BABUK-RANSOMSWARE

BABUK-RANSOMSWAREBabuk Ransomsware

Description

Since this is the first detection of this malware in the wild, it’s not surprising that Babuk is not obsfuscated at all. Overall, it’s a pretty standard ransomware that utilizes some of the new techniques we see such as multi-threading encryption as well as abusing the Windows Restart Manager similar to Conti and REvil. For encrypting scheme, Babuk uses its own implementation of SHA256 hashing, ChaCha8 encryption, and Elliptic-curve Diffie–Hellman (ECDH) key generation and exchange algorithm to protect its keys and encrypt files. Like many ransomware that came before, it also has the ability to spread its encryption through enumerating the available network resources.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
Babuk-Locker
Software
Babuk
Software
Babax
Software
crypt ransomware
Software
BKRansomware
Software
MaktubLocker
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.