicrosoft.com
RansomHouse

"The ransomware shares code with Babuk... Given Babuk’s source code leak..."

via trellix blogtrellix.com
ExCobalt

Lockers such as Babuk and LockBit.

via the hacker newsthehackernews.com
Cinnamon Tempest

...deploying multiple strains of ransomware based on the leaked Babuk source code.

via mitre attack websiteattack.mitre.org
MITRE ATT&CK

Techniques & procedures

21 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1078Valid AccountsEvidence1

...threat actors leveraging a contractor's login credentials to connect to the internal systems via VPN... weaponizing trusted relationships.

T1190Exploit Public-Facing ApplicationEvidence1

Last month, Microsoft reported that the threat actors were exploiting a SharePoint vulnerability to breach corporate networks and deploy ransomware.

Execution

1 technique
T1059.003Windows Command ShellEvidence2
TacticExecution

During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.

Persistence

1 technique
T1078Valid AccountsEvidence1

...threat actors leveraging a contractor's login credentials to connect to the internal systems via VPN... weaponizing trusted relationships.

T1078Valid AccountsEvidence1

...threat actors leveraging a contractor's login credentials to connect to the internal systems via VPN... weaponizing trusted relationships.

Stealth

5 techniques
T1027.002Software PackingEvidence1
TacticStealth

"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."

T1036MasqueradingEvidence1
TacticStealth

The deception is deliberate, designed to mislead victims and possibly even seasoned investigators into misidentifying the actual threat actor behind the attack.

T1078Valid AccountsEvidence1

...threat actors leveraging a contractor's login credentials to connect to the internal systems via VPN... weaponizing trusted relationships.

T1140Deobfuscate/Decode Files or InformationEvidence3
TacticStealth

The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'

T1497.001System ChecksEvidence1

...create Linux encryptors targeting VMware ESXi servers.

Discovery

6 techniques
T1007System Service DiscoveryEvidence2
TacticDiscovery

"actors used the following command ... to obtain information about services: net start"; "APT1 used the commands net start and tasklist to get a listing of the services on the system"; "OilRig has used sc query on a victim to gather information about services"; "Indrik Spider has used the win32_service WMI class to retrieve a list of services"

T1057Process DiscoveryEvidence2
TacticDiscovery

The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.

T1082System Information DiscoveryEvidence3
TacticDiscovery

"4H RAT sends an OS version identifier in its beacons"; "admin@338 actors used ... ver ... systeminfo"; "Bundlore will enumerate the macOS version ... using /usr/bin/sw_vers -productVersion"; "DarkTortilla ... querying ... WMI objects"; "Turla ... discover operating system configuration details using the systeminfo and set commands"

T1083File and Directory DiscoveryEvidence2
TacticDiscovery

“3PARA RAT has a command to retrieve metadata for files on disk as well as a command to list the current working directory… admin@338 actors used… dir c:\ >> %temp%\download … APT28 has used Forfiles to locate PDF, Excel, and Word documents…”

T1120Peripheral Device DiscoveryEvidence1
TacticDiscovery

"Babuk can enumerate disk volumes, get disk information"; "Ryuk has called GetLogicalDrives ... and GetDriveTypeW"; "Cuba can enumerate local drives, disk type, and disk free space"; "Chimera ... fsutil fsinfo drives"

T1497.001System ChecksEvidence1

...create Linux encryptors targeting VMware ESXi servers.

Exfiltration

3 techniques
T1048Exfiltration Over Alternative ProtocolEvidence1

The police documents were stolen and published by the ransomware attack group Babuk...

T1537Transfer Data to Cloud AccountEvidence2

The hackers from the Babuk group subsequently published those documents online, and transparency group Distributed Denial of Secrets redistributed them to news outlets including the Guardian.

T1567Exfiltration Over Web ServiceEvidence1

The Babuk (aka Babyk and Babuk Locker) ransomware operation surfaced at the beginning of 2021 by targeting businesses in double-extortion attacks.

Impact

4 techniques
T1486Data Encrypted for ImpactEvidence17
TacticImpact

EndPoint는 Windows 환경뿐 아니라 ESXi와 NAS 환경도 겨냥하며, 파일 암호화와 데이터 유출 협박을 함께 수행하는 Double Extortion 방식을 사용한다.

T1489Service StopEvidence1
TacticImpact

Examples include Babuk 'can stop anti-virus services', BOLDMOVE disabling daemons, Conficker terminating services, Lazarus malware disabling Windows services, and SolarWinds Compromise where APT29 'used the service control manager on a remote system to disable services associated with security monitoring products.'

T1490Inhibit System RecoveryEvidence2
TacticImpact

Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.

T1657Financial TheftEvidence3
TacticImpact

The group claimed to have stolen over 250 GB of data from police servers and threatened to expose the information if the department didn’t pay a ransom.

Other

2 techniques
T1562Impair DefensesEvidence2

The content repeatedly describes threat actors and malware disabling, stopping, uninstalling, or modifying antivirus, EDR, Windows Defender, AMSI, logging, and other security controls.

T1562.001Disable or Modify ToolsEvidence1

Examples include 'Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools', 'BlackByte disabled security tools such as Windows Defender', 'Scattered Spider has uninstalled and disabled security tools', and many malware families terminating AV/EDR processes or services.

INDICATORS OF COMPROMISE

IOCs tracked for this family

4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
4 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.md5●●●●●●●●●●●●View more in app3 days ago
hash.md5●●●●●●●●●●●●View more in app3 days ago
hash.md5●●●●●●●●●●●●View more in app3 days ago
hash.md5●●●●●●●●●●●●View more in app3 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching4

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution17

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities3

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping21

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.