Babuk Ransomsware

First seen
2021-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:46:52

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications

Context

Since this is the first detection of this malware in the wild, it’s not surprising that Babuk is not obsfuscated at all. Overall, it’s a pretty standard ransomware that utilizes some of the new techniques we see such as multi-threading encryption as well as abusing the Windows Restart Manager similar to Conti and REvil. For encrypting scheme, Babuk uses its own implementation of SHA256 hashing, ChaCha8 encryption, and Elliptic-curve Diffie–Hellman (ECDH) key generation and exchange algorithm to protect its keys and encrypt files. Like many ransomware that came before, it also has the ability to spread its encryption through enumerating the available network resources.

Related threat objects

Reports & references

  • chuongdong.com — Babukransomware (report)

External references