BlueSky is a Windows ransomware family first discovered in June 2022. It encrypts files on local storage and mounted network shares, using separate threads for file enumeration and encryption to accelerate processing. Its cryptographic design uses ChaCha20 for file encryption and Curve25519 for key generation and shared-key derivation. It excludes selected files and directories, renames encrypted files, and places ransom notes in affected directories. Host-specific identifiers, a mutex, and stored encryption-state and recovery information support its execution and key handling.
BlueSky has been delivered through staged PowerShell scripts that decode and download additional components, check administrative privileges, and attempt local privilege escalation before executing the ransomware. Observed chains use modified JuicyPotato tooling on older Windows systems and exploits for CVE-2020-0796 and CVE-2021-1732 on newer systems. Payloads masquerade as legitimate applications and have been executed from the Windows startup folder. Defense-evasion features include string encryption, hashed API names, obfuscation, and anti-debugging mechanisms.
BlueSky's multithreaded architecture and network-share discovery code closely resemble Conti v3, while its cryptographic design resembles Babuk; these similarities do not establish common operators. BruteSQL has deployed BlueSky in attacks involving Microsoft SQL Server brute-forcing. A December 2022 intrusion began with compromise of an internet-facing SQL Server and progressed through Cobalt Strike, Tor2Mine tooling, and lateral movement before BlueSky deployment and SMB-based propagation. No data exfiltration was observed in that intrusion. Atera has also appeared in attack chains leading to BlueSky deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
If the host is running Windows 10 or later, then the script will download and execute ghost.exe and spooler.exe to exploit local privilege escalation vulnerabilities CVE-2020-0796 and CVE-2021-1732 respectively. | Executive Summary BlueSky ransomware is an emerging family that has adopted modern techniques to evade security defenses.
If the host is running Windows 10 or later, then the script will download and execute ghost.exe and spooler.exe to exploit local privilege escalation vulnerabilities CVE-2020-0796 and CVE-2021-1732 respectively. | Executive Summary BlueSky ransomware is an emerging family that has adopted modern techniques to evade security defenses.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618). | These attacks leverage Remcos (a commercially available remote access trojan) and deploy various families of ransomware including TargetCompany, aka Mallox; GlobeImposter, aka Alpha865qqz; and BlueSky.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618). | These attacks leverage Remcos (a commercially available remote access trojan) and deploy various families of ransomware including TargetCompany, aka Mallox; GlobeImposter, aka Alpha865qqz; and BlueSky.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This server is related to another piece of malware, the BlueSky ransomware.
Executive Summary BlueSky ransomware is an emerging family that has adopted modern techniques to evade security defenses.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618).
If the host is running Windows 10 or later, then the script will download and execute ghost.exe and spooler.exe to exploit local privilege escalation vulnerabilities CVE-2020-0796 and CVE-2021-1732 respectively.
T1027 Obfuscated Files or Information BlueSky can use API obfuscation to protect its functionality from analysis.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the ransomware families deployed in the broader SQL Server attack activity, but not further analyzed in detail in the report.
Ransomware connected to infrastructure examined during the investigation of TargetCompany-related activity. The report describes encryption similarities with TargetCompany and identifies BruteSQL as having deployed BlueSky in July 2022. These observations suggest connections but do not establish that the operators are identical.
Ransomware mentioned in connection with attack chains using Atera.
Ransomware deployed after MSSQL brute-force compromise. It was dropped as vmware.exe, spread across the network over SMB, encrypted files, renamed them with the .bluesky extension, and dropped a ransom note named '# DECRYPT FILES BLUESKY #.txt'.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.