Babuk Locker is a ransomware and extortion operation that emerged in early 2021 and became known for double-extortion attacks combining data theft with file encryption. The group publicly threatened victims through a leak site and gained particular notoriety after targeting the Metropolitan Police Department of the District of Columbia, where it claimed to have stolen large volumes of sensitive law-enforcement data and threatened further coercive exposure. Babuk Locker also targeted corporate organizations, including victims in retail and professional sports. The operation is notable for ransomware capable of encrypting VMware ESXi-hosted virtual hard disks, a capability that made it relevant in attacks against virtualized enterprise infrastructure. Reporting also indicates the group used pre-authentication remote code execution opportunities against ESXi-related environments. Babuk Locker’s activity reflects core ransomware tradecraft including initial access, data exfiltration, persistence, post-exploitation, and defense evasion in support of extortion. After heightened scrutiny following the DC police incident, Babuk Locker announced that it would stop conducting encryption-based intrusions and shift toward pure data-theft extortion. It stated that it would continue breaching organizations, stealing sensitive files, and publishing victim data if payment was refused, and also offered leak-site hosting for other criminal groups. This places the group among actors that moved from conventional ransomware toward encryption-less extortion. A leaked Babuk builder later enabled other threat actors to generate customized Babuk-derived ransomware for Windows, VMware ESXi, and NAS platforms, leading to copycat campaigns worldwide. Those later derivative attacks should be distinguished from the original Babuk Locker operation. By 2025, the Babuk name was also associated with deceptive extortion activity involving unsubstantiated or recycled breach claims, further complicating attribution around the brand.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in connection with a leak site where stolen victim data was released.
Extortion actor noted for deceptive/psychological pressure operations, including unsubstantiated breach claims and recycled/falsified leaks that complicate verification.
Ransomware group noted for deceptive extortion tactics, including unsubstantiated breach claims and recycling outdated/falsified leak data to apply psychological pressure.
A ransomware operation whose leaked builder was subsequently used in a new global ransomware campaign; the original group conducted double-extortion attacks against corporate victims and later shifted to a non-encrypting data extortion model under the name PayLoad Bin.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.