# BaBlock/Rorschach Ransomware Hits Sapienza University of Rome — Femwar02 Affiliate First Appearance, Fastest Encryption (4m30s), DLL Sideloading via Cortex XDR, Direct Syscalls EDR Evasion, Autonomous AD GPO Propagation, 122K Students Affected, Millions-Euro Ransom

> BaBlock/Rorschach ransomware attack on Sapienza University of Rome (largest university in Europe, ~122K enrolled) by previously unknown affiliate 'Femwar02'. Attack launched night of Feb 1-2, 2026, paralyzed all digital infrastructure including Infostud academic portal, institutional website, and internal systems during critical exam period. Ransom demanded: millions of euros in cryptocurrency with 72-hour ultimatum. BaBlock/Rorschach is a next-generation ransomware first discovered March 2022 that combines techniques from LockBit v2.0, Babuk, and Yanluowang with unique features including fastest encryption speed ever benchmarked (4m30s vs LockBit's 7m), direct syscalls for EDR evasion, DLL sideloading via legitimate executables (including Palo Alto Cortex XDR), VMProtect packing, and autonomous AD Group Policy propagation. V1 title claimed 'pro-Russian' motivation — CORRECTED: BaBlock has CIS language exclusions (common Eastern European cybercrime trait) but the Femwar02 affiliate explicitly stated non-political financial motivation. Concurrent NoName057(16) DDoS attacks on Italian institutions were SEPARATE campaigns. Italian Procura di Roma opened criminal investigation for unauthorized system access. Agenzia per la Cybersicurezza Nazionale (ACN) and Polizia Postale involved in response. Recovery began Feb 7, 2026 — Identity management, Moodle, Zoom, Gmail restored; Infostud remained offline pending security testing. File encryption marker prefix: 'fermwar'. Previous Sapienza breach in 2011 (student/faculty data leaked).

- **Published:** 2026-02-02T12:00:00Z
- **Last reviewed:** 2026-02-02T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0097
- **ID:** TL-2026-0097
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** RESOLVED
- **Actor:** Femwar02 (Russia)
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On February 2, 2026, Sapienza University of Rome — the largest university in Europe with approximately 122,000 students, plus faculty, administrators, and researchers — was paralyzed by a ransomware attack conducted by an affiliate crew calling themselves 'Femwar02', operating under the BaBlock (also known as Rorschach) ransomware-as-a-service ecosystem.

The attack began during the night of February 1-2 and was discovered Monday morning when all digital services became unreachable. The university immediately isolated its entire network infrastructure as a precautionary measure. Affected systems included: the institutional website (uniroma1.it), Infostud (the central portal for exam registration, certificate printing, and career management), all internal administrative systems, and departmental networks.

The timing was devastating — the attack struck during the final weeks of the exam period, just before the start of the second semester, maximizing operational impact on the academic community.

The attackers issued a 72-hour ultimatum demanding payment of millions of euros in cryptocurrency, threatening to publish data of hundreds of thousands of students, faculty, and staff on the dark web. According to Corriere della Sera reporting, the attackers explicitly stated their motivation was NOT political — a critical correction from the v1 database entry which incorrectly labeled this as a 'pro-Russian' attack.

BaBlock/Rorschach ransomware was first discovered by Trend Micro in March 2022 and independently analyzed by Check Point Research in April 2023. It represents a 'Frankenstein' creation combining the most effective techniques from multiple ransomware families:

1. ENCRYPTION SPEED: 4 minutes 30 seconds for full system encryption in controlled tests — faster than LockBit v3.0 (7 minutes). Uses intermittent encryption (partial file encryption) with curve25519 + eSTREAM hc-128 hybrid cryptography borrowed from Babuk source code.

2. DELIVERY: Multi-component package — encrypted config.ini payload, DarkLoader DLL (decryptor/injector), legitimate executable for DLL sideloading, CMD file with 4-digit passcode. Check Point documented abuse of Palo Alto Cortex XDR Dump Service Tool (cy.exe) for sideloading.

3. EXECUTION: Injects into notepad.exe via hooked Ntdll.RtlTestBit API. Protected by VMProtect anti-virtualization. Uses direct syscalls (syscall instruction) for NT APIs to evade security monitoring — extremely rare in ransomware.

4. PROPAGATION: Autonomous AD Group Policy deployment when executed on Domain Controller — copies itself to domain machines, creates scheduled tasks for process killing and ransomware execution. Similar to LockBit 2.0 but independently implemented.

5. EVASION: Process argument falsification (spawns processes with fake arguments, rewrites in memory), shadow copy deletion via vssadmin, Windows event log clearing, firewall disabling.

6. CIS EXCLUSION: Language checks for Armenian, Azerbaijani, Kazakh, Russian, Ukrainian, Belarusian, Tajik, Georgian, Kyrgyz, Turkmen, Uzbek — exits without encrypting on CIS systems. This is a common Eastern European cybercrime trait, NOT evidence of Russian state sponsorship.

The 'Femwar02' affiliate had never appeared in ransomware tracking databases before this attack. The encrypted file prefix 'fermwar' (note: typo variant of the crew name) served as the compromise indicator during recovery.

Concurrent but SEPARATE: NoName057(16), a pro-Russian hacktivist collective, launched DDoS attacks against Italian municipal websites (Parma, Reggio Emilia, Giugliano) and the Uffizi Gallery during the same week, citing 'Russophobia' and taunting Italian cybersecurity ahead of the 2026 Milan-Cortina Olympics. These were politically motivated DDoS attacks unrelated to the financially motivated Sapienza ransomware.

Response involved: Agenzia per la Cybersicurezza Nazionale (ACN), Polizia Postale (investigation), Procura di Roma (criminal charges for unauthorized system access, coordinated by procuratore aggiunto Sergio Colaiocco). Prorettore Leonardo Querzoni (VP Digital Technologies and Cybersecurity) led university response.

Recovery timeline: Feb 2 — full network isolation; Feb 3 — Procura investigation opened; Feb 4 — Bablock/Rorschach identified by Corriere della Sera; Feb 7 — Identity management, SPID/CIE authentication, Moodle, Zoom, Gmail/Google Apps restored with mandatory password reset; Infostud remained offline for security testing. University deployed physical infopoints and paper-based exam registration as interim measures.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1059.003 Windows Command Shell
- T1053.005 Scheduled Task
- T1106 Native API
- T1484.001 Group Policy Modification
- T1574.001 DLL
- T1055 Process Injection
- T1685.005 Clear Windows Event Logs
- T1686 Disable or Modify System Firewall
- T1685 Disable or Modify Tools
- T1036.005 Match Legitimate Resource Name or Location
- T1027.002 Software Packing
- T1497 Virtualization/Sandbox Evasion
- T1553.002 Code Signing
- T1003 OS Credential Dumping
- T1110.001 Password Guessing
- T1082 System Information Discovery
- T1614.001 System Language Discovery
- T1057 Process Discovery
- T1046 Network Service Discovery
- T1570 Lateral Tool Transfer
- T1021.002 SMB/Windows Admin Shares
- T1005 Data from Local System
- T1572 Protocol Tunneling
- T1041 Exfiltration Over C2 Channel
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery
- T1489 Service Stop
- T1588.002 Tool
- T1036.003 Rename Legitimate Utilities
- T1003.001 LSASS Memory
- T1110.003 Password Spraying
- T1690 Prevent Command History Logging
- T1657 Financial Theft
- T1567 Exfiltration Over Web Service

## Sources

- [Attacco hacker alla Sapienza: chi sono gli hacker di Bablock/Rorschach](https://www.redhotcyber.com/post/attacco-hacker-alla-sapienza-chi-sono-gli-hacker-di-bablock-rorschach/)
- [Sapienza paralizzata da un attacco informatico](https://www.redhotcyber.com/post/sapienza-paralizzata-da-un-attacco-informatico-perche-luniversita-ha-spento-tutto/)
- [Attacco Hacker All'università La Sapienza — avviata indagine e richiesta di riscatto](https://www.redhotcyber.com/post/attacco-hacker-alluniversita-la-sapienza-avviata-unindagine-e-richiesta-di-riscatto/)
- [La Sapienza riattiva i servizi digitali dopo l'attacco hacker](https://www.redhotcyber.com/post/la-sapienza-riattiva-i-servizi-digitali-dopo-lattacco-hacker/)
- [Comunicato prorettore Querzoni — aggiornamento attacco Sapienza](https://www.redhotcyber.com/post/aggiornamento-attacco-hacker-della-sapienza-il-comunicato-agli-studenti-dal-prorettore/)
- [Attacco hacker alla Sapienza, la Procura avvia un'indagine — ANSA](https://www.ansa.it/sito/notizie/cronaca/2026/02/03/attacco-hacker-alla-sapienza-procura-avvia-indagine_32d58151-7643-4bd4-a559-15c7207cb620.html)
- [La Sapienza riparte dopo l'attacco hacker — RomaToday](https://www.romatoday.it/attualita/attacco-hacker-sapienza-ripristino-primi-servizi.html)
- [An Analysis of the BabLock Ransomware — Trend Micro](https://www.trendmicro.com/en_us/research/23/d/an-analysis-of-the-bablock-ransomware.html)
- [Rorschach — A New Sophisticated and Fast Ransomware — Check Point Research](https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/)
- [NoName057(16) colpisce Italia dopo Sapienza e Uffizi — concurrent DDoS context](https://www.redhotcyber.com/post/litalia-sotto-attacco-hacker-dopo-la-sapienza-e-gli-uffizi-noname05716-colpisce-ancora/)
- [Trend Micro BaBlock IOC List](https://www.trendmicro.com/content/dam/trendmicro/global/en/research/23/d/an-analysis-of-the-bablock-ransomware-/iocs-an-analysis-of-the-babLock-ransomware.txt)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0097
