Threat reportRansomwareTL-2026-0097
BaBlock/Rorschach Ransomware Hits Sapienza University of Rome — Femwar02 Affiliate First Appearance, Fastest Encryption (4m30s), DLL Sideloading via Cortex XDR, Direct Syscalls EDR Evasion, Autonomous AD GPO Propagation, 122K Students Affected, Millions-Euro Ransom
BaBlock/Rorschach Ransomware Hits Sapienza University of (TL-2026-0097) is a high-severity ransomware operation, first published 2026-02-02. It is attributed to Femwar02 (Russia) with medium confidence, maps to 35 MITRE ATT&CK techniques (T1003, T1003.001, T1005), and is covered by 9 detection rules and 26 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 35MITRE ATT&CK
- Actors
- 1Femwar02
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-0097
- Threat ID
- TL-2026-0097
- Severity
- HIGH
- Status
- RESOLVED
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- Femwar02
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- Education, Government
- Target regions
- Europe
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in BaBlock/Rorschach Ransomware Hits Sapienza University of
Malware and tooling: Rorschach Ransomware, Chisel, FScan, Kerbrute, Mimikatz
How BaBlock/Rorschach Ransomware Hits Sapienza University of works
BaBlock/Rorschach ransomware attack on Sapienza University of Rome (largest university in Europe, ~122K enrolled) by previously unknown affiliate 'Femwar02'. Attack launched night of Feb 1-2, 2026, paralyzed all digital infrastructure including Infostud academic portal, institutional website, and internal systems during critical exam period. Ransom demanded: millions of euros in cryptocurrency with 72-hour ultimatum. BaBlock/Rorschach is a next-generation ransomware first discovered March 2022 that combines techniques from LockBit v2.0, Babuk, and Yanluowang with unique features including fastest encryption speed ever benchmarked (4m30s vs LockBit's 7m), direct syscalls for EDR evasion, DLL sideloading via legitimate executables (including Palo Alto Cortex XDR), VMProtect packing, and autonomous AD Group Policy propagation. V1 title claimed 'pro-Russian' motivation — CORRECTED: BaBlock has CIS language exclusions (common Eastern European cybercrime trait) but the Femwar02 affiliate explicitly stated non-political financial motivation. Concurrent NoName057(16) DDoS attacks on Italian institutions were SEPARATE campaigns. Italian Procura di Roma opened criminal investigation for unauthorized system access. Agenzia per la Cybersicurezza Nazionale (ACN) and Polizia Postale involved in response. Recovery began Feb 7, 2026 — Identity management, Moodle, Zoom, Gmail restored; Infostud remained offline pending security testing. File encryption marker prefix: 'fermwar'. Previous Sapienza breach in 2011 (student/faculty data leaked).
On February 2, 2026, Sapienza University of Rome — the largest university in Europe with approximately 122,000 students, plus faculty, administrators, and researchers — was paralyzed by a ransomware attack conducted by an affiliate crew calling themselves 'Femwar02', operating under the BaBlock (also known as Rorschach) ransomware-as-a-service ecosystem.
The attack began during the night of February 1-2 and was discovered Monday morning when all digital services became unreachable. The university immediately isolated its entire network infrastructure as a precautionary measure. Affected systems included: the institutional website (uniroma1.it), Infostud (the central portal for exam registration, certificate printing, and career management), all internal administrative systems, and departmental networks.
The timing was devastating — the attack struck during the final weeks of the exam period, just before the start of the second semester, maximizing operational impact on the academic community.
The attackers issued a 72-hour ultimatum demanding payment of millions of euros in cryptocurrency, threatening to publish data of hundreds of thousands of students, faculty, and staff on the dark web. According to Corriere della Sera reporting, the attackers explicitly stated their motivation was NOT political — a critical correction from the v1 database entry which incorrectly labeled this as a 'pro-Russian' attack.
BaBlock/Rorschach ransomware was first discovered by Trend Micro in March 2022 and independently analyzed by Check Point Research in April 2023. It represents a 'Frankenstein' creation combining the most effective techniques from multiple ransomware families:
1. ENCRYPTION SPEED: 4 minutes 30 seconds for full system encryption in controlled tests — faster than LockBit v3.0 (7 minutes). Uses intermittent encryption (partial file encryption) with curve25519 + eSTREAM hc-128 hybrid cryptography borrowed from Babuk source code.
2. DELIVERY: Multi-component package — encrypted config.ini payload, DarkLoader DLL (decryptor/injector), legitimate executable for DLL sideloading, CMD file with 4-digit passcode. Check Point documented abuse of Palo Alto Cortex XDR Dump Service Tool (cy.exe) for sideloading.
3. EXECUTION: Injects into notepad.exe via hooked Ntdll.RtlTestBit API. Protected by VMProtect anti-virtualization. Uses direct syscalls (syscall instruction) for NT APIs to evade security monitoring — extremely rare in ransomware.
4. PROPAGATION: Autonomous AD Group Policy deployment when executed on Domain Controller — copies itself to domain machines, creates scheduled tasks for process killing and ransomware execution. Similar to LockBit 2.0 but independently implemented.
5. EVASION: Process argument falsification (spawns processes with fake arguments, rewrites in memory), shadow copy deletion via vssadmin, Windows event log clearing, firewall disabling.
6. CIS EXCLUSION: Language checks for Armenian, Azerbaijani, Kazakh, Russian, Ukrainian, Belarusian, Tajik, Georgian, Kyrgyz, Turkmen, Uzbek — exits without encrypting on CIS systems. This is a common Eastern European cybercrime trait, NOT evidence of Russian state sponsorship.
The 'Femwar02' affiliate had never appeared in ransomware tracking databases before this attack. The encrypted file prefix 'fermwar' (note: typo variant of the crew name) served as the compromise indicator during recovery.
Concurrent but SEPARATE: NoName057(16), a pro-Russian hacktivist collective, launched DDoS attacks against Italian municipal websites (Parma, Reggio Emilia, Giugliano) and the Uffizi Gallery during the same week, citing 'Russophobia' and taunting Italian cybersecurity ahead of the 2026 Milan-Cortina Olympics. These were politically motivated DDoS attacks unrelated to the financially motivated Sapienza ransomware.
Response involved: Agenzia per la Cybersicurezza Nazionale (ACN), Polizia Postale (investigation), Procura di Roma (criminal charges for unauthorized system access, coordinated by procuratore aggiunto Sergio Colaiocco). Prorettore Leonardo Querzoni (VP Digital Technologies and Cybersecurity) led university response.
Recovery timeline: Feb 2 — full network isolation; Feb 3 — Procura investigation opened; Feb 4 — Bablock/Rorschach identified by Corriere della Sera; Feb 7 — Identity management, SPID/CIE authentication, Moodle, Zoom, Gmail/Google Apps restored with mandatory password reset; Infostud remained offline for security testing. University deployed physical infopoints and paper-based exam registration as interim measures.
MITRE ATT&CK techniques used in TL-2026-0097
credential-access
T1003 OS Credential Dumping; T1003.001 LSASS Memory; T1110.001 Password Guessing; T1110.003 Password Spraying
collection
lateral-movement
T1021.002 SMB/Windows Admin Shares; T1570 Lateral Tool Transfer
defense-evasion
T1027.002 Software Packing; T1036.003 Rename Legitimate Utilities; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1078 Valid Accounts; T1484.001 Group Policy Modification; T1497 Virtualization/Sandbox Evasion
exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
discovery
T1046 Network Service Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1614.001 System Language Discovery
execution
T1053.005 Scheduled Task; T1059.003 Windows Command Shell; T1106 Native API
impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1657 Financial Theft
defense-impairment
T1553.002 Code Signing; T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs; T1686 Disable or Modify System Firewall; T1690 Prevent Command History Logging
command-and-control
persistence
resource-development
Remediation for BaBlock/Rorschach Ransomware Hits Sapienza University of
Immediate actions
- Network isolation upon ransomware detection to prevent lateral movement
- Mandatory password reset for all university credentials upon service restoration
- Verify no 'fermwar' prefixed files on endpoints before reconnecting to network
- Use only uncompromised devices (non-managed or personal with own connectivity) for initial access
- Deploy physical infopoints and paper-based processes as interim service continuity
Workarounds
- Monitor for notepad.exe spawned with unusual command-line arguments (ransomware injection target)
- Alert on vssadmin shadow copy deletion, bcdedit boot config changes, and Windows event log clearing in rapid succession
- Block Chisel and Fscan tool execution on endpoints
Longer-term hardening
- Implement DLL sideloading prevention via application allowlisting (WDAC/AppLocker)
- Monitor for abuse of signed security tool executables (Cortex XDR, etc.) for DLL sideloading
- Block direct syscall execution patterns in endpoint detection rules
- Restrict Group Policy Object creation and modification to authorized administrators only
- Implement network segmentation to contain ransomware propagation from Domain Controllers
- Deploy offline/immutable backup solutions tested with regular restoration drills
- Audit AD for unauthorized scheduled tasks and group policies
Weaknesses (CWE) in BaBlock/Rorschach Ransomware Hits Sapienza University of
Timeline of BaBlock/Rorschach Ransomware Hits Sapienza University of
- Earliest known BaBlock/Rorschach ransomware samples discovered in the wild. Source: Trend Micro research
- Trend Micro identifies BaBlock ransomware with unique numerical extension appending (00-99) and multi-component delivery package. Source: https://www.trendmicro.com/en_us/research/23/d/an-analysis-of-the-bablock-ransomware.html
- Check Point Research publishes analysis naming the ransomware 'Rorschach', documenting fastest encryption speed (4m30s), direct syscalls, and DLL sideloading via Palo Alto Cortex XDR. Source: https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/
- Trend Micro publishes detailed BaBlock analysis linking it to LockBit v2.0 code base with Babuk and Yanluowang elements, confirms VMProtect packing and DarkLoader component. Source: Trend Micro
- Femwar02 affiliate launches BaBlock/Rorschach ransomware attack against Sapienza University of Rome during overnight hours (Sunday night to Monday). Source: Red Hot Cyber
- Sapienza discovers ransomware attack Monday morning when all digital services become unreachable. University immediately isolates entire network infrastructure. Prorettore Querzoni issues emergency communication to students and faculty. ACN and Polizia Postale engaged. Source: https://www.redhotcyber.com/post/sapienza-paralizzata-da-un-attacco-informatico-perche-luniversita-ha-spento-tutto/
- Procura di Roma opens criminal investigation for unauthorized system access (accesso abusivo a sistema informatico), coordinated by procuratore aggiunto Sergio Colaiocco. Source: https://www.ansa.it/sito/notizie/cronaca/2026/02/03/attacco-hacker-alla-sapienza-procura-avvia-indagine_32d58151-7643-4bd4-a559-15c7207cb620.html
- NoName057(16) pro-Russian hacktivist group launches separate DDoS attacks on Italian municipalities (Parma, Reggio Emilia, Giugliano, Valle d'Aosta) and claims to have hacked Italian surveillance cameras ahead of 2026 Olympics. SEPARATE from Sapienza ransomware. Source: Red Hot Cyber
- Corriere della Sera identifies BaBlock/Rorschach as the ransomware variant, Femwar02 as the affiliate crew. Attackers claim non-political financial motivation. 72-hour ransom ultimatum for millions in cryptocurrency. Concurrent NoName057(16) DDoS attacks on Italian institutions (separate campaign). Source: Red Hot Cyber
- Sapienza begins gradual service restoration: Identity management, SPID/CIE authentication, Moodle e-learning, Zoom, Gmail/Google Apps (uniroma1.it), Medialibrary Online. Mandatory password reset required. Infostud remains offline pending security testing. Users warned to only connect from uncompromised devices (no 'fermwar' prefix files). Source: https://www.redhotcyber.com/post/la-sapienza-riattiva-i-servizi-digitali-dopo-lattacco-hacker/
- As of 2026-05-29, this specific incident is over: Sapienza fully recovered from offline backups, restoring its last service Infostud on Feb 17, 2026, with the ransom never paid and the 72-hour ultimatum long lapsed. The first-appearance Femwar02 affiliate has logged no further victims since February and the BaBlock/Rorschach (no CVE) intrusion is contained, so the threat is resolved.
Sources cited for BaBlock/Rorschach Ransomware Hits Sapienza University of
- Attacco hacker alla Sapienza: chi sono gli hacker di Bablock/Rorschach
- Sapienza paralizzata da un attacco informatico
- Attacco Hacker All'università La Sapienza — avviata indagine e richiesta di riscatto
- La Sapienza riattiva i servizi digitali dopo l'attacco hacker
- Comunicato prorettore Querzoni — aggiornamento attacco Sapienza
- Attacco hacker alla Sapienza, la Procura avvia un'indagine — ANSA
- La Sapienza riparte dopo l'attacco hacker — RomaToday
- An Analysis of the BabLock Ransomware — Trend Micro
- Rorschach — A New Sophisticated and Fast Ransomware — Check Point Research
- NoName057(16) colpisce Italia dopo Sapienza e Uffizi — concurrent DDoS context
- Trend Micro BaBlock IOC List
Detection coverage for TL-2026-0097
As of 2026-02-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0097 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.