Babuk Locker 2.0, also known as Bjorka or SkyWave, after failing to make any profit from selling public databases on forums, decided to impersonate Babuk Ransomware group. He launched a blog where he claimed multiple public breaches from BreachForums as ransomware attacks
Uses ChaCha8 and ECDH encryption
Deletes shadow copies
Terminates services and processes
Targets ESXi hypervisors via SSH