Skip to content

β€” Bavaqai

Threat-actor battle card Β· maintained from public sources Β· last updated 2026-08-15 Β· also known as BAVACAI (DLS/payload variant; file extension .BAVACAI); "File Manager" (DLS brand name); BARADAI (shared-infrastructure sibling)

CategoryRansomware
AttributionUnknown β€” MedusaLocker family; no government attribution published; no language artefacts confirmed in public reporting
First seen2026-05
StatusActive
Rank#7
Victims YTD30+
Primary targetsEducation, Legal, Manufacturing, Retail, Logistics, Nonprofit, Government, Technology; US, Brazil, France, Chile, Australia, Italy, Israel, Malaysia, Bulgaria, Tanzania, Canada

Overview

Bavaqai (also tracked as Bavacai/BAVACAI) is a MedusaLocker family ransomware operation that debuted in May 2026 with 16 victims posted simultaneously to its "File Manager" data-leak site, reaching an estimated 25+ total DLS posts in its first month β€” placing it in the ransomware ecosystem's top seven for May alongside SafePay and Nova (three new groups in a single month is unusual). The group is part of the MedusaLocker lineage and shares its DLS infrastructure and operator pattern with sibling variant BARADAI. Through Q2 2026, Dragos reported 12 industrial-sector victim claims; the group made the Bitdefender Top 10 list for June 2026. Estimated 2026 YTD victim count is 30+ (conservative; unconfirmed pending direct ransomware.live access). No CISA, FBI, NSA, or NCSC advisory has been published as of August 2026.

Attribution is unknown β€” no government or authoritative-vendor attribution published. No CIS-exclusion kill-switch or language artefacts have been identified.

Tradecraft

  • Family: MedusaLocker variant; encryption: AES-256-CBC + RSA-4096.
  • File extension: .BAVACAI appended to encrypted files.
  • Ransom notes: WHATS_HAPPEND.txt AND read_to_decrypt_files.html dropped across directories post-encryption.
  • Initial access: RDP brute force on exposed services (MedusaLocker lineage pattern).
  • Negotiation: qTox-based comms; Tor negotiation portal.
  • Persistence: Autorun registry key under CurrentVersion\Run to survive reboots.
  • Execution: cmd.exe for scripted infection and control commands.
  • Impact: Terminates SQL and related database services (via taskkill / net stop) to unlock locked files before encryption.
  • Pre-encryption exfiltration: Data staged and exfiltrated before encryption; 72-hour publication deadline in ransom notes.
  • Extortion model: Double-extortion (encrypt + DLS publication via "File Manager" site); ransom range reported at $10,000–$80,000.
  • Credential pre-exposure: 58.3% of victims had prior infostealer domain compromise (ransomware.live aggregate).

Notable victims

May 2026 debut DLS posts (FalconFeeds, Breachsense May 2026 report): - Trimble Inc. (technology/US) β€” large public construction software company - AcadΓ©mie de Montpellier (education authority/FR) β€” covers ~500,000 students - CEAGESP (logistics/BR) - ActionAid (nonprofit/TZ) - Elken Sdn Bhd (direct sales/MY) - Desert Christian Schools, CourtSmart Digital, Atencio Engineering (education/legal/tech β€” US) - Colegio MarΓ­a Inmaculada (education/CL)

May 28, 2026: - Mairie Thiverval-Grignon (municipal government/FR) β€” indexed under medusalocker on ransomware.live; confirms cross-attribution

July 9, 2026: - Canadian Armed Forces / forces.gc.ca (government/defense/CAN) β€” πŸŸ₯ DLS claim; some tracker feeds index under medusalocker slug; scope unconfirmed

Assessment

Bavaqai's May 2026 debut at 25+ victims placed it in the top seven immediately. Subsequent quarters show continued but reduced activity: 12 industrial-sector claims in Q2 2026 per Dragos, a Bitdefender top-10 placement for June, and the high-profile Canadian Armed Forces listing in July. The group has not made major monthly-report top-group lists for June or July, suggesting post-debut output has settled into single-digit or low-teens monthly victims. The MedusaLocker lineage provides a well-documented TTP playbook; the RDP initial-access vector and AES-256-CBC encryption are consistent with other MedusaLocker operators. The shared "File Manager" DLS with BARADAI suggests a common operator or tooling-as-a-service relationship. The $10k–$80k ransom range indicates opportunistic breadth targeting rather than vertically specialized high-value operations. No CISA/FBI/NSA advisory as of August 2026 β€” lower-profile than Tier-1 groups despite notable victims. Monitor Dragos Q3 2026 and Bitdefender July report for trend direction; promote to confirmed Tier-1 if monthly output returns to May 2026 debut levels.

Sources

πŸ—‚οΈ Attacks & victims

All disclosed victims attributed to this actor, newest first.

July 2026

Jul 09 Canadian Armed Forces (forces.gc.ca) Bavaqai Ransomware Β· Government / Defense Β· CAN Bavaqai (MedusaLocker/BAVACAI variant) listed the Canadian Armed Forces domain forces.gc.ca on its 'File Manager' DLS on approximately July 9 2026. Some tracker feeds index this under the medusalocker group slug. DLS claim β€” scope and exfiltrated data not confirmed. Β· Sources: https://socradar.io/data-breach/forces-medusalocker-ransomware-2026/

← All threat actors Β· Full victim database β†’