Uptime Hamster: 10d 8h 39mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza babuk

babuk

1 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-29
Aliases: Vasa Locker, Babyk, Fancy Gang, Babuk, Conti, LockBit 3
Ver en IntelTracker → APTTrail →
Babuk is a ransomware group that emerged in December 2020, quickly adopting a ransomware-as-a-service (RaaS) model and double extortion tactics to target large corporate and government entities primarily for financial gain. The group gained notoriety for its "big-game hunting" approach, particularly after an attack on the Washington D.C. Metropolitan Police Department in April 2021, which reportedly led to internal discord and the group's announced retirement in mid-2021. A defining characteristic of Babuk's operational lifespan was the subsequent leak of its complete source code, facilitating the proliferation of new ransomware variants and inspiring copycat groups like Babuk2 or Babuk-Bjorka, which have since impersonated the original operation using recycled data. The group is assessed with high confidence to be of Eastern European, specifically Russian, origin.

Aliases del actor

Vasa LockerBabykFancy GangBabukContiLockBit 3

Actores similares

Babuk-Lockerransomware · 0babuk2ransomware · 180babuk-bjorkaransomware · 0lockbit3ransomware · 2016lockbit2ransomware · 1002contiransomware · 351lockbit5ransomware · 278medusalockeractor · 26tridentlockerransomware · 6avoslockerransomware · 3

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Forounknownransomware.anggipradana.comRansomware Group: babuk2
Malware asociado
win.nymaim, win.lockfile, Arkei, win.emotet, OriginLoader
Tecnicas MITRE
T1491, T1543, T1562, T1036, T1548, T1529
CVEs relacionadas
CVE-2023-38831, CVE-2023-36884, CVE-2023-29324, CVE-2023-23397, CVE-2022-36537, CVE-2022-30190
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United Kingdom (1)

Paises objetivo (SOCRadar)

United Arab EmiratesAustraliaBrazilCanadaChileChinaColombiaCubaGermanySpain

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingCredit UnionsRail TransportationSoftware PublishersReal EstateHospitalsAccommodationAir TransportationManufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com