logo

And that's a wrap for Babuk Tortilla ransomware as free decryptor released

ID: d5de2758-8a93-5d49-85bb-07f7d428a639

STIX ID: report--d5de2758-8a93-5d49-85bb-07f7d428a639

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2024-01-09

Date Updated: 2026-04-26

Author: Connor Jones

...
...

**Executive summary:** Security researchers (Cisco Talos and Avast) and Dutch authorities obtained an updated decryptor for the Babuk 'Tortilla' ransomware variant after the arrest of an operator; because the variant reused a single private key across victims, the decryptor can recover files for all Tortilla victims and is being distributed via Avast and the No More Ransom project. The report also notes Tortilla's technical characteristics (AES-256 + ChaCha8, Monero payments), its initial ProxyShell targeting and unpacking chain hosted on a pastebin clone, and that the decryptor was extracted and optimized rather than releasing untrusted code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.