Researchers analyzed a leaked Babuk ransomware builder and concluded it is likely authentic, showing it can generate platform-specific encryptor and decryptor binaries for Windows, ARM-based NAS devices, and VMware ESXi servers. The leaked package reportedly included a Windows builder executable, binary templates, Unix executables, and a ransom note template, and reverse engineering found strong similarities between builder-produced samples and known Babuk malware, including closely matching structure, encryption behavior, and assembly code. Analysts said the builder can either create elliptic-curve keys automatically or accept a supplied key, allowing operators to reuse the same decryption executable across multiple builds.
The generated Babuk payloads were reported to delete shadow copies, disrupt VSS-related activity, empty the recycle bin, drop ransom notes named "How to Restore Your Files.txt", append the .babyk extension to encrypted files, and add the signature "choung dong looks like hot dog!!". The corresponding decryptor searches for .babyk files, validates and removes the signature, restores file contents, deletes ransom notes, and displays a completion message. Researchers said the leak could help defenders improve IoCs, YARA detections, and tracking of unofficial Babuk variants, while also lowering the barrier for other ransomware actors to reuse the tooling.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Both analyses state that a builder for the Babuk ransomware family was leaked online in late June or early July 2021, exposing tooling for generating Windows, NAS, and ESXi encryptor and decryptor binaries.
Cyble stated that Babuk was highly active in May 2021 and conducted at least 42 attacks, with the United States, Canada, Spain, France, and Germany listed as the most affected countries.
Cyble reported that the Babuk encryptor binary analyzed in the leaked package was compiled on 2021-03-23 19:22:40 as a GUI-based x86 C/C++ application.
Static analysis cited by Cyble found builder.exe was compiled on 2021-03-16 10:03:10 as a console-based x86 C/C++ application.
Cyble reported that Babuk came to light in January 2021 after impacting at least five large enterprises across multiple sectors.
Lab52 obtained and analyzed the leaked package and concluded it was very likely an authentic Babuk builder, while Cyble separately documented its build process and generated binaries for multiple platforms.
Lab52 reported that the leaked builder was uploaded to VirusTotal, where Kevin Beaumont identified the sample as a Babuk ransomware builder.
Lab52 said the builder leak occurred after Babuk publicly moved away from ransomware-as-a-service operations toward data-leak extortion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.