In late June , the “Babuk Locker” ransomware builder was leaked online , which allowed malicious actors to use it to create their own version of the ransomware.
The operators of Babuk Locker ceased operations in late Aprilafter the attack on the Police Department . Experts believe that the group's decision to withdraw from ransomware could be the result of an operational error, since it was not a good idea to threaten the US police department due to the information it handles.
The ransomware gang broke into the Metropolitan Police Department in Washington, DC, encrypted its files, and then demanded a $4 million ransom.
Read also: Babuk Locker: Ransomware builder leaked online

In late May, the Babuk Locker operators renamed the ransomware leak website Payload.bin and began offering the opportunity for other cybercrime gangs to use it to leak the data they steal from their respective victims.
The builder allows for the creation of customized versions of the Babuk Locker ransomware that work for Windows, ARM-based network storage attached (NAS) devices, and VMWare ESXi servers.
See also: US: Accuses China of committing ransomware attacks

Now the hacking gang appears to have been hit by a ransomware attack, with unknown individuals flooding its forum, a dark web ransomware forum called “RAMP,” with gay porn images and GIFs. Those behind the attack also demanded $5,000,000 in Bitcoin, but Babuk’s gang refused to pay the ransom.
Suggestion: Kaseya REvil ransomware: Company obtained decryption key
The analysis of the Bitcoin address used by the malicious actors to demand the ransom payment remains “empty.” According to “The Record,” as a result of the attack, Babuk operators were forced to empty their forum at least twice. Even though Babuk operators did this, the attackers managed to fill the gang’s site with pornographic images and GIFs.
Information source: securityaffairs.co
