{"id":45089,"date":"2021-06-28T15:45:37","date_gmt":"2021-06-28T12:45:37","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=45089"},"modified":"2025-08-31T20:03:50","modified_gmt":"2025-08-31T17:03:50","slug":"babuk-locker-ransomware-design-template-leaked-online","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/babuk-locker-ransomware-design-template-leaked-online\/","title":{"rendered":"Babuk Locker ransomware design template leaked online"},"content":{"rendered":"<p>Unknown actors posted online an archive containing a Babuk Locker ransomware design template. Security researcher Kevin Beaumont drew attention to it.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">Ransomware leak time \u2014 Babuk\u2019s builder. Used for making Babuk payloads and decryption.<\/p>\n<p>builder.exe foldername, e.g. builder.exe victim will spit out payloads for:<\/p>\n<p>Windows, VMware ESXi, network attached storage x86 and ARM.<\/p>\n<p>note.txt must contain ransom.<a href=\"https:\/\/t.co\/K3J3zr1XBv\">https:\/\/t.co\/K3J3zr1XBv<\/a> <a href=\"https:\/\/t.co\/1bl7oc0TvO\">pic.twitter.com\/1bl7oc0TvO<\/a><\/p>\n<p>\u2014 Kevin Beaumont (@GossiTheDog) <a href=\"https:\/\/twitter.com\/GossiTheDog\/status\/1409117153182224386?ref_src=twsrc%5Etfw\">June 27, 2021<\/a><\/p>\n<\/blockquote>\n<p><script async=\"\" src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>According to him, the builder enables creating a custom variant of the malware to encrypt files on Windows systems, in network-attached storage (NAS) and on VMware ESXi servers.<\/p>\n<div id=\"attachment_140476\" style=\"width: 1152px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-140476\" class=\"size-full wp-image-140476\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/Babuk-leak-files.png\" alt=\"\u0428\u0430\u0431\u043b\u043e\u043d \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044f Babuk Locker \u043f\u043e\u043f\u0430\u043b \u0432 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f\" width=\"1142\" height=\"508\" srcset=\"https:\/\/forklog.com\/wp-content\/uploads\/Babuk-leak-files.png 1142w, https:\/\/forklog.com\/wp-content\/uploads\/Babuk-leak-files-300x133.png 300w, https:\/\/forklog.com\/wp-content\/uploads\/Babuk-leak-files-1024x456.png 1024w, https:\/\/forklog.com\/wp-content\/uploads\/Babuk-leak-files-768x342.png 768w\" sizes=\"auto, (max-width: 1142px) 100vw, 1142px\" \/><\/p>\n<p id=\"caption-attachment-140476\" class=\"wp-caption-text\">Data: The Record.<\/p>\n<\/div>\n<div id=\"attachment_140477\" style=\"width: 1130px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-140477\" class=\"size-full wp-image-140477\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/Babuk-leak-decrypted.png\" alt=\"\u0428\u0430\u0431\u043b\u043e\u043d \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0432\u044b\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044f Babuk Locker \u043f\u043e\u043f\u0430\u043b \u0432 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f\" width=\"1120\" height=\"604\" srcset=\"https:\/\/forklog.com\/wp-content\/uploads\/Babuk-leak-decrypted.png 1120w, https:\/\/forklog.com\/wp-content\/uploads\/Babuk-leak-decrypted-300x162.png 300w, https:\/\/forklog.com\/wp-content\/uploads\/Babuk-leak-decrypted-1024x552.png 1024w, https:\/\/forklog.com\/wp-content\/uploads\/Babuk-leak-decrypted-768x414.png 768w\" sizes=\"auto, (max-width: 1120px) 100vw, 1120px\" \/><\/p>\n<p id=\"caption-attachment-140477\" class=\"wp-caption-text\">Data: The Record.<\/p>\n<\/div>\n<p>At the time of writing it is unclear who published the archive publicly. The leak could have resulted from an unsuccessful transaction when the Babuk Locker developers tried to sell the builder to a third party, or it could have been posted deliberately by competitors or white-hat hackers.<\/p>\n<p>As reported earlier, the Babuk Locker group began operations in January 2021 and has already affected several major companies, including the Houston Rockets basketball club and the Spanish electronics retailer Phone House.<\/p>\n<p>In March, they stole <a href=\"https:\/\/forklog.com\/en\/news\/espionage-against-uyghurs-on-facebook-ransomware-attacks-and-other-cybersecurity-news\">more than 700 GB of data from the American military contractor<\/a> PDI Group.<\/p>\n<p>In April, the ransomware operators <a href=\"https:\/\/forklog.com\/en\/news\/hackers-threaten-to-expose-informants-for-washington-dc-police\">attacked the department of the U.S. capital police<\/a>, stealing 250 GB of data. They demanded a ransom, threatening to reveal informants in law enforcement.<\/p>\n<p>In May, hackers published online 22 files containing personal data of officers of the police department. According to media reports, this happened after <a href=\"https:\/\/forklog.com\/en\/news\/media-u-s-police-data-leaked-online-after-refusal-to-pay-4-million-in-bitcoins\">negotiations over the ransom amount allegedly reached an impasse<\/a>.<\/p>\n<p>Later the extortionists announced they were ceasing operations. They renamed their site to Payload.bin, which began functioning as a host for publishing data of victims of other ransomware operators.<\/p>\n<p>Subscribe to ForkLog news on Telegram: <a href=\"https:\/\/t.me\/forklogfeed\" target=\"_blank\" rel=\"nofollow noopener\">ForkLog Feed<\/a> \u2014 the full news stream, <a href=\"https:\/\/telegram.me\/forklog\" target=\"_blank\" rel=\"nofollow noopener\">ForkLog<\/a> \u2014 the most important news, infographics and opinions.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Unknown actors posted online an archive containing a Babuk Locker ransomware design template. Security researcher Kevin Beaumont drew attention to it.<\/p>\n","protected":false},"author":1,"featured_media":45090,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1154,1419],"class_list":["post-45089","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-crimes","tag-source-code"],"aioseo_notices":[],"amp_enabled":true,"views":"14","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/45089","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=45089"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/45089\/revisions"}],"predecessor-version":[{"id":45091,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/45089\/revisions\/45091"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/45090"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=45089"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=45089"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=45089"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}