Babuk-Locker

First seen
2021-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:48:48

Targeted industries: healthcare-and-pharmaceutical technology-and-telecommunications financial-services education-and-nonprofits government-and-public-sector

Context

Babuk‑Locker emerged in early 2021 as a Ransomware‑as‑a‑Service (RaaS) gang targeting high‑value “big game” enterprises across sectors like healthcare, telecommunications, finance, education, and government. It initially deployed crypto-ransomware—encrypting files using ChaCha8 encryption with keys secured via elliptic‑curve Diffie‑Hellman—and later added a double‑extortion model involving data theft and leak site threats. Notable incidents include attacks on the Washington, D.C. Metropolitan Police Department and other organizations. In mid‑2021, Babuk’s source code was leaked, prompting both a fragmentation of its core operations and emergence of variants like Babuk Tortilla and Babuk V2. Affiliates exploited vulnerabilities in ESXi hypervisors to deliver destructive variants, and law enforcement actions eventually disrupted key operators.

Related threat objects

Reports & references

  • bleepingcomputer.com — Leaked Babuk Locker Ransomware Builder Used In New Attacks (report)
  • bleepingcomputer.com — Babuk Ransomwares Full Source Code Leaked On Hacker Forum (report)
  • blog.cyberint.com — Babuk Locker (report)
  • ransomlook.io — Babuk Locker (report)

External references