TF-MAL-elf.babuk
📛 Threat Title
Malware family: Babuk
Description
ThreatFox malware family `elf.babuk`. Printable name: Babuk.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.babuk
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.babuk
IOC database
- Type
- domain
- Value
elf.babuk- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.babuk
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.babuk
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Babuk is a Ransomware-as-a-service (RaaS) malware that has been used since at least 2021. The operators of Babuk employ a "Big Game Hunting" approach to targeting major enterprises and operate a leak site to post stolen data as part of their extortion scheme.
-
web:cybersecuritynews.com
Derp.Ca researchers identified the malware through a complete reverse-engineering analysis of both the Windows binary and the Linux ELF variant. They noted that seventeen VirusTotal engines flagged the Windows sample as Babuk , linking it to the Babuk source code that leaked publicly in September 2021.
-
web:github.com
Note THREAT INTELLIGENCE DOCUMENTATION — FOR AUTHORIZED SECURITY RESEARCH ONLY. This repository contains analysis documentation only (no source code) from the reverse engineering of the Babuk ransomware family . Published to support malware analysis, detection engineering, incident response, and academic research.
-
web:helpful.foundation
Babuk is a Russian-speaking cybercrime group that emerged in early 2021, known for operating a Ransomware-as-a-Service (RaaS) model. The group quickly gained notoriety for its "double extortion" tactics—encrypting victims' files while also stealing sensitive data and threatening to leak it if ransom demands aren't met.
-
web:malpedia.caad.fkie.fraunhofer.de
Ransomware Encryption Internals: A Behavioral Characterization Babuk Babuk BlackMatter 2021-10-12 ⋅ CrowdStrike ⋅ CrowdStrike Intelligence Team ECX: Big Game Hunting on the Rise Following a Notable Reduction in Activity Babuk BlackMatter DarkSide REvil Avaddon Babuk BlackMatter DarkSide LockBit Mailto REvil 2021-09-10 ⋅ S2W LAB Inc. ⋅ ...
-
web:mssplab.github.io
Malware analysis report: Babuk ransomware 15 minute read Babuk is a ransomware family that was first discovered in early 2021. It quickly became infamous, especially among corporate networks, for its ability to quickly encrypt files and demand ransom.
-
web:securityboulevard.com
This led to a proliferation of ransomware variants based on that code family (Play and RTM Locker). According to investigations on public information, Babuk2 is not a continuation of the original Babuk ransomware group. Instead, it is an independent hacker group named Bjorka who has adopted Babuk's name and attack templates.
-
web:www.picussecurity.com
The following evidence debunks their claims of a return. The Malware is Actually LockBit 3.0 Technical analysis of the encryptor advertised by Babuk2 reveals it is not Babuk code, but rather a rebrand of LockBit 3.0 (LockBit Black) [7]. The sample uses LockBit's specific wallpaper and ransom note generation routines [7].
-
web:www.sentinelone.com
What is Babuk ransomware? Babuk is a ransomware family that targets corporate networks. It infiltrates systems, encrypts files, and demands payment for a decryption key, often threatening to leak stolen data if the victim doesn't pay . Babuk emerged in early 2021 (likely operated by a Russian crew) as a Ransomware-as-a-Service.
-
web:www.trellix.com
Babuk ransomware is a new ransomware family originally detected at the beginning of 2021. Its operators adopted the same operating methods as other ransomware families and leaked the stolen data. Babuk's codebase and artefacts are highly similar to Vasa Locker's. Babuk advertises on both English-speaking and Russian-speaking forums.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.