Ransomware - Bagli

Bagli
Aliases
Bagli Wiper
Description

Bagli is commonly called Bagli Wiper because it doesn't actually encrypt files; it overrides the file's bytes with the Random() function (.NET). Therefore, it's technically not ransomware; it's pseudo-ransomware as a wiper. Although a ransom note—oxu.txt—is dropped that demands a ransom of $350 in Bitcoin, there is no possible way to recover files. The ransom note is in Azerbaijani, and the wiper's creator, ryukRans, spoke primarily Russian on XSS.is (a hacking forum). Therefore, we denoted the user as Azerbaijani with low-to-moderate confidence.

All in all, Bagli isn't a sophisticated or unique wiper. It's most known for being the foundation and beginning ancestry of another popular ransomware builder, Chaos. Due to the builder's open-source nature, Chaos has hundreds of variants. Thankfully, later versions of Chaos have decryptors for most of its creations. The only exceptions are versions 1.0 and 2.0, which are built upon the wiper aspect of Bagli.

Ransomware Type
RaaS
Wiper
Country of Origin
Azerbaijan
First Seen
Last Seen
Threat Actors
Type
Actor
Individual
ryukRans
Extortion Types
Blackmail
Direct Extortion
Pseudo-Extortion
Extortion Amounts
Amount
$350
Communication
Medium
Identifier
Email
XSS.is
Encryption
Additional Encryption
Overwrites bytes with Random() function
Crypto Wallets
Blockchain Type
Crypto Wallet
BTC
bc1qnurh904jcnxm0amfg2cy3406k4ed2vd2x67s8p
File Extension
<file name>.<file extension>.bagli
Ransom Note Name
oxu.txt