Babuk

MITRE ATT&CK: S0638 View on attack.mitre.org

Aliases: Babyk, Vasa Locker, Babuk

First seen
2021-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows, linux
Related IoCs
58 (58 malicious)
Last IoC activity
2026-08-23 09:50:00
Profile updated
2026-07-07 13:43:44

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications

Context

Babuk is a Ransomware-as-a-service (RaaS) malware that has been used since at least 2021. The operators of Babuk employ a "Big Game Hunting" approach to targeting major enterprises and operate a leak site to post stolen data as part of their extortion scheme.

Recent IoC activity

58 malicious indicators in Maltiverse are attributed to Babuk (S0638). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 2026-08-22_3a4d630b5c774a3057bfd2fff3068811_babuk_destroyer_elex 2026-08-23 1
file sample 2026-08-21_29fecce202dd89b5d1a5789a6913cae5_babuk_destroyer_elex 2026-08-22 1
file sample allah.7z 2026-08-22 1
file sample e_win.exe 2026-08-22 1
file sample 2026-08-21_643e8db8b8a5c7812491731dbfc7f9f9_babuk_destroyer_elex 2026-08-22 1
file sample 2026-08-21_717b0fde35bf26d2115561de89dd1eaa_babuk_destroyer_elex 2026-08-22 1
file sample 2026-08-21_84554c197bbe2f11cb0b913ec27b3c54_babuk_destroyer_elex 2026-08-22 1
file sample 2026-08-21_90b442d47bba0a051be9d9e463c2e6bf_babuk_destroyer_elex 2026-08-22 1
file sample 2026-08-21_32dbacbf50faa12cb0962cb389f6e5d4_babuk_destroyer_elex 2026-08-21 1
file sample 2026-08-21_8f6725ad92dc028a7bca0b1a64a9eba7_babuk_destroyer_elex 2026-08-21 1
file sample 2026-08-19_6149930099f1aba1e117568002bf7335_akira_cobalt-strike_icedid_rusty-... 2026-08-20 1
file sample 2026-08-14_21dcc56d58f5aec984afb38a076d3512_destroyer_elex 2026-08-14 1
file sample e_win.exe 2026-08-12 2
file sample 7e9e5142b18ae0f1d89fb0a4b36617b1798a9cc7ab392808d426aedf63dd593b 2026-08-12 1
file sample a7e2b2d70830a390d7a7e356c975089c0a26a0f6cc0d18f3c50915feb250a28d 2026-08-12 1
file sample e_win.exe 2026-07-29 1
file sample sub_8203c2f00ecd.bin 2026-07-29 3
file sample 2025-04-21_c2f7a0d4773f939dc37bc0d911b4a408_babuk_destroyer_elex 2026-07-27 2
file sample e_win.exe 2026-07-19 2
file sample 393a7a313548a4edc025fb47c6c8e614ecc2b41db880ecb59f20cf238e9a864c.bin 2026-07-15 2

Detection coverage

  • 5 YARA rules
  • 307 Sigma rules

Malware & tools used

  • Disable or Modify Tools (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Native API (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Software Packing (attack-pattern)
  • Service Stop (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)

Detection rules

  • MALPEDIA_Elf_Babuk_Auto (yara-rule)
  • MALPEDIA_Win_Babuk_Auto (yara-rule)
  • TRELLIX_ARC_Ransom_Babuk (yara-rule)
  • TRELLIX_ARC_RANSOM_Babuk_Packed_Feb2021 (yara-rule)
  • ARKBIRD_SOLG_RAN_Piton_Nov_2021_1 (yara-rule)

Reports & references

  • CrowdStrike — Big Game Hunting On The Rise Again According To Ecrime Index (report)
  • docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
  • krebsonsecurity.com — Ransomware Gangs And The Name Game Distraction (report)
  • medium.com — W4 May En Story Of The Week Ransomware On The Darkweb 5F5B8D4C3B6F (report)
  • Kaspersky — 102169 (report)
  • Broadcom/Symantec — The Ransomware Threat September 2021 (report)
  • vulnerability.ch — Ransomware And Date Leak Site Publication Time Analysis (report)
  • splunk.com — Gone In 52 Seconds And 42 Minutes A Comparative Analysis Of Ransomware Encryption Speed (report)
  • splunk.com — An Empirically Comparative Analysis Of Ransomware Binaries (report)
  • killingthebear.jorgetesta.tech — Evil Corp (report)
  • bleepingcomputer.com — New Evil Corp Ransomware Mimics Payloadbin Gang To Evade Us Sanctions (report)
  • bleepingcomputer.com — Data Leak Marketplaces Aim To Take Over The Extortion Economy (report)
  • medium.com — W4 Jan En Story Of The Week Ransomware On The Darkweb 7595544363B1 (report)
  • medium.com — Blackmatter X Babuk Using The Same Web Server For Sharing Leaked Files D01C20A74751 (report)
  • medium.com — Groove X Ramp The Relation Between Groove Babuk Ramp And Blackmatter F75644F8F92D (report)
  • medium.com — Grooves Thoughts On Blackmatter Babuk And Interruption In The Supply Of Cheese In The B5328Bc764F2 (report)
  • McAfee — How Groove Gang Is Shaking Up The Ransomware As A Service Market To Empower Affiliates (report)
  • raw.githubusercontent.com — Insomnihack 2022 Ransomware Encryption Internals (report)
  • medium.com — W1 Jun En Story Of The Week Ransomware On The Darkweb Af491D33868B (report)
  • McAfee — Are Virtual Machines The New Gold For Cyber Criminals (report)
  • bleepingcomputer.com — Microsoft Exchange Servers Hacked To Deploy Hive Ransomware (report)
  • databreaches.net — Babuk Re Organizes As Payload Bin Offers Its First Leak (report)
  • bleepingcomputer.com — Leaked Babuk Locker Ransomware Builder Used In New Attacks (report)
  • advintel.io — Groove Vs Babuk Groove Ransom Manifesto Ramp Underground Platform Secret Inner Workings (report)
  • krebsonsecurity.com — Russian Hacker Wazawaka Indicted For Ransomware (report)

External references