lilith
Lilith is a C/C++-based double-extortion ransomware that emerged in July 2022, targeting 64-bit Windows systems and sharing code with the Babuk ransomware family, with its first confirmed victim being a large South American construction firm.
Lilith is a double-extortion ransomware group from 2022 based on Babuk code.
Lilith is a C/C++-based double-extortion ransomware group that emerged in July 2022, sharing code similarities with the Babuk ransomware family. It primarily targets 64-bit Windows systems, with its first confirmed victim being a large South American construction firm. Key TTPs include file encryption accompanied by data theft for double-extortion, and the use of encryptor tools likely derived from Babuk code. Defenders should focus on anomalies in 64-bit Windows environments, Babuk-associated IOCs, and signs of data exfiltration preceding encryption.
Lilith is a C/C++-based double-extortion ransomware that emerged in July 2022, targeting 64-bit Windows systems and sharing code with the Babuk ransomware family, with its first confirmed victim being a large South American construction firm.
The Lilith ransomware group emerged in July 2022 and primarily targets 64-bit Windows systems.
Key TTPs include file encryption accompanied by data theft for double-extortion and the use of encryptor tools sharing code similarities with the Babuk ransomware family.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.