#babuk2
Trustwave researchers have linked the newly revived Babuk ransomware brand—tracked as Babuk2—to an infamous data leaker named Bjorka.

www.trustwave.com/en-us/resour...
April 3, 2025 at 1:54 PM
#amazon listed as #Ransomware Victim by tracking site:

Victim: amazon com
Ransomware Group: Babuk2
Discovery Date: 2025-03-20 23:52

www.ransomware.live/id/YW1hem9uL...
Ransomware.live 👀
Ransomware.live tracks ransomware groups and their activity. It was created by Julien Mousqueton, a security researcher. The website provides information on the groups' infrastructure, victims, and pa...
www.ransomware.live
March 21, 2025 at 10:34 AM
-Hunters international prepares to shut down and rebrand
-Babuk2 gang linked to data broker Bjorka
-Stripe API abused for skimming
-Abuse of SVG redirects becomes mainstream
-UNC5221 deploys new Ivanti zero-day
-DrayTek reboot loops linked to pre-2020 bugs
-Five Eyes warns about fast flux networks
April 4, 2025 at 8:59 AM
Ransomware Attack: MYINDIHOME TELKOM INDONESIA Targeted by Babuk2 Group

2025-01-28 : In the ever-evolving world of cyber threats, one of the most alarming trends is the rise of ransomware attacks, where hackers demand hefty sums to return access to compromised data. One such group, Babuk2, has…
Ransomware Attack: MYINDIHOME TELKOM INDONESIA Targeted by Babuk2 Group
2025-01-28 : In the ever-evolving world of cyber threats, one of the most alarming trends is the rise of ransomware attacks, where hackers demand hefty sums to return access to compromised data. One such group, Babuk2, has recently made headlines with their latest target: MYINDIHOME TELKOM INDONESIA. This attack, reported on January 28, 2025, highlights the ongoing dangers of cybercrime and the growing impact on global businesses.
undercodenews.com
January 28, 2025 at 5:44 PM
#Rheinmetall ist bei ransomware.live unter dem Threat Actor #Babuk2 gelistet 🤔 #Ransomware #Exfiltration
April 4, 2025 at 8:50 AM
Right now, "so-called" #ransomware group #Babuk2 posted on its DLS the dataset - prolly the one found on the dark web.

@sonoclaudio.ransomnews.online @signorina37.ransomnews.online @garantepiracy.it
🚨 Cyber Alert‼️

🇪🇸 Spain – Iberdrola: 1.1M customer IBAN records up for sale

The threat actor known as AltaMar claims to be selling 1.1 million IBAN leads of Iberdrola.
April 14, 2025 at 9:05 AM
(non) etica del ransomware con le sue dinamiche.

Perché, quindi, i dati di #babuk e #babuk2 non sono veritieri? Perche quelle rivendicazioni sono state già pubblicate da altri gruppi. E perché il gruppo non è attivo da anni.

Il source code del "babuk ransomware" è stato leakato e condiviso

💰
January 28, 2025 at 6:11 AM
Babuk2 Ransomware Issuing Fake Extortion Demands With Data from Old Breaches
Babuk2 Ransomware Issuing Fake Extortion Demands With Data from Old Breaches
The Babuk2 ransomware group has been caught issuing extortion demands based on false claims and recycled data from previous breaches. This revelation comes from recent investigations conducted by the Halcyon RISE Team, shedding light on a concerning trend in the world of cybercrime. The Babuk2 group, also known as Babuk-Bjorka, has been making waves with public announcements of numerous attacks. However, these claims have not been corroborated by third parties or the alleged victims, raising suspicions about the authenticity of these incidents. Halcyon analysts identified that the group appears to be leveraging data from earlier breaches to support their extortion claims. Many of the purported victims were previously targeted by other ransomware groups such as RansomHub, FunkSec, LockBit, and even the original Babuk team. What makes this situation particularly alarming is the lack of evidence supporting any new, live ransomware encryption or fresh network intrusions. The Halcyon RISE Team’s analysis suggests that the data being used is recycled from past incidents, despite Babuk2’s claims of conducting multiple attacks in early 2025. The Deceptive Nature of Babuk2’s Operations The Babuk2 operation seems to be capitalizing on the notoriety of the original Babuk ransomware, which was active in 2021. By using the Babuk name, the group aims to establish credibility in the cybercriminal underworld. The administrator, known as Bjorka, has been active on various forums and Telegram , with a history of involvement in other data breaches and extortion attempts. This tactic of issuing fake extortion demands poses significant risks to businesses, both financially and reputationally. Even if the attack claims are false, the mere threat can pressure organizations into paying ransoms or investing in unnecessary remediation measures. It shows the critical importance of due diligence and independent verification of any reported network intrusions. The high-profile nature of some of Babuk2’s claims, including an alleged significant incident targeting Indian military and government data, necessitates heightened vigilance among decision-makers and cybersecurity professionals. As the cybersecurity landscape continues to evolve, it’s crucial for organizations to stay informed and consult with experts to accurately interpret and respond to such threats. The Babuk2 case serves as a stark reminder of the deceptive tactics employed by cybercriminals and the need for robust verification processes in the face of extortion attempts. Investigate Real-World Malicious Links & Phishing Attacks With  Threat Intelligence Lookup  -  Try for Free The post Babuk2 Ransomware Issuing Fake Extortion Demands With Data from Old Breaches appeared first on Cyber Security News .
cybersecuritynews.com
March 20, 2025 at 2:00 PM
BTW, 62 firiem / institucii po celom svete ma momentalne problem s Babuk2. najviac ma zaraza len to, ze SEIA mala rovnaky problem uz v:
Discovery Date: 2024-03-08 14:43
Discovery Date: 2024-06-04 23:52

ja neviem, nebolo by spravne urobit aspon skolenie zamestnancom, nech vedia pouzivat PC!?
January 27, 2025 at 3:28 PM
Dark Web Profile: Babuk/Babuk2
Dark Web Profile: Babuk/Babuk2 - SOCRadar® Cyber Intelligence Inc.
In 2025, a new iteration, Babuk2, resurfaced under the alias Bjorka, a notorious hacker known for targeting the Indonesian government...
socradar.io
April 11, 2025 at 12:13 PM
-Chrome rolls out new Rust-based font loader
-CapitalOne hacker to be resentenced
-BlackBasta admin brags about getting state protection
-Rise in ServiceNow exploitation
-New Ox Thief, VanHelsing, and Babuk2 ransomware
-New DollyWay botnet
-RansomHub's new Betruger backdoor
-Arcane Stealer report
March 21, 2025 at 8:32 AM
#Rheinmetall ist wohl von der babuk2 Gruppe angegriffen worden. 750 GByte an Daten will die Gruppe abgezogen haben.

www.borncity.com/blog/2025/04...
Rheinmetall Opfer eines Cyberangriffs der Babuk2-Gruppe?
Ist der Rüstungskonzern Rheinmetall Opfer eines Ransomware-Angriffs geworden? Zumindest behauptet die Babuk2-Ransomware-Gruppe einen erfolgreichen Angriff auf das Unternehmen ausgeführt zu haben.
www.borncity.com
April 4, 2025 at 7:31 PM
According to https://ransomware.live, babuk2 ransomware group has added MYPERTAMINA INDONESIA to its victims.
January 28, 2025 at 5:56 AM
Ransomware Attack Alert: smic.mi.th (Thailand Intelligence Agency) Targeted by babuk2

Latest Ransomware Incident Overview smic.mi.th (Thailand Intelligence Agency) Incident Details: Public Sector Stay updated with the latest information on ransomware attacks and protect your business from cyber…
Ransomware Attack Alert: smic.mi.th (Thailand Intelligence Agency) Targeted by babuk2
Latest Ransomware Incident Overview smic.mi.th (Thailand Intelligence Agency) Incident Details: Public Sector Stay updated with the latest information on ransomware attacks and protect your business from cyber threats. Source: ransomware.live
cyberthreatintelligence.net
March 20, 2025 at 9:27 AM
Ransomware Attack Alert: Florida Department of Transportation (FDOT) Targeted by babuk2

Latest Ransomware Incident Overview Florida Department of Transportation (FDOT) Incident Details: Public Sector Stay updated with the latest information on ransomware attacks and protect your business from…
Ransomware Attack Alert: Florida Department of Transportation (FDOT) Targeted by babuk2
Latest Ransomware Incident Overview Florida Department of Transportation (FDOT) Incident Details: Public Sector Stay updated with the latest information on ransomware attacks and protect your business from cyber threats. Source: ransomware.live
cyberthreatintelligence.net
March 16, 2025 at 3:01 PM
Ransomware Attack Alert: Ministry Of Defense of the Republic Of Korea Targeted by babuk2

Latest Ransomware Incident Overview Ministry Of Defense of the Republic Of Korea Incident Details: Public Sector Stay updated with the latest information on ransomware attacks and protect your business from…
Ransomware Attack Alert: Ministry Of Defense of the Republic Of Korea Targeted by babuk2
Latest Ransomware Incident Overview Ministry Of Defense of the Republic Of Korea Incident Details: Public Sector Stay updated with the latest information on ransomware attacks and protect your business from cyber threats. Source: ransomware.live
cyberthreatintelligence.net
March 16, 2025 at 11:52 PM
Threat actor #Babuk2 disclosed a list of recent victims they would attack, including #Amazon.

However, many of those victims have already been attacked by other groups such as #LockBit3 and #CL0P^_

We're working on an analytical profile of the apolitical and money-driven group Babuk, stay tuned!
March 21, 2025 at 10:13 AM
According to Ransomware.live, babuk2 ransomware group has added Intelligence Bureau of the Joint Staff Department of the Central Military Commission... (🇨🇳) to its victims.
March 19, 2025 at 6:28 PM
According to Ransomware.live, babuk2 ransomware group has added Baykar Turkish defense company C4I and artificial intelligence By Babuk Locker 2.0 (🇹🇷) to its victims.
March 12, 2025 at 12:55 AM
Ransomware Attack Alert: pajak.go.id Targeted by babuk2

Latest Ransomware Incident Overview pajak.go.id Incident Details: Public Sector Stay updated with the latest information on ransomware attacks and protect your business from cyber threats. Source: ransomware.live
Ransomware Attack Alert: pajak.go.id Targeted by babuk2
Latest Ransomware Incident Overview pajak.go.id Incident Details: Public Sector Stay updated with the latest information on ransomware attacks and protect your business from cyber threats. Source: ransomware.live
cyberthreatintelligence.net
March 18, 2025 at 6:39 PM
Ransomware Attack Alert: icmr.gov.in Targeted by babuk2

Latest Ransomware Incident Overview icmr.gov.in Incident Details: Public Sector Stay updated with the latest information on ransomware attacks and protect your business from cyber threats. Source: ransomware.live
Ransomware Attack Alert: icmr.gov.in Targeted by babuk2
Latest Ransomware Incident Overview icmr.gov.in Incident Details: Public Sector Stay updated with the latest information on ransomware attacks and protect your business from cyber threats. Source: ransomware.live
cyberthreatintelligence.net
March 17, 2025 at 1:36 AM
Ransomware Attack Alert: Mpaj.gov.my Targeted by babuk2

Latest Ransomware Incident Overview Mpaj.gov.my Incident Details: Public Sector Stay updated with the latest information on ransomware attacks and protect your business from cyber threats. Source: ransomware.live
Ransomware Attack Alert: Mpaj.gov.my Targeted by babuk2
Latest Ransomware Incident Overview Mpaj.gov.my Incident Details: Public Sector Stay updated with the latest information on ransomware attacks and protect your business from cyber threats. Source: ransomware.live
cyberthreatintelligence.net
March 21, 2025 at 7:42 AM
Ransomware Attack Alert: www.gob.ve Targeted by babuk2

Latest Ransomware Incident Overview www.gob.ve Incident Details: Public Sector Stay updated with the latest information on ransomware attacks and protect your business from cyber threats. Source: ransomware.live
Ransomware Attack Alert: www.gob.ve Targeted by babuk2
Latest Ransomware Incident Overview www.gob.ve Incident Details: Public Sector Stay updated with the latest information on ransomware attacks and protect your business from cyber threats. Source: ransomware.live
cyberthreatintelligence.net
March 19, 2025 at 8:11 PM