Buhti — Ransomware Profile
Buhti is a financially motivated ransomware operation first publicly documented by Palo Alto Networks Unit 42 in February 2023, initially as a Go-written strain aimed at Linux hosts. Symantec later assigned the operators the designation Blacktail after finding no link between Buhti and any existing cyber-crime group. Rather than writing its own encryptors, the crew deployed a barely-altered build derived from the leaked LockBit 3.0 ransomware against Windows machines and Babuk-derived payloads against Linux, appending a .buthi extension to encrypted files. A notable bespoke component is a Golang information stealer that collects documents, archives, presentations and audio/video files and packs them into a ZIP archive, giving the operation double-extortion leverage. Blacktail moved quickly on freshly disclosed vulnerabilities for initial access, weaponising Zoho ManageEngine (CVE-2022-47966), IBM Aspera Faspex (CVE-2022-47986) and PaperCut NG/MF (CVE-2023-27350). Kaspersky telemetry placed victim organisations across a dozen countries including the United States, United Kingdom, Germany, Spain, France, India and China.Also tracked as
Blacktail
Vendor research
- Buhti: New Ransomware Operation Relies on Repurposed Payloads Symantec Threat Hunter Team
- Threat Signal Report: Buhti Ransomware Fortinet FortiGuard Labs
- Organizations Worldwide Targeted in Rapidly Evolving Buhti Ransomware Operation SecurityWeek
- Buhti Ransomware Gang Switches Tactics, Utilizes Leaked LockBit and Babuk Code The Hacker News