Warning: Babuk Locker Ransomware is Active Again, Attacking the World
Babuk Locker is a ransomware operation born in early 2021, targeting companies, stealing their data and extorting money.
After carrying out an attack on Washington DC's Metropolitan Police Department (MPD), the ransomware gang ceased operations in April and switched to a model of non-encrypted data extortion under the name PayLoad Bin.
Last week, security researcher Kevin Beaumont discovered someone had uploaded the Babuk operation's ransomware generator to VirusTotal.
Creating custom ransomware is simple. All the threat agent has to do is modify the accompanying note, including contact information. Then run the executable to create a custom ransomware encoder and decoder that targets Windows, VMware ESXi, Network Attached Storage (NAS) x86, and an ARM NAS device.
Soon after this ransomware generator leaked online, a threat actor started using it to launch a ransomware campaign.
On June 29, on Reddit, a victim reported they were hacked by software claiming to be "Babuk Locker".
BleepingComputer quoted security researcher MalwareHunterTeam as saying, starting June 29, ID Ransomware received a spike in Babuk Locker.
Victims come from all over the world, and ransom notes are all sent from the email address of the threater.
Like the original operation, this ransomware attack adds the .babyk extension to the encrypted file name and issues a ransom note called How To Restore Your Files.txt.
Compared to asking for hundreds of thousands and millions of USD in the first operation, this time they only demanded 210 USD from the victim.
Locker uses a dedicated Tor payment site to negotiate with victims. However, the new attacks are using email, specifically babukransom@tutanota.com, to communicate with victims.
It's not clear how the ransomware is being spread, but there is a thread where victims can share more information about the Babuk Locker attack.
You should read it
- This is the world's fastest ransomware, encrypting 53GB of data in just over 4 minutes
- 7 kinds of ransomware you didn't expect
- How to hide folders and data on Windows 10 Mobile
- List of the 3 most dangerous and scary Ransomware viruses
- Ransomware can encrypt cloud data
- General guidelines for decoding ransomware
- What is Ransomware Task Force (RTF)?
- [Infographic] 7 effective ways to protect businesses from Ransomware
May be interested
- Warning: Ransomware is spreading through fake malicious Windows updatesnamed magniber, this dangerous ransomware strain has been around on the internet for a while, and ranks in the dangerous group with its diverse infectivity.
- How to hide folders and data on Windows 10 Mobile9zen universal locker is an application that helps lock passwords and important files. if others want you to open the folder, we can enter a fake password and will not display the contents of the file inside.
- What is Fargo Ransomware? How to avoid?ransomware is a major threat to the digital world, made even more so by cybercriminals coming up with various strategies. one way to solve the problem is to learn how these attacks work.
- No More Ransom - the flag of the war against ransomwareafter 3 years of active operation, no more ransom has quickly become the name that received the most affection in the security - cyber security world.
- QNAP advises users to disconnect NAS from internet to avoid DeadBolt ransomware ransomwarenetwork attached storage (nas), and especially nas from qnap, should not be exposed to the internet. this is a warning that has just been issued by qnap in the context of a new ransomware called deadbolt that is actively searching for remote-accessible nas systems.
- Dangerous 'Helldown' Ransomware Warning Expands to Linux and VMwaredubbed magniber, this dangerous ransomware strain has been around for a while now, and is ranked among the most dangerous with its diverse infection capabilities.
- Windows SMB users should close some ports to prevent WannaCrywill ransomware wannacry come back to attack us? try closing some of the ports below to prevent ransomware from attacking!
- Ako ransomware is raging all over the world, what do you know about this ransomware?ako was first discovered when a victim posted information about an infection he encountered on the bleeping computer security forum.
- List of the 3 most dangerous and scary Ransomware viruseswhile security solutions to protect us from threats, hackers are increasingly improving, while malicious programs (malware) are also becoming more and more 'cunning'. and one of the recent threats is how to extort money through ransomware.
- Warning campaign of large-scale ransomware attack, misuse of 7zip to encrypt QNAP devicesinternational cybersecurity researchers have warned of a massive ransomware attack against qnap devices around the world.