Babuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most used compiled versions, but ESX and a 32bit old PE executable were observed over time. as well It uses an Elliptic Curve Algorithm (Montgomery Algorithm) to build the encryption keys.
Uses ChaCha8 and ECDH encryption
Deletes shadow copies
Terminates services and processes
Targets ESXi hypervisors via SSH