Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Babuk

Babuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most used compiled versions, but ESX and a 32bit old PE executable were observed over time. as well It uses an Elliptic Curve Algorithm (Montgomery Algorithm) to build the encryption keys.

Victims
8
 
First Discovered
2020-10-25
victim
Last Discovered
2023-07-31
victim
Inactive Since
2yrs
more than
Avg Delay
757.8
days
Infostealer
33.3%
victims with domain
Countries
3
hit
View Victims on World Map View Group Statistics

Known Locations (1)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Babuk - Leaks site No 2026-04-28T07:22:42 nq4zyac4ukl4tykmidbzgdlvaboqeqsemkp4t35bzvjeve6zm2lqcjid.onion

Target
Top 5 Activity Sectors
  • Business Services 2
  • Construction 1
  • Transportation/Logistics 1
  • Consumer Services 1
  • Hospitality and Tourism 1
Top 5 Countries
  • US flag United States 3
  • FR flag France 1
  • GB flag United Kingdom 1

Heatmap

Tools Used
This information is provided by Ransomware-Tool-Matrix
Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
File[.]io

Negotiation Chats (2)
20210203 106 msgs
20210428 44 msgs

YARA Rules (1)

Victims (8)
Logo
Discovered: 2023-07-31 (2y ago)  ·  Attack est.: 2021-06-15
The Babuk v2.0 new…
Logo
Discovered: 2023-07-31 (2y ago)  ·  Attack est.: 2021-06-21
The Babuk 2.0 new…
Logo
Discovered: 2023-07-31 (2y ago)  ·  Attack est.: 2021-07-07
The Babuk v2.0 new…
Logo
Discovered: 2023-07-31 (2y ago)  ·  Attack est.: 2021-07-06
The Babuk 2.0new…
Logo
Discovered: 2023-07-31 (2y ago)  ·  Attack est.: 2021-07-27
https://www.bridgemillathleticclub.com…
Logo
Discovered: 2021-04-01 (5y ago)
No description available
Logo
Discovered: 2021-04-01 (5y ago)
No description available
Logo
Discovered: 2020-10-25 (5y ago)
No description available