Babuk — Ransomware Profile
Babuk was a ransomware-as-a-service operation that surfaced at the end of 2020, according to Malwarebytes; Malpedia records the same family under the additional names Babyk and Vasa Locker. Its operators combined file encryption with theft and leak-site extortion, and the group drew wide attention after breaching the Washington, D.C. Metropolitan Police Department in April 2021, publishing stolen internal files including personal data on MPD officers, as reported by Malwarebytes and StateScoop. That incident reportedly split the group internally, and per Huntress and Malwarebytes the operators announced a shift away from encryption and then a shutdown of the ransomware operation; the ransomware builder itself was found leaked on VirusTotal in June 2021, which Malwarebytes described as a muddled retirement, and a purported member subsequently posted the group's full Windows, ESXi, and NAS source code to a Russian-speaking forum in September 2021, per BleepingComputer. That leak allowed other, unrelated crews to build their own lockers from Babuk's code, but the original operation itself did not resume. This entry covers only that 2020-2021 operation; a separate outfit calling itself "Babuk2" or "Babuk-Bjorka," run by an actor using the handle Bjorka, appeared in 2025 and is, per Halcyon's research, not a direct continuation of the original group but a scheme that reuses victim data from breaches claimed by other ransomware groups (including RansomHub, FunkSec, and LockBit) to fabricate fresh extortion claims under the Babuk name. Vendors describe Babuk's membership as Russian-speaking, but no reviewed source ties the original operation to a specific state or country with confidence, so no country code is assigned here.Also tracked as
Babuk Locker, Babyk, Vasa Locker
IntelFusions coverage (4)
- Ransomware crew now takes orders over a chat app 2026-09-04 · Ransomware
- Russian factories hit by new ransomware built for Windows and ESXi 2026-07-30 · Ransomware
- New Babuk Based Ransomware Hits Windows, VMware, and NAS Systems 2026-06-05 · Ransomware
- From Conti Code to ESXi Servers: SentinelOne Decodes Akira's Cross-Platform Ransomware Evolution 2026-02-16 · Ransomware