Rorschach, also referred to as BabLock, is a ransomware family associated with Linux and VMware ESXi encryption activity. It has been identified as one of several ransomware families that adopted code derived from the leaked Babuk source code, specifically in ESXi-focused lockers that emerged from the second half of 2022 through the first half of 2023. This places Rorschach within a broader wave of actors and malware families that reused Babuk-derived components to accelerate development of Linux and hypervisor-targeting ransomware. Rorschach is linked to ransomware operations against VMware ESXi environments, a high-value target class in enterprise networks because compromise can disrupt multiple hosted virtual machines at once. Its inclusion among Babuk-descended ESXi ransomware indicates use of code patterns and functionality consistent with Babuk-derived Linux encryptors. The available information supports ransomware encryption capability and targeting of virtualized infrastructure, but does not provide high-confidence detail on a distinct operator, victimology, extortion workflow, or a unique intrusion playbook beyond its Babuk-code lineage. Known alias: BabLock.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware family/group cited as a Babuk ESXi source-code descendant.
Named as an ESXi-focused ransomware family/operator in the context of Babuk code reuse (attribution/relationship not further detailed).
Ransomware family observed using leaked Babuk source code/builder to create ESXi encryptors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.