BlueSky is a Windows ransomware family first observed in 2022 and notable for combining implementation traits associated with Conti and Babuk. Its architecture includes multithreaded file encryption and network-share enumeration resembling Conti, while its cryptographic design uses ChaCha20 for file encryption and Curve25519-based key exchange more closely aligned with Babuk. BlueSky encrypts files on local systems and mounted network shares, appends a distinctive extension to affected files, and drops ransom notes on compromised hosts. It also maintains host-specific state through generated victim identifiers, mutex creation, and registry-stored recovery metadata.
The malware incorporates multiple anti-analysis and defense-evasion measures, including string and API obfuscation, hashed API resolution, and anti-debugging logic. Observed execution chains used staged PowerShell delivery, privilege checks, and local privilege-escalation attempts on different Windows versions, including use of JuicyPotato on older systems and exploitation of CVE-2020-0796 and CVE-2021-1732 on newer systems. In intrusion reporting, BlueSky was deployed after compromise of internet-facing Microsoft SQL Server environments, including cases where attackers brute-forced the MSSQL sa account, enabled command execution through SQL Server features, and then launched PowerShell-based payloads before ransomware deployment.
BlueSky has been associated with broader post-exploitation activity involving Cobalt Strike, SMB-based propagation, credential-dumping activity, and lateral movement via remote service creation. In at least one documented intrusion, ransomware deployment followed initial access in roughly half an hour, indicating a fast hands-on-keyboard operation. Code-level links to Conti and Babuk have been reported, but BlueSky is treated as a distinct ransomware family. Reporting has also noted operational overlap with SQL-server-focused intrusion clusters and possible connections to actors involved in brute-force attacks on exposed MSSQL infrastructure. Victims have included organizations compromised through public-facing Windows server infrastructure rather than a single narrowly defined sector.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
If the host is running Windows 10 or later, then the script will download and execute ghost.exe and spooler.exe to exploit local privilege escalation vulnerabilities CVE-2020-0796 and CVE-2021-1732 respectively. | Executive Summary BlueSky ransomware is an emerging family that has adopted modern techniques to evade security defenses.
If the host is running Windows 10 or later, then the script will download and execute ghost.exe and spooler.exe to exploit local privilege escalation vulnerabilities CVE-2020-0796 and CVE-2021-1732 respectively. | Executive Summary BlueSky ransomware is an emerging family that has adopted modern techniques to evade security defenses.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618). | These attacks leverage Remcos (a commercially available remote access trojan) and deploy various families of ransomware including TargetCompany, aka Mallox; GlobeImposter, aka Alpha865qqz; and BlueSky.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618). | These attacks leverage Remcos (a commercially available remote access trojan) and deploy various families of ransomware including TargetCompany, aka Mallox; GlobeImposter, aka Alpha865qqz; and BlueSky.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Executive Summary BlueSky ransomware is an emerging family that has adopted modern techniques to evade security defenses.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618).
If the host is running Windows 10 or later, then the script will download and execute ghost.exe and spooler.exe to exploit local privilege escalation vulnerabilities CVE-2020-0796 and CVE-2021-1732 respectively.
T1027 Obfuscated Files or Information BlueSky can use API obfuscation to protect its functionality from analysis.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the ransomware families deployed in the broader SQL Server attack activity, but not further analyzed in detail in the report.
Ransomware deployed after MSSQL brute-force compromise. It was dropped as vmware.exe, spread across the network over SMB, encrypted files, renamed them with the .bluesky extension, and dropped a ransom note named '# DECRYPT FILES BLUESKY #.txt'.
A ransomware family mentioned as a possible connected group sharing similarities with TargetCompany operations.
Ransomware targeting Windows hosts that uses multithreaded encryption, anti-analysis techniques such as string encryption, API obfuscation and anti-debugging, and encrypts files with ChaCha20/Curve25519 before appending the .bluesky extension and dropping ransom notes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.