babuk2 logo

babuk2

1 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: SkyWave, Bjorka, Satanlock, babuk 2.0, Babyk
Ver en IntelTracker → APTTrail →
Babuk2 emerged in early 2025, operating under the aliases Bjorka and Skywave, and is widely regarded as a copycat group distinct from the original Babuk ransomware operation that became defunct in 2021. This iteration leverages the notoriety of the original Babuk and the Bjorka persona, a figure known for targeting the Indonesian government, to primarily achieve financial gain through data theft and extortion. The group is characterized by inconsistent and chaotic behavior, frequently recycling data from previous breaches by other threat actors, leading to questions about the authenticity and technical validation of their claimed compromises. Babuk2's defining trait is its reliance on public perception and the fear generated by the Babuk name rather than consistently demonstrating advanced technical capabilities, often utilizing previously leaked information to create the illusion of new, successful attacks.
Tecnicas MITRE
T1074, T1490, T1486

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United Kingdom (1)

Paises objetivo (SOCRadar)

United Arab EmiratesAustriaAustraliaBrazilCanadaChinaColombiaGermanyEcuadorSpain

Sectores objetivo (SOCRadar)

Other Information ServicesReal EstateHospitalsAccommodationAir TransportationManufacturingConstructionPublic AdministrationOil & GasEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com