Tortilla is a financially motivated ransomware actor active since July 2021, known for deploying a variant of Babuk ransomware against vulnerable Microsoft Exchange servers. Its operations predominantly affected victims in the United States, with additional infections in the United Kingdom, Germany, Ukraine, Finland, Brazil, Honduras, and Thailand. The actor conducted internet-wide scanning to identify vulnerable hosts and attempted to exploit the ProxyShell vulnerability chain. Its operations also used the China Chopper web shell and included earlier experimentation with PowerCat to obtain and maintain remote access. Tortilla used executable and DLL downloaders, obfuscated PowerShell, and a multistage loading chain. An intermediate unpacker decoded and decrypted an embedded ransomware payload in memory before injecting it into a legitimate Windows process. Defense-evasion techniques included an AMSI bypass, disabling Microsoft Defender protections, payload packing, and removing metadata identifying downloaded files as originating from the internet. The Babuk payload encrypted files on compromised servers and mounted drives, stopped backup-related services, and deleted volume shadow copies to impede recovery. Tortilla demanded $10,000 for a decryption key. Tortilla reused a single encryption key pair across its victims. During cooperation with Dutch police, Cisco Talos recovered the actor's decryptor and extracted its private key, which Avast incorporated into its free Babuk decryptor to enable recovery of affected files. Dutch police identified and apprehended the actor behind the operation, and the Dutch Prosecution Office prosecuted the actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
ProxyShell is a name given to an attack that chains a trio of vulnerabilities together (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), to enable unauthenticated attackers to perform remote code execution (RCE) and to snag plaintext passwords.
ProxyShell is a name given to an attack that chains a trio of vulnerabilities together (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), to enable unauthenticated attackers to perform remote code execution (RCE) and to snag plaintext passwords.
ProxyShell is a name given to an attack that chains a trio of vulnerabilities together (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), to enable unauthenticated attackers to perform remote code execution (RCE) and to snag plaintext passwords.
The initial downloader is a modified EfsPotato exploit to target proxyshell and PetitPotam vulnerabilities. | EfsPotato is an exploit that attempts to escalate the process privileges using a vulnerability in the Encrypted File System (CVE-2021-36942).
25 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted ransomware operations targeting vulnerable Microsoft Exchange servers, deploying the Tortilla variant of Babuk through ProxyShell exploitation and a multistage infection chain. The operator reused a single encryption key pair across victims. Dutch authorities apprehended and prosecuted the operator using Talos intelligence; Talos recovered the private key for inclusion in Avast's Babuk decryptor.
A threat actor operating a Babuk-derived ransomware campaign using the Tortilla variant; victims can be identified by .babyk-encrypted files and the ransom note 'How To Restore Your Files.txt'.
Conducts ransomware attacks against vulnerable Microsoft Exchange servers. Researchers observed the campaign on October 12, 2021, and assessed ProxyShell exploitation through China Chopper deployment as the initial infection vector with moderate confidence. The actor previously experimented with remote-access payloads and demonstrates low-to-medium technical skill, including minor modifications to existing malware and offensive tools.
A newly observed ransomware actor deploying Babuk variants, primarily by exploiting vulnerable Microsoft Exchange servers via ProxyShell and deploying China Chopper web shells, then using staged loaders and in-memory unpacking to deliver ransomware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.