Abyss Locker is a Babuk-derived double-extortion ransomware group targeting critical systems, including VMware ESXi.
Analyst brief
Abyss Locker is a cybercrime ransomware group active since March 2023, derived from the Babuk source code. Based on the provided data, it targets the Professional Services and Government & Defense sectors in Germany, while globally focusing on healthcare, manufacturing, finance, and technology. The group employs double-extortion tactics, encrypting Windows, Linux, and VMware ESXi systems. Defenders should prioritize vulnerability management on ESXi and Linux servers, enforce network segmentation, and monitor for IOCs associated with Babuk-derived ransomware variants.
abyss
crime
Abyss (also known as Abyss Locker) is a ransomware operation first identified in March 2023, derived from the Babuk source code, that targets Windows and Linux/VMware ESXi systems using double-extortion tactics across healthcare, manufacturing, finance, and technology sectors — predominantly in North America.
Which ransomware family's source code is Abyss Locker derived from?+
Abyss Locker is derived from the Babuk ransomware source code.
Which systems should defenders primarily focus on to protect against Abyss Locker?+
Defenders should prioritize vulnerability management on ESXi and Linux servers, enforce network segmentation, and monitor for IOCs associated with Babuk-derived ransomware variants.