babuk2
1 incidentes
1 paises
0 sectores
ransomware RU Ultimo: 2026-06-25
Aliases: SkyWave, Bjorka, Satanlock, babuk 2.0, Babyk
Babuk2 emerged in early 2025, operating under the aliases Bjorka and Skywave, and is widely regarded as a copycat group distinct from the original Babuk ransomware operation that became defunct in 2021. This iteration leverages the notoriety of the original Babuk and the Bjorka persona, a figure known for targeting the Indonesian government, to primarily achieve financial gain through data theft and extortion. The group is characterized by inconsistent and chaotic behavior, frequently recycling data from previous breaches by other threat actors, leading to questions about the authenticity and technical validation of their claimed compromises. Babuk2's defining trait is its reliance on public perception and the fear generated by the Babuk name rather than consistently demonstrating advanced technical capabilities, often utilizing previously leaked information to create the illusion of new, successful attacks.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Abrir perfil →
Paises objetivo (SOCRadar)
United Arab Emirates
Austria
Australia
Brazil
Canada
China
Colombia
Germany
Ecuador
Spain
Sectores objetivo (SOCRadar)
Other Information ServicesReal EstateHospitalsAccommodationAir TransportationManufacturingConstructionPublic AdministrationOil & GasEducational Services
URLs nuevas detectadas en IntelTracker