logo

Payload ransomware hits Windows and ESXi with Babuk-style encryption

ID: febc3fee-395a-5c00-b364-4dc80150005c

STIX ID: report--febc3fee-395a-5c00-b364-4dc80150005c

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-03-17

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Payload is an emerging, high-impact ransomware operation active since at least February 2026 that combines Babuk-style cryptography (Curve25519 ECDH, ChaCha20) with aggressive anti-forensics, EDR/backup disruption, and a double-extortion leak site; it targets both Windows and VMware ESXi (VM disk encryption) and has claimed multiple mid-to-large victims across sectors including healthcare, real estate, energy, telecom, and agriculture.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.