logo

Ransomware Tracker (Entry #226): Bagli

ID: 4bf8524e-b0cf-5be8-9a32-58c737a13b3a

STIX ID: report--4bf8524e-b0cf-5be8-9a32-58c737a13b3a

Feed Name: WatchGuard Secplicity Blog

Threat Score
60/100

Date Published: 2025-03-08

Date Updated: 2026-05-01

Author: Ryan Estes

...
...

Bagli is a .NET wiper (pseudo-ransomware) that irreversibly overwrites files while dropping a ransom note (oxu.txt) demanding payment; the report notes Azerbaijani-language evidence and links to a forum user (ryukRans). Although Bagli is low sophistication, it served as the open-source foundation for the Chaos ransomware builder, which spawned many variants (most of which have decryptors except early Bagli-based versions).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.