{"schema":"aeternae-malware-metadata/v1","generated_at":"2026-10-08T08:40:00+00:00","total_matching":1,"page":1,"page_size":200,"records":[{"id":"3da18083fc8eff2544aa256a7c6bed0caf1b96cbbfa3d9a65cf06049668701cb","kind":"reference","title":"Babuk - S0638","family":"Babuk - S0638","category":"Malware intelligence","summary":"Name of ATT&CK software | [Babuk](https://attack.mitre.org/software/S0638) is a Ransomware-as-a-service (RaaS) malware that has been used since at least 2021. The operators of [Babuk](https://attack.mitre.org/software/S0638) employ a \"Big Game Hunting\" approach to targeting major enterprises and operate a leak site to post stolen data as part of their extortion scheme.(Citation: Sogeti CERT ESEC B","first_seen":1692676833,"last_seen":1692676833,"created_at":1791438150,"updated_at":1791438150,"source_count":1,"data":{"context":"2023/05/ra-group-ransomware.json","tags":["misp:galaxy-name=\"Malware\"","misp:galaxy-type=\"mitre-malware\"","misp-galaxy:mitre-malware=\"Babuk - S0638\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2023/05/ra-group-ransomware.json"],"filenames":[],"features":[],"related_cves":[],"labels":["Babuk - S0638"]},"observations":[{"source_id":"talos_ioc","source_url":"https://github.com/Cisco-Talos/IOCs/blob/main/2023/05/ra-group-ransomware.json","source_label":"Babuk - S0638","evidence_class":"provider_reported","confidence":null,"observed_at":1692676833,"fetched_at":1791438150,"data":{"context":"2023/05/ra-group-ransomware.json","tags":["misp:galaxy-name=\"Malware\"","misp:galaxy-type=\"mitre-malware\"","misp-galaxy:mitre-malware=\"Babuk - S0638\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2023/05/ra-group-ransomware.json"],"family":"Babuk - S0638"}}],"indicators":[]}]}