s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-elf.babuk

📛 Threat Title

Malware family: Babuk

Category: Babuk First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.babuk`. Printable name: Babuk.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.babuk VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.babuk

IOC database

Type
domain
Value
elf.babuk
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.babuk

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.babuk

References (1)

Remediations (10)

  • web:attack.mitre.org

    Babuk is a Ransomware-as-a-service (RaaS) malware that has been used since at least 2021. The operators of Babuk employ a "Big Game Hunting" approach to targeting major enterprises and operate a leak site to post stolen data as part of their extortion scheme.

  • web:cybersecuritynews.com

    Derp.Ca researchers identified the malware through a complete reverse-engineering analysis of both the Windows binary and the Linux ELF variant. They noted that seventeen VirusTotal engines flagged the Windows sample as Babuk , linking it to the Babuk source code that leaked publicly in September 2021.

  • web:github.com

    Note THREAT INTELLIGENCE DOCUMENTATION — FOR AUTHORIZED SECURITY RESEARCH ONLY. This repository contains analysis documentation only (no source code) from the reverse engineering of the Babuk ransomware family . Published to support malware analysis, detection engineering, incident response, and academic research.

  • web:helpful.foundation

    Babuk is a Russian-speaking cybercrime group that emerged in early 2021, known for operating a Ransomware-as-a-Service (RaaS) model. The group quickly gained notoriety for its "double extortion" tactics—encrypting victims' files while also stealing sensitive data and threatening to leak it if ransom demands aren't met.

  • web:malpedia.caad.fkie.fraunhofer.de

    Ransomware Encryption Internals: A Behavioral Characterization Babuk Babuk BlackMatter 2021-10-12 ⋅ CrowdStrike ⋅ CrowdStrike Intelligence Team ECX: Big Game Hunting on the Rise Following a Notable Reduction in Activity Babuk BlackMatter DarkSide REvil Avaddon Babuk BlackMatter DarkSide LockBit Mailto REvil 2021-09-10 ⋅ S2W LAB Inc. ⋅ ...

  • web:mssplab.github.io

    Malware analysis report: Babuk ransomware 15 minute read Babuk is a ransomware family that was first discovered in early 2021. It quickly became infamous, especially among corporate networks, for its ability to quickly encrypt files and demand ransom.

  • web:securityboulevard.com

    This led to a proliferation of ransomware variants based on that code family (Play and RTM Locker). According to investigations on public information, Babuk2 is not a continuation of the original Babuk ransomware group. Instead, it is an independent hacker group named Bjorka who has adopted Babuk's name and attack templates.

  • web:www.picussecurity.com

    The following evidence debunks their claims of a return. The Malware is Actually LockBit 3.0 Technical analysis of the encryptor advertised by Babuk2 reveals it is not Babuk code, but rather a rebrand of LockBit 3.0 (LockBit Black) [7]. The sample uses LockBit's specific wallpaper and ransom note generation routines [7].

  • web:www.sentinelone.com

    What is Babuk ransomware? Babuk is a ransomware family that targets corporate networks. It infiltrates systems, encrypts files, and demands payment for a decryption key, often threatening to leak stolen data if the victim doesn't pay . Babuk emerged in early 2021 (likely operated by a Russian crew) as a Ransomware-as-a-Service.

  • web:www.trellix.com

    Babuk ransomware is a new ransomware family originally detected at the beginning of 2021. Its operators adopted the same operating methods as other ransomware families and leaked the stolen data. Babuk's codebase and artefacts are highly similar to Vasa Locker's. Babuk advertises on both English-speaking and Russian-speaking forums.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.