Albabat Ransomware Targets Windows, Linux, and macOS Using GitHub Infrastructure (Campaign)
ID: 9fb200f4-cbfa-5262-ad1f-a42c0598ebc9
STIX ID: report--9fb200f4-cbfa-5262-ad1f-a42c0598ebc9
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-03-21
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers identified new Albabat ransomware variants (v2.0.0 and v2.5) that extend operations from Windows to Linux and macOS, retrieve dynamic configuration from a private GitHub repository via the REST API, encrypt numerous file types while excluding system directories, terminate processes to enable encryption, and exfiltrate/collect system and user data to a Supabase-hosted PostgreSQL instance; operators maintain development logs and added cryptocurrency wallet addresses in v2.5.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
