According to “The Record,” the tool (builder) used to create the “Babuk Locker” ransomware has now leaked online and is available for anyone interested to obtain a copy for free. Malicious actors could therefore use it to create their own version of the popular ransomware.
The Babuk Locker operators stopped their “operation” in late April, after the attack on the Washington Police Department. Experts believe that the gang’s decision to abandon the ransomware practice could be the result of an operational error – it seems that it was a bad idea to threaten the US police department because of the information it handles.
Read also: The Babuk ransomware gang stops its "operation"!
The ransomware gang hit the Washington, D.C. Metropolitan Police Department, encrypted its files, and then demanded a $4 million ransom. The Babuk ransomware gang claimed at the time that it stole 250GB of files, including personal data of police officers and informants.

In late May, the ransomware operators renamed their data leak site to Payload.bin and began offering other gangs the opportunity to use it to leak the data they steal from their victims.
The Record's experts obtained and analyzed a copy of the builder and confirmed that it allows the creation of customized versions of Babuk Locker that can be used to encrypt files located on Windows systems, ARM-based network attached storage (NAS) devices, and VMWare ESXi servers.
See also: Washington Metropolitan Police Department: Officer data leaked

So far, it is unclear whether Babuk's gang tried to sell the ransomware builder to a third party, in a deal that went wrong, or whether the builder was leaked by an adversary or white-hat security researcher.
The available builder also creates decryptors that could be used by victims to recover encrypted files.
The builder was uploaded to the malware scanning service “VirusTotal” and discovered by renowned cybersecurity expert Kevin Beaumont.

Suggestion: Ransomware groups use virtual machines to "cover" their attacks
Recently, another ransomware builder was leaked online – the source code for the Paradise Ransomware was released on the hacking forum “XSS”, allowing malicious actors to develop their own customized ransomware “operation”. The news of the source code’s availability was first reported by Tom Malka, senior threat analyst at security firm “Security”, to BleepingComputer and “The Record”.
The availability of these builders on the Internet is concerning, given that other malicious gangs could enter the threat landscape using their own ransomware to target organizations around the world.
Babuk's "operation" lasted a short time, but he managed to achieve notable success, with widely publicized incidents such as the attacks on the Washington Metropolitan Police, the Houston Rockets, and Yamabiko.
