{"id":2597,"date":"2021-05-04T21:12:40","date_gmt":"2021-05-05T02:12:40","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2597"},"modified":"2021-05-04T21:12:40","modified_gmt":"2021-05-05T02:12:40","slug":"babuk-locker-the-first-ransomware-of-2021","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/","title":{"rendered":"Babuk Locker &#8211; The First Ransomware of 2021"},"content":{"rendered":"\n<p>It&#8217;s a new year and with it comes a new ransomware called Babuk Locker that targets corporate victims in human-made attacks. Babuk Locker is a new ransomware operation launched in early 2021 and has since accumulated a small list of victims from around the world.<\/p>\n\n\n\n<p>It falls within what we know as RaaS (Ransomware-as-a-Service), where different actors participate in the creation of the code and its subsequent distribution. Attackers will usually ask for ransom, but they will also threaten to publish the content. Each Babuk Locker executable analyzed by BleepingComputer has been customized by victim to contain an encoded extension, ransom note, and Tor victim URL. According to security researcher Chuong Dong, who also analyzed the new ransomware, the encryption for this threat is amateurish, but includes strong encryption that prevents victims from recovering their files for free.<\/p>\n\n\n\n<p>This, despite the fact that this threat is new, has already had a great impact: in just a few months, it persecuted at least five large companies such as: health care services, banking and financial institutions, hosting and transportation, managing to obtain $ 85,000 after one of his victims would come to the rescue. We don&#8217;t know which company paid, but we do know of a public confirmation from a target company: Serco, an outsourcing company, confirmed that it had been targeted with a double-extortion ransomware attack in late January. That&#8217;s an attack in which ransomware operators not only lock files, but also steal data and threaten to leak it if the ransom is not paid.<\/p>\n\n\n\n<p>Babuk uses its own encryption scheme. It uses ChaCha8, a variant of Salsa20, stream encryption used for example in the REvil malware (Sodinokibi), as well as elliptic curve cryptography (ECDH). During encryption it will launch multiple threads to encrypt the disks, varying the load of the threads according to the size of the disk.<\/p>\n\n\n\n<p>Also check:<br><a href=\"https:\/\/truxgoservers.com\/blog\/revil-is-a-dangerous-ransomware\/\">REvil is a dangerous ransomware<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/egregor-is-a-ransomware-that-has-been-very-active\/\">Egregor is a ransomware that has been very active<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s a new year and with it comes a new ransomware called Babuk Locker that targets corporate victims in human-made attacks. Babuk Locker is a new ransomware operation launched in early 2021 and has since accumulated a small list of victims from around the world. It falls within what we know as RaaS (Ransomware-as-a-Service), where [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2598,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2597","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Babuk Locker - The First Ransomware of 2021 - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Unfortunately, ransomware is always improving and today we will see one of the new ransomware called Babuk Locker........\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Babuk Locker - The First Ransomware of 2021 - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Unfortunately, ransomware is always improving and today we will see one of the new ransomware called Babuk Locker........\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-05T02:12:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Babuk.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/babuk-locker-the-first-ransomware-of-2021\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/babuk-locker-the-first-ransomware-of-2021\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Babuk Locker &#8211; The First Ransomware of 2021\",\"datePublished\":\"2021-05-05T02:12:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/babuk-locker-the-first-ransomware-of-2021\\\/\"},\"wordCount\":331,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/babuk-locker-the-first-ransomware-of-2021\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Babuk.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/babuk-locker-the-first-ransomware-of-2021\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/babuk-locker-the-first-ransomware-of-2021\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/babuk-locker-the-first-ransomware-of-2021\\\/\",\"name\":\"Babuk Locker - The First Ransomware of 2021 - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/babuk-locker-the-first-ransomware-of-2021\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/babuk-locker-the-first-ransomware-of-2021\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Babuk.jpg\",\"datePublished\":\"2021-05-05T02:12:40+00:00\",\"description\":\"Unfortunately, ransomware is always improving and today we will see one of the new ransomware called Babuk Locker........\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/babuk-locker-the-first-ransomware-of-2021\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/babuk-locker-the-first-ransomware-of-2021\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/babuk-locker-the-first-ransomware-of-2021\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Babuk.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Babuk.jpg\",\"width\":1200,\"height\":800},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/babuk-locker-the-first-ransomware-of-2021\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Babuk Locker &#8211; The First Ransomware of 2021\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Babuk Locker - The First Ransomware of 2021 - Truxgo Server Blog","description":"Unfortunately, ransomware is always improving and today we will see one of the new ransomware called Babuk Locker........","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/","og_locale":"es_MX","og_type":"article","og_title":"Babuk Locker - The First Ransomware of 2021 - Truxgo Server Blog","og_description":"Unfortunately, ransomware is always improving and today we will see one of the new ransomware called Babuk Locker........","og_url":"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-05-05T02:12:40+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Babuk.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Babuk Locker &#8211; The First Ransomware of 2021","datePublished":"2021-05-05T02:12:40+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/"},"wordCount":331,"commentCount":1,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Babuk.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/","url":"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/","name":"Babuk Locker - The First Ransomware of 2021 - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Babuk.jpg","datePublished":"2021-05-05T02:12:40+00:00","description":"Unfortunately, ransomware is always improving and today we will see one of the new ransomware called Babuk Locker........","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Babuk.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Babuk.jpg","width":1200,"height":800},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/babuk-locker-the-first-ransomware-of-2021\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Babuk Locker &#8211; The First Ransomware of 2021"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2597","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2597"}],"version-history":[{"count":3,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2597\/revisions"}],"predecessor-version":[{"id":3974,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2597\/revisions\/3974"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2598"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2597"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2597"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2597"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}