BabyDuck is a nascent ransomware group that emerged around September 2021. This group is distinct from the well-known Babuk group, though its ransomware strain is based on Babuk ransomware. BabyDuck focuses on financial gain through ransomware deployments and employs double extortion tactics. It has gained attention for its aggressive expansion, rapid attack cycles, and the effective use of encryption algorithms and data leak threats.
Tecnicas MITRE
T1566.001, T1070.004, T1486, T1027
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
United Arab EmiratesAustraliaBrazilCanadaSwitzerlandChileChinaColombiaGermanySpain
Sectores objetivo (SOCRadar)
Construction of BuildingsFood ManufacturingSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir TransportationManufacturingConstruction