Albabat 2.0.0 Decoded: A Config-Driven Design
ID: 3de90e64-1929-5f3b-a70a-8a98b3493091
STIX ID: report--3de90e64-1929-5f3b-a70a-8a98b3493091
Feed Name: Pulsedive Blog
Threat Score
**Albabat ransomware analysis:** This report analyzes a Rust-based Albabat sample (v2.0.0), documents how it retrieves a GitHub-hosted config to control encryption, exfiltrates system metadata to a Postgres endpoint, disables Windows defenses, deletes recovery artifacts, terminates key processes, and drops an HTML ransom note (includes IOCs such as hashes, RSA public key, BTC address, and targeted file/process lists).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
