β Bavaqai¶
Threat-actor battle card Β· maintained from public sources Β· last updated 2026-08-15 Β· also known as BAVACAI (DLS/payload variant; file extension .BAVACAI); "File Manager" (DLS brand name); BARADAI (shared-infrastructure sibling)
Overview¶
Bavaqai (also tracked as Bavacai/BAVACAI) is a MedusaLocker family ransomware operation that debuted in May 2026 with 16 victims posted simultaneously to its "File Manager" data-leak site, reaching an estimated 25+ total DLS posts in its first month β placing it in the ransomware ecosystem's top seven for May alongside SafePay and Nova (three new groups in a single month is unusual). The group is part of the MedusaLocker lineage and shares its DLS infrastructure and operator pattern with sibling variant BARADAI. Through Q2 2026, Dragos reported 12 industrial-sector victim claims; the group made the Bitdefender Top 10 list for June 2026. Estimated 2026 YTD victim count is 30+ (conservative; unconfirmed pending direct ransomware.live access). No CISA, FBI, NSA, or NCSC advisory has been published as of August 2026.
Attribution is unknown β no government or authoritative-vendor attribution published. No CIS-exclusion kill-switch or language artefacts have been identified.
Tradecraft¶
- Family: MedusaLocker variant; encryption: AES-256-CBC + RSA-4096.
- File extension:
.BAVACAIappended to encrypted files. - Ransom notes:
WHATS_HAPPEND.txtANDread_to_decrypt_files.htmldropped across directories post-encryption. - Initial access: RDP brute force on exposed services (MedusaLocker lineage pattern).
- Negotiation: qTox-based comms; Tor negotiation portal.
- Persistence: Autorun registry key under
CurrentVersion\Runto survive reboots. - Execution: cmd.exe for scripted infection and control commands.
- Impact: Terminates SQL and related database services (via
taskkill/net stop) to unlock locked files before encryption. - Pre-encryption exfiltration: Data staged and exfiltrated before encryption; 72-hour publication deadline in ransom notes.
- Extortion model: Double-extortion (encrypt + DLS publication via "File Manager" site); ransom range reported at $10,000β$80,000.
- Credential pre-exposure: 58.3% of victims had prior infostealer domain compromise (ransomware.live aggregate).
Notable victims¶
May 2026 debut DLS posts (FalconFeeds, Breachsense May 2026 report): - Trimble Inc. (technology/US) β large public construction software company - AcadΓ©mie de Montpellier (education authority/FR) β covers ~500,000 students - CEAGESP (logistics/BR) - ActionAid (nonprofit/TZ) - Elken Sdn Bhd (direct sales/MY) - Desert Christian Schools, CourtSmart Digital, Atencio Engineering (education/legal/tech β US) - Colegio MarΓa Inmaculada (education/CL)
May 28, 2026:
- Mairie Thiverval-Grignon (municipal government/FR) β indexed under medusalocker on ransomware.live; confirms cross-attribution
July 9, 2026:
- Canadian Armed Forces / forces.gc.ca (government/defense/CAN) β π₯ DLS claim; some tracker feeds index under medusalocker slug; scope unconfirmed
Assessment¶
Bavaqai's May 2026 debut at 25+ victims placed it in the top seven immediately. Subsequent quarters show continued but reduced activity: 12 industrial-sector claims in Q2 2026 per Dragos, a Bitdefender top-10 placement for June, and the high-profile Canadian Armed Forces listing in July. The group has not made major monthly-report top-group lists for June or July, suggesting post-debut output has settled into single-digit or low-teens monthly victims. The MedusaLocker lineage provides a well-documented TTP playbook; the RDP initial-access vector and AES-256-CBC encryption are consistent with other MedusaLocker operators. The shared "File Manager" DLS with BARADAI suggests a common operator or tooling-as-a-service relationship. The $10kβ$80k ransom range indicates opportunistic breadth targeting rather than vertically specialized high-value operations. No CISA/FBI/NSA advisory as of August 2026 β lower-profile than Tier-1 groups despite notable victims. Monitor Dragos Q3 2026 and Bitdefender July report for trend direction; promote to confirmed Tier-1 if monthly output returns to May 2026 debut levels.
Sources¶
- FalconFeeds β Initial 16-victim debut alert, May 5, 2026
- FalconFeeds β Mairie Thiverval-Grignon, May 28, 2026
- Breachsense β May 2026 Ransomware Report
- Bitdefender β Threat Debrief June 2026
- Dragos β Industrial Ransomware Analysis Q2 2026
- SOCRadar β forces.gc.ca / MedusaLocker breach, July 2026
- CYFIRMA β Weekly Intelligence Report 08 May 2026
- pcrisk.com β BAVACAI Ransomware removal guide
- ransomware.live β Bavacai group page
- RansomLook β Bavacai group page
ποΈ Attacks & victims¶
All disclosed victims attributed to this actor, newest first.
July 2026