ATT&CKReferencesMcAfee Babuk February 2021

McAfee Babuk February 2021

Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareBabuk

Babuk can enumerate all services running on a compromised host.

T1027.002
Software Packing
MalwareBabuk

Versions of Babuk have been packed.

T1049
System Network Connections Discovery
MalwareBabuk

Babuk can use “WNetOpenEnumW” and “WNetEnumResourceW” to enumerate files in network resources for encryption.

T1057
Process Discovery
MalwareBabuk

Babuk has the ability to check running processes on a targeted system.

T1059.003
Windows Command Shell
MalwareBabuk

Babuk has the ability to use the command line to control execution on compromised hosts.

T1083
File and Directory Discovery
MalwareBabuk

Babuk has the ability to enumerate files on a targeted system.

T1106
Native API
MalwareBabuk

Babuk can use multiple Windows API calls for actions on compromised hosts including discovery and execution.

T1486
Data Encrypted for Impact
MalwareBabuk

Babuk can use ChaCha8 and ECDH to encrypt data.

T1489
Service Stop
MalwareBabuk

Babuk can stop specific services related to backups.

T1490
Inhibit System Recovery
MalwareBabuk

Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet.

T1680
Local Storage Discovery
MalwareBabuk

Babuk can enumerate disk volumes, get disk information, and query service status.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.