Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Bluesky

137
Global rank
130 infographic chevron month
Month rank
149 infographic chevron week
Week rank
0
IOCs

BlueSky ransomware, first identified in June 2022, shares code similarities with other well-known ransomware families like Conti and Babuk. It primarily spreads via phishing emails and malicious links and can propagate through networks using SMB protocols. BlueSky uses advanced evasion techniques, such as hiding its processes from debuggers via the NtSetInformationThread API, making it difficult for analysts to detect and mitigate its attacks.

Ransomware
Type
Unknown
Origin
1 May, 2022
First seen
17 September, 2025
Last seen

How to analyze Bluesky with ANY.RUN

Type
Unknown
Origin
1 May, 2022
First seen
17 September, 2025
Last seen

IOCs

Last Seen at

Recent blog posts

post image
How to Grow SOC Team Expertise for Ultimate T...
watchers 398
comments 0
post image
Phishing, Cloud Abuse, and Evasion: Advanced...
watchers 2181
comments 0
post image
Release Notes: Palo Alto Networks, Microsoft,...
watchers 5122
comments 0

What is BlueSky ransomware?

BlueSky ransomware is a strain of malicious software that encrypts files on a victim's system, rendering them inaccessible until a ransom is paid. First detected in June 2022, it shares similarities with other notorious ransomware families like Conti and Babuk.

BlueSky spreads through methods such as phishing emails, malicious links, and network protocols like SMB (port 445 TCP). Once inside a system, it uses advanced evasion techniques, such as hiding threads from debuggers, to avoid detection. It targets both files and processes, encrypting files with RSA encryption and adding the ".bluesky" extension to them while maintaining operational stability by avoiding critical system processes.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

BlueSky ransomware technical details

BlueSky ransomware encrypts files on the infected system, spreads through network shares, and uses advanced evasion techniques to avoid detection.

The primary functionalities of BlueSky ransomware include:

  • Uses RSA encryption to lock files and adds a ".bluesky" extension to the affected files.
  • Avoids system-critical processes while terminating secondary ones to optimize encryption without causing a system crash.
  • Utilizes advanced anti-debugging techniques such as hiding threads from debuggers through the NtSetInformationThread API.
  • Writes specific registry keys, including x25519_pub and RECOVERYBLOB, which are essential for the encryption and decryption process.
  • Uses multi-threading to efficiently handle file encryption tasks, targeting both local files and network shares through SMB.

BlueSky ransomware execution process

To see how BlueSky operates, let’s upload its sample to the ANY.RUN sandbox.

BlueSky ransomware specifically targets files and processes for encryption. However, it strategically avoids critical system processes to prevent system crashes that could halt the encryption process prematurely. This selective targeting allows it to continue encrypting files while the system remains operational.

Encrypted files are marked with the “.bluesky” extension, and a ransom note is left in the directories containing the encrypted files.

Bluesky in ANY.RUN sandbox BlueSky ransom note displayed in ANY.RUN’s sandbox

Before the encryption takes place, the ransomware writes critical information to the system’s registry, such as x25519_pub and RECOVERYBLOB. These are used by the attackers to potentially decrypt files if the ransom is paid.

Bluesky registry manipulation Registry changes displayed by the ANY.RUN’s sandbox

One of BlueSky’s key features is its evasion tactics. It hides execution threads from debuggers using the NtSetInformationThread API, making it difficult for analysts and security tools to track its behavior in real-time. This advanced anti-debugging capability ensures that the malware can run stealthily in a compromised environment, minimizing the chances of detection.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

BlueSky ransomware distribution methods

Similar to other malware families like AsyncRAT and Lumma Stealer, BlueSky ransomware is distributed through a variety of methods, making it a versatile and dangerous threat. Here are the primary distribution methods:

  • Phishing emails: Delivered via emails containing malicious attachments or links that prompt users to download and execute ransomware.
  • SMB protocol (Server Message Block): Spreads across networks using SMB (Port 445 TCP), which makes it possible to infect multiple machines.
  • Trojanized software: Embedded in cracked or pirated software, which users unknowingly download from unreliable sources.
  • Malicious links: Spread through phishing websites or compromised legitimate sites, directing users to download the malware.

Gathering Threat Intelligence on BlueSky Ransomware

To gather up-to-date intelligence on BlueSky ransomware, use Threat Intelligence Lookup.

This service gives you access to a vast database of threat data, built on millions of malware analysis sessions conducted in the ANY.RUN sandbox. It allows you to search using over 40 parameters, such as IPs, file names, domains, and process artifacts. Bluesky lookup search Search query for Bluesky in ANY.RUN’s Threat Intelligence Lookup

Searching for BlueSky-related terms, such as threatName:"BlueSky", in TI Lookup brings up results related to this ransomware, including associated samples, network activity, and command-and-control (C2) communication.

Test the capabilities of Threat Intelligence Lookup and the ANY.RUN sandbox.

Conclusion

BlueSky ransomware is a dangerous threat due to its file encryption, network propagation, and advanced evasion techniques. To combat this, it's essential to use tools like ANY.RUN and proactively analyze suspicious files before they cause damage. ANY.RUN provides a real-time malware analysis platform, allowing users to safely investigate and understand malware behavior, while delivering detailed reports for actionable insights.

Sign up for a free ANY.RUN account today to start analyzing threats like BlueSky.

HAVE A LOOK AT

Bumblebee Loader screenshot
Bumblebee Loader
bumblebee
Bumblebee is a highly adaptable malware loader, often used by threat actors linked to the Conti and TrickBot cybercrime groups. Since its discovery in 2021, Bumblebee has been leveraged in phishing campaigns and email thread hijacking, primarily to distribute payloads like Cobalt Strike and ransomware. The malware employs obfuscation techniques, such as DLL injection and virtual environment detection, to avoid detection and sandbox analysis. Its command-and-control infrastructure and anti-analysis features allow it to persist on infected devices, where it enables further payload downloads and system compromise.
Read More
PureCrypter screenshot
PureCrypter
purecrypter
First identified in March 2021, PureCrypter is a .NET-based loader that employs obfuscation techniques, such as SmartAssembly, to evade detection. It has been used to distribute malware families including AgentTesla, RedLine Stealer, and SnakeKeylogger. The malware is typically delivered through phishing campaigns and malicious downloads, often masquerading as legitimate files with extensions like .mp4 or .pdf. PureCrypter utilizes encryption and compression to conceal its payloads and can inject malicious code into legitimate processes to maintain persistence on the infected system.
Read More
Lumma screenshot
Lumma
lumma
Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.
Read More
Cerber screenshot
Cerber
cerber
Cerber is a Ransomware-as-a-Service (RaaS) that appeared in 2016, spread quickly and has been evolving since. It became well-known for its file encryption, offline capabilities, and sophisticated evasion techniques. It primarily targets enterprises, financial institutions, and government entities, encrypting their data and demanding ransom payments in Bitcoin. It also targets everyday users encrypting personal files (photos, documents) with the risk of their permanent loss.
Read More
Chaos Ransomware screenshot
Chaos ransomware is a malware family known for its destructive capabilities and diverse variants. It first appeared in 2021 as a ransomware builder and later acted as a wiper. Unlike most ransomware strains that encrypt data to extort payment, early Chaos variants permanently corrupted files, while later versions adopted more conventional encryption techniques.
Read More
Tycoon 2FA screenshot
Tycoon 2FA
tycoon
Tycoon 2FA is a phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) protections, particularly targeting Microsoft 365 and Gmail accounts. Its advanced evasion techniques and modular architecture make it a significant threat to organizations relying on MFA for security.
Read More