Babuk, also known as Babuk Locker, is a ransomware-as-a-service (RaaS) strain first identified in 2021. It is designed for targeted, large-scale attacks against enterprises and government organizations. Babuk follows a double-extortion model: encrypting critical files while also stealing sensitive data to pressure victims into paying.
Babuk Ransomware Features:
-
Advanced file encryption (AES, ChaCha, HC-128)
-
Secure key exchange using elliptic-curve cryptography (ECDH, Curve25519)
-
Encrypted files with custom extensions (.babuk, .babyk, etc.)
-
Automatic ransom note creation in affected directories
-
Data theft and double-extortion capability
-
Deletion of shadow copies and system restore points
-
Termination of security, backup, and database services
-
Targeting of Windows Nas and VMware ESXi environments
-
Network scanning and lateral movement within domains
-
Utilization of penetration frameworks (Cobalt Strike, Metasploit, BloodHound)
-
Mutex generation to avoid multiple infections
-
Persistence through scheduled tasks and services
