BaBlock/Rorschach Ransomware Hits Sapienza University of Rome — Femwar02 Affiliate First Appearance, Fastest Encryption (4m30s), DLL Sideloading via Cortex XDR, Direct Syscalls EDR Evasion, Autonomous AD GPO Propagation, 122K Students Affected, Millions-Euro Ransom — Threadlinqs Intelligence
As of 2026-05-30, BaBlock/Rorschach Ransomware Hits Sapienza University of Rome — Femwar02 Affiliate First Appearance, Fastest Encryption (4m30s), DLL Sideloading via Cortex XDR, Direct Syscalls EDR Evasion, Autonomous AD GPO Propagation, 122K Students Affected, Millions-Euro Ransom is a high-severity ransomware threat attributed to Femwar02 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-0097 · Severity: HIGH · Status: RESOLVED · Category: RANSOMWARE
Attribution: Femwar02 · Russia · FINANCIAL
BaBlock/Rorschach ransomware attack on Sapienza University of Rome (largest university in Europe, ~122K enrolled) by previously unknown affiliate 'Femwar02'. Attack launched night of Feb 1-2, 2026,
On February 2, 2026, Sapienza University of Rome — the largest university in Europe with approximately 122,000 students, plus faculty, administrators, and researchers — was paralyzed by a ransomware attack conducted by an affiliate crew calling themselves 'Femwar02', operating under the BaBlock (also known as Rorschach) ransomware-as-a-service ecosystem.
The attack began during the night of February 1-2 and was discovered Monday morning when all digital services became unreachable. The university immediately isolated its entire network infrastructure as a precautionary measure. Affected systems included: the institutional website (uniroma1.it), Infostud (the central portal for exam registration, certificate printing, and career management), all internal administrative systems, and departmental networks.
The timing was devastating — the attack struck during the final weeks of the exam period, just before the start of the second semester, maximizing operational impact on the academic community.
The attackers issued a 72-hour ultimatum demanding payment of millions of euros in cryptocurrency, threatening to publish data of hundreds of thousands of students, faculty, and staff on the dark web. According to Corriere della Sera reporting, the attackers explicitly stated their motivation was NOT political — a critical correction from the v1 database entry which incorrectly labeled this as a 'pro-Russian' attack.
BaBlock/Rorschach ransomware was first discovered by Trend Micro in March 2022 and independently analyzed by Check Point Research in April 2023. It represents a 'Frankenstein' creation combining the most effective techniques from multiple ransomware families:
1. ENCRYPTION SPEED: 4 minutes 30 seconds for full system encryption in controlled tests — faster than LockBit v3.0 (7 minutes). Uses intermittent encryption (partial file encryption) with curve25519 + eSTREAM hc-128 hybrid cryptography borrowed from Babuk source code.
2. DELIVERY: Multi-component package — encrypted config.ini payload, DarkLoader DLL (decryptor/injector), legitimate executable for DLL sideloading, CMD file with 4-digit passcode. Check Point documented abuse of Palo Alto Cortex XDR Dump Service Tool (cy.exe) for sideloading.
3. EXECUTION: Injects into notepad.exe via hooked Ntdll.RtlTestBit API. Protected by VMProtect anti-virtualization. Uses direct syscalls (syscall instruction) for NT APIs to evade security monitoring — extremely rare in ransomware.
4. PROPAGATION: Autonomous AD Group Policy deployment when executed on Domain Controller — copies itself to domain machines, creates scheduled tasks for process killing and ransomware execution. Similar to LockBit 2.0 but independently implemented.
5. EVASION: Process argument falsification (spawns processes with fake arguments, rewrites in memory), shadow copy deletion via vssadmin, Windows event log clearing, firewall disabling.
6. CIS EXCLUSION: Language checks for Armenian, Azerbaijani, Kazakh, Russian, Ukrainian, Belarusian, Tajik, Georgian, Kyrgyz, Turkmen, Uzbek — exits without encrypting on CIS systems. This is a common Eastern European cybercrime trait, NOT evidence of Russian state sponsorship.
The 'Femwar02' affiliate had never appeared in ransomware tracking databases before this attack. The encrypted file prefix 'fermwar' (note: typo variant of the crew name) served as the compromise indicator during recovery.
Concurrent but SEPARATE: NoName057(16), a pro-Russian hacktivist collective, launched DDoS attacks against Italian municipal websites (Parma, Reggio Emilia, Giugliano) and the Uffizi Gallery during the same week, citing 'Russophobia' and taunting Italian cybersecurity ahead of the 2026 Milan-Cortina Olympics. These were politically motivated DDoS attacks unrelated to the financially motivated Sapienza ransomware.
Response involved: Agenzia per la Cybersicurezza Nazionale (ACN), Polizia Postale (investigation), Procura di Roma (criminal charges for unauthorized system access,
Target sectors: Education, Government
Target regions: Europe
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1078, T1059.003, T1053.005, T1106, T1053.005, T1484.001, T1574.002, T1055, T1070.001, T1562.004