ATT&CKReferencesSogeti CERT ESEC Babuk March 2021

Sogeti CERT ESEC Babuk March 2021

Sogeti. (2021, March). Babuk Ransomware. Retrieved August 11, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareBabuk

Versions of Babuk have been packed.

T1057
Process Discovery
MalwareBabuk

Babuk has the ability to check running processes on a targeted system.

T1059.003
Windows Command Shell
MalwareBabuk

Babuk has the ability to use the command line to control execution on compromised hosts.

T1106
Native API
MalwareBabuk

Babuk can use multiple Windows API calls for actions on compromised hosts including discovery and execution.

T1135
Network Share Discovery
MalwareBabuk

Babuk has the ability to enumerate network shares.

T1140
Deobfuscate/Decode Files or Information
MalwareBabuk

Babuk has the ability to unpack itself into memory using XOR.

T1486
Data Encrypted for Impact
MalwareBabuk

Babuk can use ChaCha8 and ECDH to encrypt data.

T1489
Service Stop
MalwareBabuk

Babuk can stop specific services related to backups.

T1490
Inhibit System Recovery
MalwareBabuk

Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet.

T1685
Disable or Modify Tools
MalwareBabuk

Babuk can stop anti-virus services on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.