LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0638: Babuk

Babuk is a Ransomware-as-a-service (RaaS) malware that has been used since at least 2021. The operators of Babuk employ a "Big Game Hunting" approach to targeting major enterprises and operate a leak site to post stolen data as part of their extortion scheme.[1][2][3]

EnterpriseS0638MalwareObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Babuk matters because ATT&CK describes it as ransomware-as-a-service used against major enterprises, with both encryption and data-leak extortion in scope. For leaders, the decision value is not a single malware name; it is whether the organization can see and contain the ransomware sequence: discovery of services, processes, files, network connections, shares, and storage, followed by attempts to impair defenses, stop services, inhibit recovery, and encrypt data on Windows and Linux systems.

Executive priority

Treat this as a resilience and incident-readiness use case. Executives should ask whether critical Windows and Linux assets, file shares, backup/recovery paths, and security tooling are monitored well enough to detect discovery and impact behaviors before encryption becomes widespread. Priority should go to evidence that backups are recoverable, recovery features cannot be easily disabled, security tools are protected from tampering, and SOC/IR teams have playbooks for ransomware with possible data-extortion pressure.

Technical view

ATT&CK provides no standalone detection text for Babuk, so validation should be built from its mapped behaviors. SOC and detection teams should test coverage for command shell execution, native API-heavy execution, packed or obfuscated binaries, deobfuscation activity, service/process/network/share/file/storage discovery, service stopping, recovery inhibition, defense tool modification, and data encryption. Because the object is scoped to Windows and Linux, coverage should be confirmed separately across both operating environments rather than assumed from one platform.

Likely telemetry

  • Endpoint process creation and command-line logging for Windows and Linux
  • Service control and service state-change events
  • Process enumeration and termination events
  • File, directory, network share, and local storage enumeration activity
  • Network connection listings and host network telemetry

Detection direction

  • Map detections to the related ATT&CK techniques rather than relying on a Babuk signature alone, especially T1486, T1489, T1490, and T1685 for impact and defense impairment.
  • Correlate discovery behaviors across services, processes, network connections, shares, files, and storage; individually these can be administrative, but clustering before encryption is higher value.
  • Tune false positives around legitimate administration, backup operations, software deployment, and security tool maintenance by using change windows, admin identity context, and affected asset criticality.
  • Validate visibility on Linux as well as Windows, since the ATT&CK object lists both platforms.
  • Include packed or obfuscated executable handling in triage workflows, but do not treat packing alone as sufficient evidence of Babuk.

Mitigation priorities

  • Prioritize tested, isolated, and recoverable backups, with monitoring for attempts to delete or disable recovery mechanisms.
  • Harden and monitor security tools and logging agents against stopping, tampering, or configuration changes.
  • Restrict and monitor administrative capabilities that can enumerate shares, stop services, modify recovery settings, or affect broad file storage.
  • Segment and control access to high-value file shares and critical Linux/Windows servers to reduce blast radius.
  • Prepare ransomware IR procedures that include containment, preservation of evidence, backup validation, business decision support, and data-extortion communications governance.
Additional notes and limits

The strongest relationship-driven signal is the combination of discovery, defense impairment, recovery inhibition, service stopping, and encryption. Babuk is described by ATT&CK as RaaS with a Big Game Hunting approach and leak-site extortion, so business stakeholders should include legal, communications, privacy, and continuity teams in ransomware readiness planning.

ATT&CK does not provide Babuk-specific detection guidance in the supplied object. The object lists Windows and Linux platforms but no explicit tactics field; tactical interpretation here comes from the supplied relationships. Local telemetry quality, asset criticality, administrative baselines, and backup architecture are required to assess real coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Babuk

Babuk is a Ransomware-as-a-service (RaaS) malware that has been used since at least 2021. The operators of Babuk employ a "Big Game Hunting" approach to targeting major enterprises and operate a leak site to post stolen data as part of their extortion scheme.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

14 rows
DomainIDNameRelationship / procedure
EnterpriseT1685Disable or Modify Tools

Babuk can stop anti-virus services on a compromised host.[1]

EnterpriseT1049System Network Connections Discovery

Babuk can use “WNetOpenEnumW” and “WNetEnumResourceW” to enumerate files in network resources for encryption.[2]

EnterpriseT1106Native API

Babuk can use multiple Windows API calls for actions on compromised hosts including discovery and execution.[1][2][4]

EnterpriseT1140Deobfuscate/Decode Files or Information

Babuk has the ability to unpack itself into memory using XOR.[1][4]

EnterpriseT1486Data Encrypted for Impact

Babuk can use ChaCha8 and ECDH to encrypt data.[1][2][4][5]

EnterpriseT1027.002Software PackingSub-technique

Versions of Babuk have been packed.[1][2][4]

EnterpriseT1489Service Stop

Babuk can stop specific services related to backups.[1][2][5]

EnterpriseT1490Inhibit System Recovery

Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet.[1][2]

EnterpriseT1059.003Windows Command ShellSub-technique

Babuk has the ability to use the command line to control execution on compromised hosts.[1][2]

EnterpriseT1135Network Share Discovery

Babuk has the ability to enumerate network shares.[1]

EnterpriseT1007System Service Discovery

Babuk can enumerate all services running on a compromised host.[2]

EnterpriseT1057Process Discovery

Babuk has the ability to check running processes on a targeted system.[1][2][5]

EnterpriseT1680Local Storage Discovery

Babuk can enumerate disk volumes, get disk information, and query service status.[2]

EnterpriseT1083File and Directory Discovery

Babuk has the ability to enumerate files on a targeted system.[2][5]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
766246acbed96570...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle766246acbed9…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  2. [2]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  3. [3]
    CyberScoop Babuk February 2021

    Lyngaas, S. (2021, February 4). Meet Babuk, a ransomware attacker blamed for the Serco breach. Retrieved August 11, 2021.

    Open source URL
  4. [4]
    Medium Babuk February 2021

    Sebdraven. (2021, February 8). Babuk is distributed packed. Retrieved August 11, 2021.

    Open source URL
  5. [5]
    Trend Micro Ransomware February 2021

    Centero, R. et al. (2021, February 5). New in Ransomware: Seth-Locker, Babuk Locker, Maoloa, TeslaCrypt, and CobraLocker. Retrieved August 11, 2021.

    Open source URL
  6. [6]
    Babyk

    (Citation: Sogeti CERT ESEC Babuk March 2021)(Citation: McAfee Babuk February 2021)(Citation: Trend Micro Ransomware February 2021)

  7. [7]
    Babyk

    (Citation: Sogeti CERT ESEC Babuk March 2021)(Citation: McAfee Babuk February 2021)(Citation: Trend Micro Ransomware February 2021)

  8. [8]
    Babyk

    (Citation: Sogeti CERT ESEC Babuk March 2021)(Citation: McAfee Babuk February 2021)(Citation: Trend Micro Ransomware February 2021)

  9. [9]
    CyberScoop Babuk February 2021

    Lyngaas, S. (2021, February 4). Meet Babuk, a ransomware attacker blamed for the Serco breach. Retrieved August 11, 2021.

    Open source URL
  10. [10]
    CyberScoop Babuk February 2021

    Lyngaas, S. (2021, February 4). Meet Babuk, a ransomware attacker blamed for the Serco breach. Retrieved August 11, 2021.

    Open source URL
  11. [11]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  12. [12]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  13. [13]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  14. [14]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  15. [15]
    Trend Micro Ransomware February 2021

    Centero, R. et al. (2021, February 5). New in Ransomware: Seth-Locker, Babuk Locker, Maoloa, TeslaCrypt, and CobraLocker. Retrieved August 11, 2021.

    Open source URL
  16. [16]
    Trend Micro Ransomware February 2021

    Centero, R. et al. (2021, February 5). New in Ransomware: Seth-Locker, Babuk Locker, Maoloa, TeslaCrypt, and CobraLocker. Retrieved August 11, 2021.

    Open source URL
  17. [17]
    Vasa Locker

    (Citation: Sogeti CERT ESEC Babuk March 2021)(Citation: McAfee Babuk February 2021)

  18. [18]
    Vasa Locker

    (Citation: Sogeti CERT ESEC Babuk March 2021)(Citation: McAfee Babuk February 2021)

  19. [19]
    Vasa Locker

    (Citation: Sogeti CERT ESEC Babuk March 2021)(Citation: McAfee Babuk February 2021)

  20. [20]
    mitre-attackS0638
    Open source URL
  21. [21]
    mitre-attackS0638
    Open source URL
  22. [22]
    mitre-attackS0638
    Open source URL
  23. [23]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  24. [24]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  25. [25]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  26. [26]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  27. [27]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  28. [28]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  29. [29]
    Medium Babuk February 2021

    Sebdraven. (2021, February 8). Babuk is distributed packed. Retrieved August 11, 2021.

    Open source URL
  30. [30]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  31. [31]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  32. [32]
    Medium Babuk February 2021

    Sebdraven. (2021, February 8). Babuk is distributed packed. Retrieved August 11, 2021.

    Open source URL
  33. [33]
    Medium Babuk February 2021

    Sebdraven. (2021, February 8). Babuk is distributed packed. Retrieved August 11, 2021.

    Open source URL
  34. [34]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  35. [35]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  36. [36]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  37. [37]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  38. [38]
    Medium Babuk February 2021

    Sebdraven. (2021, February 8). Babuk is distributed packed. Retrieved August 11, 2021.

    Open source URL
  39. [39]
    Medium Babuk February 2021

    Sebdraven. (2021, February 8). Babuk is distributed packed. Retrieved August 11, 2021.

    Open source URL
  40. [40]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  41. [41]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  42. [42]
    Trend Micro Ransomware February 2021

    Centero, R. et al. (2021, February 5). New in Ransomware: Seth-Locker, Babuk Locker, Maoloa, TeslaCrypt, and CobraLocker. Retrieved August 11, 2021.

    Open source URL
  43. [43]
    Trend Micro Ransomware February 2021

    Centero, R. et al. (2021, February 5). New in Ransomware: Seth-Locker, Babuk Locker, Maoloa, TeslaCrypt, and CobraLocker. Retrieved August 11, 2021.

    Open source URL
  44. [44]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  45. [45]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  46. [46]
    Medium Babuk February 2021

    Sebdraven. (2021, February 8). Babuk is distributed packed. Retrieved August 11, 2021.

    Open source URL
  47. [47]
    Medium Babuk February 2021

    Sebdraven. (2021, February 8). Babuk is distributed packed. Retrieved August 11, 2021.

    Open source URL
  48. [48]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  49. [49]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  50. [50]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  51. [51]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  52. [52]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  53. [53]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  54. [54]
    Trend Micro Ransomware February 2021

    Centero, R. et al. (2021, February 5). New in Ransomware: Seth-Locker, Babuk Locker, Maoloa, TeslaCrypt, and CobraLocker. Retrieved August 11, 2021.

    Open source URL
  55. [55]
    Trend Micro Ransomware February 2021

    Centero, R. et al. (2021, February 5). New in Ransomware: Seth-Locker, Babuk Locker, Maoloa, TeslaCrypt, and CobraLocker. Retrieved August 11, 2021.

    Open source URL
  56. [56]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  57. [57]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  58. [58]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  59. [59]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  60. [60]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  61. [61]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  62. [62]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  63. [63]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  64. [64]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  65. [65]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  66. [66]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  67. [67]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  68. [68]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  69. [69]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  70. [70]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  71. [71]
    Sogeti CERT ESEC Babuk March 2021

    Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  72. [72]
    Trend Micro Ransomware February 2021

    Centero, R. et al. (2021, February 5). New in Ransomware: Seth-Locker, Babuk Locker, Maoloa, TeslaCrypt, and CobraLocker. Retrieved August 11, 2021.

    Open source URL
  73. [73]
    Trend Micro Ransomware February 2021

    Centero, R. et al. (2021, February 5). New in Ransomware: Seth-Locker, Babuk Locker, Maoloa, TeslaCrypt, and CobraLocker. Retrieved August 11, 2021.

    Open source URL
  74. [74]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  75. [75]
    McAfee Babuk February 2021

    Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

    Open source URL
  76. [76]
    Trend Micro Ransomware February 2021

    Centero, R. et al. (2021, February 5). New in Ransomware: Seth-Locker, Babuk Locker, Maoloa, TeslaCrypt, and CobraLocker. Retrieved August 11, 2021.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.