The old way: BabLock, new ransomware quietly cruising around Europe, Middle East, and Asia
ID: cb303416-5a61-5571-975a-22ddb7262ed6
STIX ID: report--cb303416-5a61-5571-975a-22ddb7262ed6
Feed Name: Group-IB Blog
Threat Score
The report details Group-IB's investigation of the BabLock ransomware, a sophisticated multi-platform (Windows/Linux/ESXi) family used in targeted post‑holiday attacks since mid‑2022; attackers gained initial access via Zimbra RCE (CVE-2022-41352), moved laterally with RDP/Cobalt Strike and GPO deployment, employed DLL side‑loading, anti‑analysis techniques, and encrypted files across hosts and ESXi VMs while leaving extensive IOCs and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
