After a few months of activity, the Babuk ransomware operators posted a short message titled “Hello World 2” on their data leak site on April 29 , stating that they would be ending the extortion operation after achieving their goal. Other ransomware gangs have chosen to release decryption keys or even refund the ransoms paid by their victims before shutting down their operations – something the Babuk gang does not intend to do.
However, the gang wanted to leave some «legacy». Thus, the source code for the Babuk file-encrypting malware will be available to the public once the operation is terminated.
Read also: Babuk: The new ransomware family targeting corporate networks!

It is worth noting that the message published by the gang was modified and was briefly visible only on the main page of its site. In a version captured by Dmitry Smilyanets of Recorded Future, the hackers mentioned that the PD was their latest target, a clear reference to their latest victim, the Metropolitan Police Department of Washington, DC (MPD). As can be seen in the screenshot below, “PD” was also in the title.

Another version of the message, captured by BleepingComputer, did not mention the PD at all, potentially suggesting that the gang is preparing to shut down operations in the near future after breaching a different victim. The hackers said they stole 250GB of data before encrypting MPD computers, and posted screenshots of files stolen in the attack to prove their claims.
See also: The Washington DC Metropolitan Police Department was hacked!
Babuk ransomware emerged on the threat landscape at the beginning of the year. Since its inception, it has targeted victims around the world and demanded ransoms ranging from $60,000 to $85,000 in Bitcoin.
According to BleepingComputer, each executable from this ransomware strain was customized to each victim with a hardcoded extension, while the hackers left a ransom note and a Tor URL, where the victims communicated with the gang to negotiate the ransom.
Initially, the operators of the Babuk ransomware stated that they would not target various types of organizations in the healthcare, non-profit, education, and small and medium-sized businesses sectors, with some exceptions. In a later post on their data leak site, the hackers stated that their attacks had been ongoing since at least mid-October 2020, while removing the aforementioned exceptions.
Suggestion: Coveware: Ransomware victims' ransom payments have increased

It is unclear how many organizations fell victim to the Babuk ransomware operation, but the gang's data leak site listed more than a dozen companies as of April 29 that had not paid the ransom.
Other victims may be available on hidden pages, as is the case with the Metropolitan Police Department, which is no longer listed on the main page, but still exists on the data leak site.
It is worth noting that some ransomware gangs have previously announced that they would cease operations, but have returned under a different name. Also, members of a ransomware gang that ceases its activity may be integrated into a new operation – for example, Maze ceased its activity and its members were integrated into the Egregor ransomware operation.
Information source: bleepingcomputer.com
