Babuk Locker is a human-operated ransomware family that emerged in early 2021 and targeted corporate victims worldwide. It is associated with double-extortion operations in which attackers steal sensitive data before encrypting systems and then threaten public release of the stolen information to coerce payment. The group became particularly notable for high-profile enterprise intrusions and for later announcing a shift away from encryption toward pure data-theft and extortion activity. Babuk-related operators also maintained leak infrastructure used to expose victim data and, at one stage, offered hosting for other criminal groups’ stolen files.
Babuk Locker is known for ransomware capabilities affecting Windows environments and virtualized infrastructure, including VMware ESXi. Reporting also indicates builder support for NAS architectures in both x86 and ARM variants. The malware was notable for encrypting files on ESXi-hosted virtual disk environments, a capability that increased its impact against enterprise virtualization estates. Contemporary analysis assessed its cryptography as sufficiently strong to make free decryption impractical when properly deployed.
The family gained additional significance after its builder leaked publicly, lowering the barrier for other threat actors to generate customized Babuk-derived ransomware and decrypters. Subsequent campaigns used Babuk-themed variants distinct from the original operation, and third-party reporting has linked later ransomware activity, including Daixin Team operations, to leaked Babuk source code. Babuk Locker therefore occupies an important place in the ransomware ecosystem both as an active extortion operation and as a codebase that enabled follow-on threats.
Victimology centered on enterprises and other organizational targets rather than commodity consumer infections. Observed impacts included encryption of business systems, theft of sensitive internal data, and extortion pressure through threatened publication. Babuk Locker is also associated with deceptive extortion behavior in later reporting, including questionable or recycled leak claims, underscoring its role in the broader evolution of ransomware-driven data extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
According to third-party reporting, the Daixin Team’s ransomware is based on leaked Babuk Locker source code.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
If companies don't want to pay to have their data returned, the group says it will list it on their site, just like it did until now, exposing the victim's sensitive documents.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family mentioned in connection with a leak site used to release stolen victim data.
Ransomware operation noted for deceptive extortion tactics, including unsubstantiated breach claims and recycling outdated/falsified leak data to pressure victims.
Human-operated ransomware targeting corporate victims. The content says it uses ChaCha8/SHA256 and ECDH-based key protection to encrypt files and make free decryption impractical.
Ransomware family/operation whose leaked builder allows attackers to generate customized encryptors and decryptors targeting Windows, VMware ESXi, NAS x86, and NAS ARM devices. The new campaign appends the .babyk extension and drops a ransom note named 'How To Restore Your Files.txt'.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.