Two business days into the New Year, a novel enterprise ransomware has emerged

security
(Image credit: Shutterstock / binarydesign)

A new ransomware strain has been discovered demanding thousands of dollars from its victims. Babuk Locker is a ransomware operation that only began in 2021 but which has already acquired a small list of victims from various countries.

“Since this is the first detection of this malware in the wild, it’s not surprising that Babuk is not obfuscated at all,” Chuong Dong, a security researcher that has analyzed the new strain, explained. “Overall, it’s a pretty standard ransomware that utilizes some of the new techniques we see such as multi-threading encryption as well as abusing the Windows Restart Manager similar to Conti and REvil.

Unfortunately, although Babuk shows evidence that its creators possess pretty amateurish coding skills, the encryption scheme employed is pretty robust, meaning victims will struggle to recover their files without paying the ransom fee. So far, ransom demands have ranged from $60,000 to $85,000.

A new ransomware risk

Once the ransomware has been activated, it terminates the Windows processes that prevent encryption before terminating a host of other programs on the victim's device. A ransom note is also created, including instructions for how to negotiate with the ransomware operators. Some victims have also confirmed that the malware creators have shared sensitive information with them as proof that they have stolen files in their possession.

In addition, Babuk Locker also threatens to leak stolen information on a hacker forum in a further effort to extort money from its victims. So far, the victims of the ransomware are a pretty varied bunch, including an elevator company, a medical testing products manufacturer, and an air conditioning company.

If businesses were hoping that 2021 might offer them some respite from ransomware attacks, the appearance of Babuk Locker suggests otherwise. Last year, there was a host of high-profile ransomware attacks, including ones targeting Foxconn and Kmart.

Via BleepingComputer

TOPICS
Barclay Ballard

Barclay has been writing about technology for a decade, starting out as a freelancer with ITProPortal covering everything from London’s start-up scene to comparisons of the best cloud storage services.  After that, he spent some time as the managing editor of an online outlet focusing on cloud computing, furthering his interest in virtualization, Big Data, and the Internet of Things. 

Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does
iPhone 13 mini
The iPhone mini won't be returning, according to rumors – and you think that's a mistake