BlueSky is a financially motivated, Russian-origin ransomware group active from mid-2022 to early 2023.
Analyst brief
BlueSky is a financially motivated ransomware group active from mid-2022 to early 2023. The group primarily targets Windows hosts. They utilize multi-threaded ChaCha20/Curve25519 encryption for fast file locking, with code sharing significant overlap with Conti v2/v3 and Babuk ransomware families. Defenders should implement detection rules based on Conti/Babuk TTPs against this group, attributed with high confidence to Russian-origin threat actors, and prepare for the rapid impact of ChaCha20 encryption.
bluesky
crime
BlueSky is a financially motivated ransomware group active from mid-2022 into early 2023, using multi-threaded ChaCha20/Curve25519 encryption for fast file locking on Windows hosts, with code sharing significant overlap with Conti v2/v3 and Babuk, attributed with high confidence to Russian-origin threat actors.