A ransomware strain deployed by Evil Corp impersonating the Babuk gang to evade OFAC sanctions.
Analyst brief
PayloadBIN is a ransomware strain deployed in 2021 by the criminal group Evil Corp as a rebrand of their WastedLocker/Hades/Phoenix lineage. It specifically impersonates the Babuk gang’s branding to evade US Treasury OFAC sanctions rather than operating as an independent entity. Key TTPs include file encryption, ransom demands, and deception tactics to obscure attribution. Defenders should monitor for indicators linked to Evil Corp, encryption patterns, and suspicious activity falsely attributed to the Babuk name.
payloadbin
crime
PayloadBIN is a ransomware strain deployed in 2021 by Evil Corp as a rebranding of their WastedLocker/Hades/Phoenix lineage, specifically designed to evade US Treasury OFAC sanctions by impersonating the unrelated Babuk gang's rebrand rather than operating as an independent group.