logo

Albabat 2.0.0 Decoded: A Config-Driven Design

ID: 3de90e64-1929-5f3b-a70a-8a98b3493091

STIX ID: report--3de90e64-1929-5f3b-a70a-8a98b3493091

Feed Name: Pulsedive Blog

Threat Score
78/100

Date Published: 2025-05-16

Date Updated: 2026-07-16

Author: Pulsedive Threat Research

...
...

**Albabat ransomware analysis:** This report analyzes a Rust-based Albabat sample (v2.0.0), documents how it retrieves a GitHub-hosted config to control encryption, exfiltrates system metadata to a Postgres endpoint, disables Windows defenses, deletes recovery artifacts, terminates key processes, and drops an HTML ransom note (includes IOCs such as hashes, RSA public key, BTC address, and targeted file/process lists).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.