Femwar02 is an emerging pro-Russian ransomware group targeting the education sector with Bablock ransomware since 2026.
Analyst brief
Femwar02 is an emerging pro-Russian ransomware group that surfaced in early 2026. It primarily targets the education sector, as demonstrated by a major attack on Italy's Sapienza University of Rome that resulted in a full network shutdown. The group leverages the Bablock ransomware, which employs advanced TTPs including fast hybrid encryption, partial file encryption, and domain-wide propagation via Group Policy on Windows Domain Controllers. Defenders should focus on monitoring for anomalous Group Policy changes on Domain Controllers, evasion via direct system calls, and the rapid encryption behavior characteristic of Bablock, which shares code similarities with LockBit 2.0.
Femwar02
unknown
Femwar02 is a previously unknown pro-Russian ransomware threat actor that emerged in early 2026, linked to a major cyberattack on Italy's Sapienza University of Rome in February 2026, which caused a full network shutdown and operational disruptions. The group deploys Bablock (also known as Rorschach), a next-generation ransomware strain first identified in 2023 that features fast hybrid encryption (curve25519 and hc-128), partial file encryption for speed, direct system calls to evade detection, and domain-wide propagation via Group Policy on Windows Domain Controllers. Bablock shares code similarities with LockBit 2.0 but incorporates elements from other families like Babuk and DarkSide, often delivered via encrypted payloads, DLL sideloading with tools like DarkLoader, and exploits such as those in Zimbra or phishing. Notably, the malware skips encrypting files written in Russian, reinforcing its pro-Russian alignment, with no prior attributions or campaigns documented before the Sapienza incident.
Which sector does the Femwar02 group primarily target?+
Femwar02 primarily targets the education sector, as demonstrated by an attack on Italy's Sapienza University.
What are the key features of the Bablock ransomware used by Femwar02?+
Bablock features fast hybrid encryption, partial file encryption, evasion via direct system calls, and domain-wide propagation via Group Policy on Windows Domain Controllers.