New Rook Ransomware Feeds Off the Code of Babuk
released on 2021-12-24 @ 11:25:34 AM
First noticed on VirusTotal on November 26th by researcher Zack Allen, Rook Ransomware initially attracted attention for the operators’ rather unorthodox self-introduction, which stated that “We desperately need a lot of money” and “We will stare at the internet”.
These odd pronouncements prompted some mirth on social media, but they were followed a few days later by more serious news. On November 30th, Rook claimed its first victim: a Kazkh financial institution from which the Rook operators had stolen 1123 GB of data, according to the gang’s victim website. Further victims have been claimed since then.
In this post, SentinelOne offers the first technical write up of the Rook ransomware family, covering both its main high-level features and its ties to the Babuk codebase.