#babuk
Threat actors have started to use the Velociraptor digital forensics and incident response (DFIR) tool in attacks that deploy LockBit and Babuk ransomware.
Hackers now use Velociraptor DFIR tool in ransomware attacks
Threat actors have started to use the Velociraptor digital forensics and incident response (DFIR) tool in attacks that deploy LockBit and Babuk ransomware.
www.bleepingcomputer.com
October 9, 2025 at 7:32 PM
Threat intel analyst Rakesh Krishnan looks at the funny case of a ransomware gang (Babuk) losing over $20,000 worth of crypto-assets from past ransom payments via an account on Indodax, an Indonesian crypto-exchange that got hacked last September.

theravenfile.com/2025/02/06/b...
BABUK RANSOMWARE: A VICTIM OF INDODAX HACK
In this article, we are going to witness a case study where a Ransomware Group had lost their “hard-earned” ransom amount to another Crypto Exchange Heist.  Hackers flees away with Money | Ima…
theravenfile.com
February 6, 2025 at 3:03 PM
Trustwave researchers have linked the newly revived Babuk ransomware brand—tracked as Babuk2—to an infamous data leaker named Bjorka.

www.trustwave.com/en-us/resour...
April 3, 2025 at 1:54 PM
🏴 Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code targeting both Windows and ESXi systems with cross-platform double-extortion attacks against healthcare, energy, real estate, and agriculture sectors, claiming 12 victims across seven countries…
September 28, 2026 at 7:04 PM
(non) etica del ransomware con le sue dinamiche.

Perché, quindi, i dati di #babuk e #babuk2 non sono veritieri? Perche quelle rivendicazioni sono state già pubblicate da altri gruppi. E perché il gruppo non è attivo da anni.

Il source code del "babuk ransomware" è stato leakato e condiviso

💰
January 28, 2025 at 6:11 AM
March 14, 2025 at 6:28 AM
Pro-Tip: “Prolonged Computer Outage” is almost always PR speak for ransomware attack.

@valerymarchive.bsky.social has been doing excellent research on Termite, the Babuk-based group behind this hospital attack and several other recent attacks.
December 6, 2024 at 1:15 PM
Analysis confirms that babuk.exe, advertised in the Babuk 2.0 #Ransomware Affiliates Telegram channel, is actually based entirely on LockBit 3.0 source code—not Babuk. More details in our @rapid7.com analysis here: www.rapid7.com/blog/post/20... #infosec #malware
A Rebirth of a Cursed Existence? - The Babuk Locker 2.0 | Rapid7 Blog
In early 2025, we came across a channel promoting itself as Babuk Locker. Since the original group had shut down in 2021, we decided to investigate whether this was a rebrand or a new threat.
www.rapid7.com
April 7, 2025 at 8:48 AM
🚨 nuovo attacco #ransomware Italia 🚨

🏴‍☠️ Babuk 2
⚙️ Esaote SPA | Genova
🔗 esaote.com
📄 sample: sì
▪️ dati esfiltrati dichiarati: 117.00GB
▪️ dati esfiltrati pubblicati: -

#ransomNews #security #infosec
March 18, 2025 at 5:15 PM
Russia arrests one of its own – a cybercrime suspect on FBI's most wanted list
Russia arrests one of its own – a cybercrime suspect on FBI's most wanted list
The latest in an unusual change of fortune for group once protected by the Kremlin An alleged former affiliate of the LockBit and Babuk ransomware operations, who also just happens to be one of the most wanted cybercriminals in the US, is now…
dlvr.it
December 2, 2024 at 12:43 PM
has babuk returned? well in one sense, yes. but in another, more accurate and specific sense: no www.rapid7.com/blog/post/20...
A Rebirth of a Cursed Existence? - The Babuk Locker 2.0 | Rapid7 Blog
In early 2025, we came across a channel promoting itself as Babuk Locker. Since the original group had shut down in 2021, we decided to investigate whether this was a rebrand or a new threat.
www.rapid7.com
April 7, 2025 at 9:18 AM
Announcement of his arrest is going to be all over Russian media, which can make Putin look good to citizens. Yet Matveev's skills combined with his background and history, would be rather concerning to global cybersecurity community. He has also been linked with Babuk ransomware. (cont'd) #NAFO
November 30, 2024 at 2:00 PM
Babukランサムウェアグループが復活、60以上の被害組織名を明かすも落とし穴あり
#CybersecurityNews
www.cyberdaily.au/security/116...
Babuk ransomware group resurrects with more than 60 victims, but there’s a catch
The seemingly rebooted threat actor posted a swathe of victims in the last couple of days – but none of them are unique to Babuk.
www.cyberdaily.au
January 30, 2025 at 12:08 AM
babuk yank
June 18, 2024 at 4:14 PM
🏴 Termite is a ransomware group first identified in late 2024 using a modified version of Babuk ransomware code; its most notable attack was the November 2024 breach of supply-chain software firm Blue Yonder, claiming 680 GB of exfiltrated data and disrupting major customers including…
September 22, 2026 at 3:01 AM
🏴 Termite is a ransomware group first identified in late 2024 using a modified version of Babuk ransomware code; its most notable attack was the November 2024 breach of supply-chain software firm Blue Yonder, claiming 680 GB of exfiltrated data and disrupting major customers including…
September 22, 2026 at 3:01 AM
🏴 Termite is a ransomware group first identified in late 2024 using a modified version of Babuk ransomware code; its most notable attack was the November 2024 breach of supply-chain software firm Blue Yonder, claiming 680 GB of exfiltrated data and disrupting major customers including…
September 22, 2026 at 3:00 AM
🏴 Termite is a ransomware group first identified in late 2024 using a modified version of Babuk ransomware code; its most notable attack was the November 2024 breach of supply-chain software firm Blue Yonder, claiming 680 GB of exfiltrated data and disrupting major customers including…
September 26, 2026 at 1:00 AM
Rare Russian ransomware hacker arrest. Authorities charged a 32-year-old, allegedly linked to Babuk, Hive, and LockBit, defying usual non-cooperation with US investigations.
December 3, 2024 at 1:00 AM
Decrypted: Midnight Ransomware

This blog dives into the technical anatomy of Midnight, its lineage from Babuk, and the critical indicators o

Read more: https://www.gendigital.com/blog/insights/research/midnight-ransomware
November 7, 2025 at 10:54 AM
Babuk. Je to napojené na ruský štát, alebo sú to len kriminálnici z ruska?

www.kelacyber.com/blog/new-rus...
New Russian-Speaking Forum - A New Place for RaaS?
Victoria Kivilevich, Threat Intelligence Analyst
www.kelacyber.com
January 27, 2025 at 10:00 AM
According to CybelAngel Threat Investigation Team Babuk is likely a Russian-speaking cybercriminal group and – so far – is not known to be tied to any other ransomware gang, excluding its partners.
January 27, 2025 at 3:59 PM
per sfruttare la notorietà del gruppo e far leva su un possibile (millantato, la storia fratricida di Babuk non mente) back to back?

La risposta non la ho.
Ma quelle rivendicazioni non sono da considerare attendibili, sotto ogni punto di vista.
January 28, 2025 at 6:11 AM