Babuk, also known as Babyk and Vasa Locker, is a ransomware family that emerged in early 2021 and was operated through a ransomware-as-a-service model. It targets Windows, Linux, including ARM-based systems, and VMware ESXi environments. Victims have included organizations in healthcare, manufacturing, logistics, public services, and critical infrastructure. The original Babuk operation practiced double extortion, combining file encryption with threats to publish stolen information.
Babuk uses hybrid cryptography, including ChaCha8 and Elliptic Curve Diffie–Hellman in documented variants. An attacker-controlled public key embedded in the payload protects per-file symmetric key material, and encrypted files contain appended key information and metadata. Windows variants interrupt backup processes and delete volume shadow copies to impede recovery. ESXi variants target virtualization storage, allowing encryption to disrupt multiple hosted virtual machines.
Leaks of Babuk's builder and source code in 2021 enabled independent threat actors to generate and modify encryptors and decryptors, producing numerous derivative families. Tortilla deployed a Babuk variant against vulnerable Microsoft Exchange servers through ProxyShell exploitation; Masque has used Babuk against ESXi environments, and Toy Ghouls previously used leaked Babuk builders. Babuk-derived payloads have also been deployed to ESXi hosts through compromised VMware vCenter instances. These derivative attacks do not necessarily involve the original Babuk operators. Public decryptors support some variants when the corresponding private keys are known, but do not provide universal recovery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cisco Talos discovered a Tortilla campaign in our product telemetry on Oct. 12, 2021, targeting vulnerable Microsoft Exchange servers and attempting to exploit the ProxyShell vulnerability to deploy the Babuk ransomware in the victim's environment. | Babuk ransomware emerged in 2021, gaining notoriety for its high-profile attacks on targeted industries, especially those in healthcare, manufacturing, logistics and public services, including critical infrastructure.
ProxyShell is a name given to an attack that chains a trio of vulnerabilities together (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), to enable unauthenticated attackers to perform remote code execution (RCE) and to snag plaintext passwords. | Tortilla is launching ProxyShell attacks on Microsoft Exchange servers to infect vulnerable servers with variants of the Babuk ransomware.
Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
ProxyShell is a name given to an attack that chains a trio of vulnerabilities together (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), to enable unauthenticated attackers to perform remote code execution (RCE) and to snag plaintext passwords. | Tortilla is launching ProxyShell attacks on Microsoft Exchange servers to infect vulnerable servers with variants of the Babuk ransomware.
QUIRSO have since mapped a sprawling global campaign that compromised 361 unique IP addresses across 47 countries, culminating in the deployment of Babuk-derived ransomware directly onto ESXi hypervisors.
The initial downloader is a modified EfsPotato exploit to target proxyshell and PetitPotam vulnerabilities. | EfsPotato is an exploit that attempts to escalate the process privileges using a vulnerability in the Encrypted File System (CVE-2021-36942). | Cisco Talos recently discovered a malicious campaign deploying variants of the Babuk ransomware predominantly affecting users in the U.S.
According to a Coveware report, Babuk ransomware is also targeting SonicWall VPNs likely vulnerable to CVE-2020-5135 exploits. This vulnerability was patched in October 2020 but it is still "heavily abused by ransomware groups today" per Coveware. | According to a Coveware report, Babuk ransomware is also targeting SonicWall VPNs likely vulnerable to CVE-2020-5135 exploits.
The version of Velociraptor observed in this incident was outdated (version 0.73.4.0) and exposed to a privilege escalation vulnerability (CVE-2025-6264), which may have been leveraged for persistence as this vulnerability can lead to arbitrary command execution and endpoint takeover.
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
...threat actors have been observed weaponizing a vulnerable version of Bitrix for initial access, followed by using the Zerologon flaw to escalate privileges.
30 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ранее она использовала сторонние шифровальщики, включая RedAlert, LockBit и Babuk.
Tortilla is launching ProxyShell attacks on Microsoft Exchange servers to infect vulnerable servers with variants of the Babuk ransomware.
Competitor ransomware groups like “Bl00dy,” “Dragonforce,” and “RA World” rely on leaked “Babuk” or “LockBit” builders to launch attacks.
Competitor ransomware groups like “Bl00dy,” “Dragonforce,” and “RA World” rely on leaked “Babuk” or “LockBit” builders to launch attacks.
Competitor ransomware groups like “Bl00dy,” “Dragonforce,” and “RA World” rely on leaked “Babuk” or “LockBit” builders to launch attacks.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Its purpose is to delete the ransom Note “ How to Restore Your Files.txt ” ... it deletes using the “ DeleteFileW ” the file
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
After inventory discovery, the attackers created local administrator accounts on ESXi hosts
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
123 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as the code base for an Akira lookalike encryptor. The lookalike uses the .akira extension and an imitation ransom note, demonstrating that these artifacts alone cannot establish an Akira infection.
Leaked Babuk codebase was reportedly used to create derived ransomware payloads that encrypt ESXi-hosted virtual machines after compromise of vCenter.
Ransomware family mentioned only as the source of a leaked builder previously used by Toy Ghouls.
Babuk-derived ransomware payloads were deployed after exploitation of VMware vCenter CVE-2026-59310 to encrypt ESXi virtual machines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.