Babuk is a ransomware family that became especially influential after its source code leaked in 2021, enabling widespread reuse and adaptation by other financially motivated threat actors and ransomware-as-a-service operations. It is associated with file encryption for impact and has been used directly by some operators while also serving as the code base for numerous derivative strains targeting enterprise environments.
Babuk has been deployed against Windows systems and also against Linux-based targets, particularly VMware ESXi and NAS environments. Reporting on Babuk and Babuk-derived variants shows a strong focus on virtualization infrastructure, where operators stop virtual machines and encrypt hypervisor-hosted data to maximize operational disruption. The leaked code materially lowered the barrier to entry for Linux and ESXi ransomware development, and multiple later ransomware families have been assessed as Babuk-derived or partially reverse-engineered from Babuk components.
Observed tradecraft linked to Babuk includes defense evasion through DLL sideloading, including abuse of legitimate Windows components to load ransomware payloads. Babuk has also appeared as a third-party encryptor used by intrusion and extortion groups rather than as a uniquely attributable closed ecosystem. Because many later strains reuse Babuk code, lineage-based attribution is often difficult, and detections labeled as Babuk may in some cases reflect derivatives rather than the original family.
Babuk is best understood both as a ransomware family in its own right and as a foundational code lineage that has shaped a large portion of subsequent cross-platform ransomware activity, especially in ESXi-focused campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The version of Velociraptor observed in this incident was outdated (version 0.73.4.0) and exposed to a privilege escalation vulnerability (CVE-2025-6264), which may have been leveraged for persistence as this vulnerability can lead to arbitrary command execution and endpoint takeover.
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
...threat actors have been observed weaponizing a vulnerable version of Bitrix for initial access, followed by using the Zerologon flaw to escalate privileges.
22 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ce groupe utilisait auparavant des ransomwares tiers (RedAlert, LockBit, Babuk).
Talos IR responded to Warlock, Babuk and Kraken ransomware variants for the first time... Notably, we also observed evidence of Babuk ransomware files on the customer’s network in this engagement, which has not been previously deployed by Storm-2603 according to public reporting, though it failed to encrypt and only renamed files.
As in previous attacks, they encrypted data using variants of LockBit 3.0 (for Windows systems) and Babuk (for NAS devices).
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat actors predominately exploited public-facing applications for initial access this quarter... Almost 40 percent of all engagements involved ToolShell activity... attackers began actively exploiting two path traversal vulnerabilities affecting on-premises SharePoint servers... resulting in unauthenticated remote code execution.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
... разработчики The Gentlemen систематически реверсят семплы Babuk, Qilin, LockBit 5.0 и Medusa, вытаскивая ... техники обфускации (T1027) ...
Distribution Vector: Frequently encountered masquerading as a setup or launcher for pirated games (such as Grand Theft Auto or Left 4 Dead), distributed via torrent and download sites.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Multiple entries describe enumerating local, logical, or physical drives and disk/volume information, e.g., 'can enumerate local drives,' 'GetLogicalDrives,' 'fsutil fsinfo drives,' 'list drives,' and 'discover logical drive information including the drive type, free space, and volume information.'
The police documents were stolen and published by the ransomware attack group Babuk...
The final payload appends the .KRYBIT extension to encrypted files (mapped to Data Encrypted for Impact, T1486) and drops a ransom note named RECOVER-README.txt
Examples include Babuk 'can stop anti-virus services', BOLDMOVE disabling daemons, Conficker terminating services, Lazarus malware disabling Windows services, and SolarWinds Compromise where APT29 'used the service control manager on a remote system to disable services associated with security monitoring products.'
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
The content repeatedly describes threat actors and malware disabling, stopping, uninstalling, or modifying antivirus, EDR, Windows Defender, AMSI, logging, and other security controls.
Examples include 'Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools', 'BlackByte disabled security tools such as Windows Defender', 'Scattered Spider has uninstalled and disabled security tools', and many malware families terminating AV/EDR processes or services.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
104 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously used third-party ransomware family referenced as part of Toy Ghouls' tooling history before developing GenieLocker.
Previously used third-party ransomware mentioned as background context for Toy Ghouls.
Previously used by Toy Ghouls before the group transitioned to GenieLocker.
Previously used third-party ransomware family mentioned as background context for Toy Ghouls operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.