logo

The old way: BabLock, new ransomware quietly cruising around Europe, Middle East, and Asia

ID: cb303416-5a61-5571-975a-22ddb7262ed6

STIX ID: report--cb303416-5a61-5571-975a-22ddb7262ed6

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2023-04-04

Date Updated: 2026-04-27

...
...

The report details Group-IB's investigation of the BabLock ransomware, a sophisticated multi-platform (Windows/Linux/ESXi) family used in targeted post‑holiday attacks since mid‑2022; attackers gained initial access via Zimbra RCE (CVE-2022-41352), moved laterally with RDP/Cobalt Strike and GPO deployment, employed DLL side‑loading, anti‑analysis techniques, and encrypted files across hosts and ESXi VMs while leaving extensive IOCs and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.