Track Common Adversary Tasks Performed Using Babuk

 





To know more about it, you can go through my detailed document by clicking here








Overview

Babuk, a Ransomware-as-a-Service (RaaS) malware identified in 2021, employs a "Big Game Hunting" approach to target major enterprises and works as a leak site to post stolen data that can be used in their extortion scheme. However, it isn't considered as a sophisticated malware because of its many flaws like bugs and non-obfuscated file codes, but, it despite of these glitches, it has managed to corrupt many files beyond repair and published stolen data on the internet as well as the dark web.

How Does it Spreads?

Alike the other RaaS products, Babuk also uses same techniques to exploit a system, i.e.:
  • Email Phishing- They also uses emails to spread the malware to a victim's computer.

  • Common Vulnerabilities & Exposures (CVEs)- It can easily exploit various CVEs targeting the popular software. 

  • Remote Desktop Protocol (RDP)- The poorly protected RDP access may also result in the successful attacks of the threat actors. 

Prevention

The following methods may help in mitigating the cyber threat:
  • Always have ample protection like updated antivirus software, multi-factor authentication for all the system accounts, etc. 

  • Never open any suspicious emails or any links attached with them.

  • Regularly update your software while ensuring that all the vulnerabilities are patched up perfectly.









To know more about it, you can go through my detailed document by clicking here













Comments

Popular posts from this blog

Deployment (Part 3)

Deployment (Part 1)

Deployment (Part 2)