Dissecting and Detecting Babuk ransomware Cryptography
ID: 01fdd3dc-737c-584a-8033-d7a059f5023f
STIX ID: report--01fdd3dc-737c-584a-8033-d7a059f5023f
Feed Name: Kudelski Security
This report analyzes the Babuk ransomware family, detailing three platform-specific variants (Windows, ESXi, NAS), the use of Curve25519 ECDH to generate per-file shared secrets and fast stream ciphers (Sosemanuk, HC-128, ChaCha variants) for encryption, noted exploitation vectors including OpenSLP and several Microsoft Exchange CVEs plus phishing and RDP, the impact of the public source-code leak enabling clones, and released Yara rules to detect the cryptographic implementations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
