Babuk is a ransomware family that became especially influential after its 2021 source-code leak, which enabled widespread reuse by other criminal operators and ransomware-as-a-service affiliates. It has been used directly in attacks and has also served as the code base for numerous derivative strains targeting enterprise environments. Babuk is associated with file encryption for impact and has been observed in Windows, Linux, ESXi, NAS, and other Linux-based storage contexts through both original and descendant implementations. The family is notable for accelerating the proliferation of cross-platform ransomware, particularly ESXi-focused lockers, by lowering the technical barrier for actors seeking to build or adapt Linux and hypervisor encryptors.
Documented Babuk behavior includes deleting shadow copies to inhibit recovery and stopping antivirus services on compromised Windows hosts. Babuk has also been linked to DLL sideloading, including abuse of a legitimate Windows debugger to deliver ransomware. Reporting further ties Babuk to attacks against virtualized infrastructure and NAS devices, and multiple later ransomware families and campaigns have been described as Babuk-derived or built from leaked Babuk code. Public reporting and law-enforcement actions have also connected Babuk deployments to financially motivated ransomware actors and affiliates, including operators involved in broader ransomware ecosystems.
Because the leaked code has been extensively repurposed, Babuk attribution now requires caution: many modern samples identified as Babuk are better understood as derivatives rather than activity by the original operators. Even so, Babuk remains a significant ransomware lineage due to its direct operational use, its role in double-extortion ecosystems through descendants, and its enduring impact on ransomware development across Windows and Linux virtualization targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The version of Velociraptor observed in this incident was outdated (version 0.73.4.0) and exposed to a privilege escalation vulnerability (CVE-2025-6264), which may have been leveraged for persistence as this vulnerability can lead to arbitrary command execution and endpoint takeover.
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
...threat actors have been observed weaponizing a vulnerable version of Bitrix for initial access, followed by using the Zerologon flaw to escalate privileges.
21 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Talos IR responded to Warlock, Babuk and Kraken ransomware variants for the first time... Notably, we also observed evidence of Babuk ransomware files on the customer’s network in this engagement, which has not been previously deployed by Storm-2603 according to public reporting, though it failed to encrypt and only renamed files.
As in previous attacks, they encrypted data using variants of LockBit 3.0 (for Windows systems) and Babuk (for NAS devices).
As the final payload, the group used the well-known ransomware LockBit 3.0 and Babuk.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat actors predominately exploited public-facing applications for initial access this quarter... Almost 40 percent of all engagements involved ToolShell activity... attackers began actively exploiting two path traversal vulnerabilities affecting on-premises SharePoint servers... resulting in unauthenticated remote code execution.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
... разработчики The Gentlemen систематически реверсят семплы Babuk, Qilin, LockBit 5.0 и Medusa, вытаскивая ... техники обфускации (T1027) ...
Distribution Vector: Frequently encountered masquerading as a setup or launcher for pirated games (such as Grand Theft Auto or Left 4 Dead), distributed via torrent and download sites.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Multiple entries describe enumerating local, logical, or physical drives and disk/volume information, e.g., 'can enumerate local drives,' 'GetLogicalDrives,' 'fsutil fsinfo drives,' 'list drives,' and 'discover logical drive information including the drive type, free space, and volume information.'
The police documents were stolen and published by the ransomware attack group Babuk...
The final payload appends the .KRYBIT extension to encrypted files (mapped to Data Encrypted for Impact, T1486) and drops a ransom note named RECOVER-README.txt
Examples include Babuk 'can stop anti-virus services', BOLDMOVE disabling daemons, Conficker terminating services, Lazarus malware disabling Windows services, and SolarWinds Compromise where APT29 'used the service control manager on a remote system to disable services associated with security monitoring products.'
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
The content repeatedly describes threat actors and malware disabling, stopping, uninstalling, or modifying antivirus, EDR, Windows Defender, AMSI, logging, and other security controls.
Examples include 'Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools', 'BlackByte disabled security tools such as Windows Defender', 'Scattered Spider has uninstalled and disabled security tools', and many malware families terminating AV/EDR processes or services.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
99 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family whose leaked source code is described as the basis for Krybit derivatives.
A ransomware family whose leaked source code is described as the basis for Krybit-derived samples.
Referenced as the ransomware family to which Se7en belongs.
Referenced as a ransomware family whose samples were reverse engineered by The Gentlemen developers to extract encryption routines, obfuscation techniques, and EDR evasion methods.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.