Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Affiliates are individuals or groups that collaborate with RaaS operators to perform actions such as initial penetration, network lateral movement, data exfiltration, and ransomware distribution.
"As the investigation continues, university technicians are working to determine the scope of the security breach before restoring data from backups. It’s also unclear whether the backups contain all data or if some remains inaccessible after ransomware encryption."
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware noted for using DLL side-loading and updated with additional features such as decrypting its configuration file.
A ransomware family noted as descended from the leaked Babuk ESXi source code.
Ransomware referenced among new ESXi-targeting strains reportedly leveraging/deriving from leaked Babuk code.
A ransomware family/variant identified as leveraging leaked Babuk code for ESXi encryptors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.