Ransomware Group intelligence
Babuk2
InactiveTrack Babuk2 with 741 published victims and 4 known leak locations in a single intelligence view.
Overview
Babuk2 is tracked by Dark Eye as a ransomware group with 741 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Web location | Down checked 22m ago | 212.24.99.211. |
| Leak location 4 | Web location | Down checked 22m ago | 5g2e.l.time4vps.cloud |
| Leak location 2 | Onion service | Down checked 22m ago | bxwu33iefqfc3rxigynn3ghvq4gdw3gxgxna5m4aa3o4vscdeeqhiqad.onion |
| Leak location 1 | Onion service | Down checked 22m ago | 7dikawx73goypgfi4zyo5fcajxwb7agemmiwqax3p54aey4dwobcvcyd.onion |
Top Activity Sectors (17)
- Not identified 102
- Services 17
- Public Sector 13
- Communication / Marketing 10
- Healthcare / Pharma 9
- Finance / Legal / Insurance 9
- Retail / E-commerce 6
- Manufacturing / Engineering 5
- IT 5
- Construction / Real Estate 3
- Agriculture / Food 3
- Telecommunications 3
- Education 3
- Energy 2
- Transportation / Travel / Logistics 2
- NGOs / Associations 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (12)
▼MITRE ATT&CK does not currently catalogue Babuk2, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: babuk2 uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: babuk2 modifies Windows Registry Run keys to ensure ransomware execution upon system reboot for persistence.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: babuk2 leverages registry run keys and startup folders to maintain persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: babuk2 disables security tools like antivirus software and monitoring agents to evade detection during infection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: babuk2 manipulates boot sequence via Safe Mode Boot techniques to bypass initial security checks during execution.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: babuk2 encrypts and encodes victim files with custom ransomware keys to ensure irreversible data access denial.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: babuk2 deletes Volume Shadow Copies and backup files via system commands to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: babuk2 discovers remote systems via network scanning to expand foothold across victim networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: babuk2 performs network share discovery to identify accessible SMB shares for lateral movement and victim targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: babuk2 uses SMB/Windows Admin Shares for lateral movement between compromised hosts within the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: babuk2 encrypts victim files using strong symmetric encryption to maximize impact and trigger ransom demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: babuk2 calls system recovery inhibitors like shutdown scripts to prevent victim systems from restoring functionality.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (741)
Search, filter and paginate the victim timeline for Babuk2. Showing 1–100 of 741.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | tecnologias.mspz2.gob.ec id19320 View details | Ecuador | Other | — | ||
|
tecnologias.mspz2.gob.ec |
||||||
| Ransomware | tecnologias.mspz2.gob.ec id32965 View details | Ecuador | Other | — | ||
|
tecenologias.mspz2.gob.ec is cataloged within the threat-intelligence index as a ransomware victim entity operating within the IT sector and linked to the country EC. The entity identifier reflects its presence in cybersecurity threat databases, where it is documented in relation to malicious activity targeting information technology infrastructure. Its classification as a ransomware victim indicates its association with a threat actor identified as babuk2, a group noted for deploying ransomware campaigns. This listing provides neutral context for threat-intelligence professionals tracking affected entities, sectors, and source attributions across regional cyber incidents. The entry serves as an authoritative reference point for understanding the entity's role within the babuk2 threat landscape without disclosing unverified incident details. |
||||||
| Ransomware | tecnologias.mspz2.gob.ec id32965 View details | Ecuador | Other | — | ||
|
tecnologias.mspz2.gob.ec |
||||||
| Ransomware | tecnologias.mspz2.gob.ec id19320 View details | Ecuador | Other | — | ||
|
tecnologias.mspz2.gob.ec |
||||||
| Ransomware | turkish defense military id18945 View details | Türkiye | Other | — | ||
|
turkish defense military |
||||||
| Ransomware | turkish defense military id32970 View details | Türkiye | Other | — | ||
|
The Turkish Defense Military is a national defense entity operating within the Public Sector in Turkey, responsible for national security, military operations, defense logistics, and protection of state assets across the nation. As a critical public infrastructure organization, it represents a high-value target for cyber threats. This listing identifies the Turkish Defense Military as a ransomware victim linked to the Babuk2 threat actor, indicating a cybersecurity incident of concern within the defense sector. The entry reflects threat-intelligence indexing without confirming specific breach details. |
||||||
| Ransomware | turkish defense military id32970 View details | Türkiye | Other | — | ||
|
turkish defense military |
||||||
| Ransomware | turkish defense military id18945 View details | Türkiye | Other | — | ||
|
turkish defense military |
||||||
| Ransomware | rheinmetall.com (Rheinmetall Defence) id18944 View details | Germany | Manufacturing / Engineering | — | ||
|
rheinmetall.com (Rheinmetall Defence) |
||||||
| Ransomware | rheinmetall.com (Rheinmetall Defence) id32971 View details | Germany | Manufacturing / Engineering | — | ||
|
Rheinmetall.com is the official web presence of Rheinmetall, a prominent German corporation operating within the manufacturing and engineering sectors. The entity provides defense, security, and technology solutions, with operations and research deeply embedded across industrial and engineering domains in Germany and internationally. Within the threat-intelligence index catalog, Rheinmetall.com is categorized specifically as a ransomware victim linked to the Babuk2 threat actor group. This classification reflects the cybersecurity context in which the entity was identified within the index's ransomware incident database. The listing type and associated threat actor provide critical context for threat analysts monitoring industrial sector vulnerabilities. |
||||||
| Ransomware | rheinmetall.com (Rheinmetall Defence) id32971 View details | Germany | Manufacturing / Engineering | — | ||
|
rheinmetall.com (Rheinmetall Defence) |
||||||
| Ransomware | rheinmetall.com (Rheinmetall Defence) id18944 View details | Germany | Manufacturing / Engineering | — | ||
|
rheinmetall.com (Rheinmetall Defence) |
||||||
| Ransomware | gangotreehomes.com (RealEstate) id18941 View details | India | NGOs / Associations | — | ||
|
gangotreehomes.com (RealEstate) |
||||||
| Ransomware | gangotreehomes.com (RealEstate) id32973 View details | India | NGOs / Associations | — | ||
|
gangotreehomes.com operates within the Construction and Real Estate sector and is situated in India. The entity represents a business organization whose infrastructure was impacted by a cyber incident. According to the threat-intelligence index, gangotreehomes.com is cataloged as a ransomware victim linked to the babuk2 threat actor. This listing type indicates that the organization experienced ransomware activity connected to babuk2, without disclosing confirmed technical details, stolen data, or financial impact. The entry serves as a reference point within the ransomware victim index for monitoring sector-specific cyber threats. |
||||||
| Ransomware | gangotreehomes.com (RealEstate) id32973 View details | India | NGOs / Associations | — | ||
|
gangotreehomes.com (RealEstate) |
||||||
| Ransomware | gangotreehomes.com (RealEstate) id18941 View details | India | NGOs / Associations | — | ||
|
gangotreehomes.com (RealEstate) |
||||||
| Ransomware | Secret plans of Indian army id18940 View details | Other | — | |||
|
Secret plans of Indian army |
||||||
| Ransomware | Secret plans of Indian army id32974 View details | Other | — | |||
|
Secret plans of Indian army refers to classified operational and strategic documentation maintained within the Indian Army's public sector infrastructure, representing sensitive national defense planning activities. As a ransomware victim entry in this threat-intelligence index, it signifies an instance where such protected governmental assets were targeted by cyber intrusion campaigns. The entity operates within the Public Sector domain of India, where defense-related systems face persistent threats from sophisticated malware families. This listing type identifies the asset as compromised under the attack profile of babuk2, a threat actor known for deploying ransomware across critical infrastructure sectors. The entry documents the association between national security-related plans and the babuk2 campaign without confirming specific breach details. |
||||||
| Ransomware | Secret plans of Indian army id32974 View details | Other | — | |||
|
Secret plans of Indian army |
||||||
| Ransomware | Secret plans of Indian army id18940 View details | Other | — | |||
|
Secret plans of Indian army |
||||||
| Ransomware | Bangladesh Armed Forces (BangLadesh Army) id18939 View details | Bangladesh | Other | — | ||
|
Bangladesh Armed Forces (BangLadesh Army) |
||||||
| Ransomware | Bangladesh Armed Forces (BangLadesh Army) id32975 View details | Bangladesh | Other | — | ||
|
Bangladesh Armed Forces (BangLadesh Army) is the principal land warfare branch of Bangladesh's national armed forces, operating within the country's public sector framework. The entity provides military defense, territorial security, and public safety services for Bangladesh, reflecting its role within government and national infrastructure protection. This listing type identifies Bangladesh Armed Forces as a ransomware victim entity linked to the babuk2 threat actor. The association places this public sector organization within the threat-intelligence index under ransomware incidents tied to babuk2 activity in Bangladesh. It was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | Bangladesh Armed Forces (BangLadesh Army) id32975 View details | Bangladesh | Other | — | ||
|
Bangladesh Armed Forces (BangLadesh Army) |
||||||
| Ransomware | Bangladesh Armed Forces (BangLadesh Army) id18939 View details | Bangladesh | Other | — | ||
|
Bangladesh Armed Forces (BangLadesh Army) |
||||||
| Ransomware | Saudi Arabian military and government internal center id18938 View details | Saudi Arabia | Public Sector | — | ||
|
Saudi Arabian military and government internal center |
||||||
| Ransomware | Saudi Arabian military and government internal center id32976 View details | Saudi Arabia | Public Sector | — | ||
|
The Saudi Arabian military and government internal center is a Saudi Arabian institution operating within the Public Sector, supporting internal administrative, operational, and defense-related functions for military and government entities. Its role encompasses centralized coordination, data management, and institutional support services aligned with national security and governance requirements across the Kingdom. This listing identifies the entity as a ransomware victim associated with the threat actor babuk2, reflecting cybersecurity exposure within critical public infrastructure. The description remains neutral and avoids speculative claims regarding compromised assets, data exfiltration, or financial impact. Authorities and sector stakeholders monitor such incidents to strengthen resilience against evolving cyber threats targeting government and military systems in Saudi Arabia. |
||||||
| Ransomware | Saudi Arabian military and government internal center id32976 View details | Saudi Arabia | Public Sector | — | ||
|
Saudi Arabian military and government internal center |
||||||
| Ransomware | Saudi Arabian military and government internal center id18938 View details | Saudi Arabia | Public Sector | — | ||
|
Saudi Arabian military and government internal center |
||||||
| Ransomware | Hellenic Airforce id18937 View details | Greece | Other | — | ||
|
Hellenic Airforce |
||||||
| Ransomware | Hellenic Airforce id32977 View details | Greece | Other | — | ||
|
The Hellenic Airforce is Greece's national air force, a Public Sector organization responsible for military aviation operations, national defense support, and security-related capabilities within the country of Greece. As a Public Sector entity, it represents critical infrastructure and government-linked functions within the GR national defense framework. This listing identifies the Hellenic Airforce as a ransomware victim associated with the threat actor babuk2. The entry reflects threat-intelligence catalog data documenting the entity's relationship to this specific cyber threat actor without confirming breach details, stolen data, or operational impact. This record serves threat analysts and security professionals monitoring Public Sector ransomware incidents across GR. |
||||||
| Ransomware | Hellenic Airforce id32977 View details | Greece | Other | — | ||
|
Hellenic Airforce |
||||||
| Ransomware | Hellenic Airforce id18937 View details | Greece | Other | — | ||
|
Hellenic Airforce |
||||||
| Ransomware | ezbuy.sg (Singapore Shopping) id18934 View details | Singapore | Retail / E-commerce | — | ||
|
ezbuy.sg (Singapore Shopping) |
||||||
| Ransomware | ezbuy.sg (Singapore Shopping) id32978 View details | Singapore | Retail / E-commerce | — | ||
|
ezbuy.sg operates within the retail and e-commerce sector, based in Singapore. The entity is cataloged as a ransomware victim within this threat-intelligence index, with an associated threat actor identified as babuk2. The listing reflects the cybersecurity classification of the organization in relation to this threat actor without disclosing unverified incident details, such as stolen data, ransom terms, or confirmed breach specifics. This entry provides neutral, encyclopedic context for researchers and defenders assessing ransomware exposure across retail and e-commerce environments in the region. |
||||||
| Ransomware | ezbuy.sg (Singapore Shopping) id32978 View details | Singapore | Retail / E-commerce | — | ||
|
ezbuy.sg (Singapore Shopping) |
||||||
| Ransomware | ezbuy.sg (Singapore Shopping) id18934 View details | Singapore | Retail / E-commerce | — | ||
|
ezbuy.sg (Singapore Shopping) |
||||||
| Ransomware | Iran gas service system id18933 View details | Iran, Islamic Republic of | Energy | — | ||
|
Iran gas service system, |
||||||
| Ransomware | Iran gas service system id32979 View details | Iran, Islamic Republic of | Energy | — | ||
|
The Iran gas service system is a national energy infrastructure component responsible for gas distribution, supply coordination, metering, and operational support across Iran's energy sector. As an entity within the Energy sector of Iran, it provides essential public and commercial gas service functions, making it a critical operational asset with potential exposure to cyber incidents. This listing identifies the Iran gas service system as a ransomware victim linked to the threat actor babuk2, reflecting its inclusion in the threat-intelligence index based on associated cyber activity. The description remains neutral and avoids speculative claims regarding data theft, ransom demands, or confirmed breach details, focusing solely on the entity's sector role and its association with babuk2. |
||||||
| Ransomware | Iran gas service system id32979 View details | Iran, Islamic Republic of | Energy | — | ||
|
Iran gas service system, |
||||||
| Ransomware | Iran gas service system id18933 View details | Iran, Islamic Republic of | Energy | — | ||
|
Iran gas service system, |
||||||
| Ransomware | kfar hatta medical center - Lebanon id18932 View details | Lebanon | Healthcare / Pharma | — | ||
|
kfar hatta medical center - Lebanon |
||||||
| Ransomware | kfar hatta medical center - Lebanon id32980 View details | Lebanon | Healthcare / Pharma | — | ||
|
kfar hatta medical center - Lebanon operates within the healthcare and medicine sector, providing medical services in Lebanon. The entity is cataloged in this threat-intelligence index as a ransomware victim linked to the babuk2 threat actor. This listing type indicates a cybersecurity incident involving ransomware activity targeting a healthcare organization. The entry reflects observed threat-intelligence data concerning the entity and its association with babuk2 without detailing unverified incident specifics such as data exfiltration scope or ransom demands. The record serves to inform security professionals and stakeholders about ransomware exposure within the healthcare sector in Lebanon. |
||||||
| Ransomware | kfar hatta medical center - Lebanon id32980 View details | Lebanon | Healthcare / Pharma | — | ||
|
kfar hatta medical center - Lebanon |
||||||
| Ransomware | kfar hatta medical center - Lebanon id18932 View details | Lebanon | Healthcare / Pharma | — | ||
|
kfar hatta medical center - Lebanon |
||||||
| Ransomware | Polizia italia mail access id18930 View details | Italy | Other | — | ||
|
Polizia italia mail access |
||||||
| Ransomware | Polizia italia mail access id32981 View details | Italy | Other | — | ||
|
poliziadistato.it is an entity operating within the IT sector, specifically within Hospitality, Food & Beverage, and Tourism environments, where digital security vulnerabilities are prevalent. The domain functions as an online presence associated with operational services relevant to this sector. It is cataloged in the threat-intelligence index as a ransomware victim, with the associated threat actor and source identified as babuk2. This listing reflects the entity's documented relationship to this cyber threat within the indexed intelligence records. The description remains factual and neutral regarding the incident specifics. |
||||||
| Ransomware | Polizia italia mail access id32981 View details | Italy | Other | — | ||
|
Polizia italia mail access |
||||||
| Ransomware | Polizia italia mail access id18930 View details | Italy | Other | — | ||
|
Polizia italia mail access |
||||||
| Ransomware | zalora.sg (Singapore Shopping) id18929 View details | Singapore | Retail / E-commerce | — | ||
|
zalora.sg (Singapore Shopping) |
||||||
| Ransomware | zalora.sg (Singapore Shopping) id32982 View details | Singapore | Retail / E-commerce | — | ||
|
Zalora.sg operates within the retail and e-commerce sector based in Singapore, providing digital commerce solutions and customer-facing services to support business operations across Southeast Asia. As a prominent online retail platform, its infrastructure and data systems represent critical assets within the regional e-commerce landscape. This entity has been formally cataloged as a ransomware victim associated with the threat actor babuk2, reflecting the cybersecurity risks inherent to digital retail environments. The listing underscores the importance of threat intelligence monitoring for sector-specific vulnerabilities and highlights the necessity of robust defenses against evolving ransomware campaigns targeting commercial enterprises in Asian markets. This entry serves as a reference point for security professionals assessing exposure within retail and e-commerce infrastructures. |
||||||
| Ransomware | zalora.sg (Singapore Shopping) id32982 View details | Singapore | Retail / E-commerce | — | ||
|
zalora.sg (Singapore Shopping) |
||||||
| Ransomware | zalora.sg (Singapore Shopping) id18929 View details | Singapore | Retail / E-commerce | — | ||
|
zalora.sg (Singapore Shopping) |
||||||
| Ransomware | ascires.com id18920 View details | Spain | Other | — | ||
|
ascires.com |
||||||
| Ransomware | ascires.com id32983 View details | Spain | Other | — | ||
|
Ascires.com operates within the information technology sector and is associated with the ES region. The entity is cataloged in the threat-intelligence index under the listing type ransomware victim, specifically linked to the threat actor babuk2. This entry documents the observed relationship between Ascires.com and babuk2 within cybersecurity intelligence records. No additional incident specifics such as stolen data, record counts, ransom demands, or confirmed breach details are included in this description. The listing serves as a neutral reference point for threat actors, defenders, and intelligence consumers monitoring ransomware activity in IT environments. |
||||||
| Ransomware | ascires.com id32983 View details | Spain | Other | — | ||
|
ascires.com |
||||||
| Ransomware | ascires.com id18920 View details | Spain | Other | — | ||
|
ascires.com |
||||||
| Ransomware | aosense.com - AO Sense INC. id18919 View details | United States | Services | — | ||
|
aosense.com - AO Sense INC. |
||||||
| Ransomware | aosense.com - AO Sense INC. id32984 View details | United States | Services | — | ||
|
Aosense.com operates within the United States manufacturing and engineering sectors, providing specialized operational intelligence and monitoring services relevant to industrial workflows and supply chain integrity. The entity is cataloged in the threat-intelligence index under the designation ransomware victim, with its primary associated threat actor and source identified as Babuk2. This listing reflects the cybersecurity community's documentation of the entity's exposure within the Babuk2 threat landscape without disclosing unverified incident details. The classification underscores the importance of monitoring industrial sectors for evolving ransomware tactics and their impacts on engineering and production environments. |
||||||
| Ransomware | aosense.com - AO Sense INC. id32984 View details | United States | Services | — | ||
|
aosense.com - AO Sense INC. |
||||||
| Ransomware | aosense.com - AO Sense INC. id18919 View details | United States | Services | — | ||
|
aosense.com - AO Sense INC. |
||||||
| Ransomware | dardoc.com id18918 View details | Denmark | Other | — | ||
|
dardoc.com |
||||||
| Ransomware | dardoc.com id32985 View details | Denmark | Other | — | ||
|
dardoc.com operates within the IT sector and is situated in Denmark (DK). The entity is cataloged within this threat-intelligence index under the listing type ransomware victim, explicitly linked to the threat actor babuk2. This classification reflects the entity's documented association with this specific ransomware campaign, providing cybersecurity professionals with contextual intelligence for threat monitoring and incident response planning. The entry serves as a reference point for understanding organizational exposure within the broader landscape of cybercrime targeting IT infrastructure across European regions. No additional incident specifics, such as data stolen or ransom demands, are included per strict factual constraints. |
||||||
| Ransomware | dardoc.com id32985 View details | Denmark | Other | — | ||
|
dardoc.com |
||||||
| Ransomware | dardoc.com id18918 View details | Denmark | Other | — | ||
|
dardoc.com |
||||||
| Ransomware | navy-mil-bd id18916 View details | Bangladesh | Other | — | ||
|
navy-mil-bd |
||||||
| Ransomware | navy-mil-bd id32986 View details | Bangladesh | Other | — | ||
|
Navy-mil-bd is an entity identified within the threat-intelligence index as a ransomware victim. Operating within the military sector context and located in Bangladesh (BD), the entity represents a target profile relevant to cyber threat analysis. Its classification as a ransomware victim associated with the threat actor Babuk2 highlights its role in tracking active malware campaigns targeting specific sectors and geographies. This listing serves to catalog the entity's exposure profile without disclosing unverified incident details. The entry supports comprehensive threat intelligence monitoring and contextualizes the entity within broader cybersecurity threat landscapes. |
||||||
| Ransomware | navy-mil-bd id32986 View details | Bangladesh | Other | — | ||
|
navy-mil-bd |
||||||
| Ransomware | navy-mil-bd id18916 View details | Bangladesh | Other | — | ||
|
navy-mil-bd |
||||||
| Ransomware | drdo.gov.in id18901 View details | India | Other | — | ||
|
drdo.gov.in |
||||||
| Ransomware | drdo.gov.in id32987 View details | India | Other | — | ||
|
drdo.gov.in operates within the Indian information technology sector, serving governmental or public-sector digital functions based on its domain classification. The entity is documented within this threat-intelligence index under the listing type ransomware victim, specifically linked to the threat actor babuk2. Babuk2 is recognized as a malware family associated with ransomware activity targeting infrastructure across multiple regions. This entry provides neutral context for threat analysts tracking cyber incidents in India's IT sector and the associated adversary landscape. The listing reflects the entity's status as a ransomware victim connected to babuk2, without disclosing unverified incident details. |
||||||
| Ransomware | drdo.gov.in id32987 View details | India | Other | — | ||
|
drdo.gov.in |
||||||
| Ransomware | drdo.gov.in id18901 View details | India | Other | — | ||
|
drdo.gov.in |
||||||
| Ransomware | uniproof.com.br id18900 View details | Brazil | Communication / Marketing | — | ||
|
uniproof.com.br |
||||||
| Ransomware | uniproof.com.br id32988 View details | Brazil | Communication / Marketing | — | ||
|
uniproof.com.br is a Brazilian services-sector entity operating within the domain of professional and service-oriented business activities in Brazil. The company is cataloged in this threat-intelligence index under the designation ransomware victim, with the associated threat actor and source identified as babuk2. This listing reflects the entity's inclusion in threat-intelligence records where babuk2 activity is reported in relation to the organization. No specific incident details such as data stolen, records impacted, ransom demands, or confirmed breach scope are included, in accordance with strict factual and neutral reporting standards. The entry provides a structured overview for cybersecurity professionals monitoring ransomware exposure across service sectors in Brazil. |
||||||
| Ransomware | uniproof.com.br id32988 View details | Brazil | Communication / Marketing | — | ||
|
uniproof.com.br |
||||||
| Ransomware | uniproof.com.br id18900 View details | Brazil | Communication / Marketing | — | ||
|
uniproof.com.br |
||||||
| Ransomware | (UPDATE) - whitecapcanada.com id18897 View details | Canada | Other | — | ||
|
(UPDATE) - whitecapcanada.com |
||||||
| Ransomware | (UPDATE) - whitecapcanada.com id32989 View details | Canada | Other | — | ||
|
whitecapcanada.com operates within the Services sector and is headquartered in Canada. The entity functions as a commercial organization providing service-oriented offerings, with its inclusion in this threat-intelligence index reflecting its status as a ransomware victim. Its listing is specifically associated with the threat actor babuk2, a malware family historically targeting service and enterprise environments. This catalog entry documents the correlation between the entity and the identified threat actor without disclosing unverified incident details. The record serves threat analysts to contextualize potential attack surfaces and monitor subsequent intelligence developments related to this organization and its associated ransomware threat. |
||||||
| Ransomware | (UPDATE) - whitecapcanada.com id32989 View details | Canada | Other | — | ||
|
(UPDATE) - whitecapcanada.com |
||||||
| Ransomware | (UPDATE) - whitecapcanada.com id18897 View details | Canada | Other | — | ||
|
(UPDATE) - whitecapcanada.com |
||||||
| Ransomware | pln.co.id - PLN INDONESIA id18861 View details | Indonesia | Other | — | ||
|
pln.co.id - PLN INDONESIA |
||||||
| Ransomware | pln.co.id - PLN INDONESIA id32990 View details | Indonesia | Other | — | ||
|
pln.co.id is an entity operating within the IT sector located in Indonesia. Its domain and operational profile align with technology services and infrastructure management within the country's digital economy. Within threat-intelligence indexing frameworks, this entity is formally categorized as a ransomware victim. The association with threat actor babuk2 indicates its inclusion in records documenting ransomware activity targeting IT-focused organizations. This listing provides neutral context for analysts monitoring cyber threats and incident correlations across sectors and geographies. |
||||||
| Ransomware | pln.co.id - PLN INDONESIA id32990 View details | Indonesia | Other | — | ||
|
pln.co.id - PLN INDONESIA |
||||||
| Ransomware | pln.co.id - PLN INDONESIA id18861 View details | Indonesia | Other | — | ||
|
pln.co.id - PLN INDONESIA |
||||||
| Ransomware | moh.gov.rw id18860 View details | Rwanda | Other | — | ||
|
moh.gov.rw |
||||||
| Ransomware | moh.gov.rw id32991 View details | Rwanda | Other | — | ||
|
moh.gov.rw is the official domain of the Ministry of Health within the Republic of Rwanda, representing a public sector entity responsible for national health administration, policy, and service delivery. Operating within the Public Sector in country RW, the entity provides essential governmental health functions and infrastructure. This listing identifies moh.gov.rw as a ransomware victim associated with the threat actor babuk2. The entry reflects threat-intelligence indexing of this entity within the context of cyber incidents targeting public infrastructure. No specific breach details, data stolen, or ransom terms are included per strict factual reporting guidelines. |
||||||
| Ransomware | moh.gov.rw id32991 View details | Rwanda | Other | — | ||
|
moh.gov.rw |
||||||
| Ransomware | moh.gov.rw id18860 View details | Rwanda | Other | — | ||
|
moh.gov.rw |
||||||
| Ransomware | iDRAC (Integrated Dell Remote Access Controller) management interface for Dell servers id18795 View details | United States | Services | — | ||
|
iDRAC (Integrated Dell Remote Access Controller) management interface for Dell servers |
||||||
| Ransomware | iDRAC (Integrated Dell Remote Access Controller) management interface for Dell servers id32993 View details | United States | Services | — | ||
|
iDRAC, the Integrated Dell Remote Access Controller management interface for Dell servers, provides remote administration, hardware monitoring, firmware management, and security configuration capabilities for enterprise IT infrastructure. It enables administrators to manage server operations, diagnose hardware issues, apply updates, and enforce access controls across Dell server fleets within the IT sector. In this catalog entry, the interface is documented as a ransomware victim associated with babuk2, a threat actor operating from the United States. This listing reflects the entity's exposure within threat-intelligence indexing without confirming specific breach details, data loss, or operational impact. The description focuses on the management interface's role and its association with the identified threat actor for catalog and intelligence purposes. |
||||||
| Ransomware | iDRAC (Integrated Dell Remote Access Controller) management interface for Dell servers id32993 View details | United States | Services | — | ||
|
iDRAC (Integrated Dell Remote Access Controller) management interface for Dell servers |
||||||
| Ransomware | iDRAC (Integrated Dell Remote Access Controller) management interface for Dell servers id18795 View details | United States | Services | — | ||
|
iDRAC (Integrated Dell Remote Access Controller) management interface for Dell servers |
||||||
| Ransomware | elsoms.com id18782 View details | United Kingdom | Other | — | ||
|
elsoms.com |
||||||
| Ransomware | elsoms.com id32994 View details | United Kingdom | Other | — | ||
|
elsoms.com operates within the Services sector and is headquartered in the United Kingdom. The entity provides professional services, though specific service offerings are not disclosed in public threat-intelligence records. It has been formally listed within the threat-intelligence index as a ransomware victim associated with the threat actor babuk2. This designation reflects the cybersecurity context in which the entity was identified, without confirming specific intrusion details or operational impact. The listing serves to inform analysts tracking ransomware campaigns and related threat actor activity across sectors and geographies. |
||||||
| Ransomware | elsoms.com id32994 View details | United Kingdom | Other | — | ||
|
elsoms.com |
||||||
| Ransomware | elsoms.com id18782 View details | United Kingdom | Other | — | ||
|
elsoms.com |
||||||
| Ransomware | brune.com.br - Group MC (conglomerate) id18781 View details | Brazil | Services | — | ||
|
brune.com.br - Group MC (conglomerate) |
||||||
| Ransomware | brune.com.br - Group MC (conglomerate) id32995 View details | Brazil | Services | — | ||
|
brune.com.br is a services-sector company based in Brazil (country: BR), operating within the broader digital and professional services marketplace. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, linked to the associated threat actor babuk2. This classification reflects the inclusion of brune.com.br within the ransomware incident dataset tied to babuk2 activity, without disclosing unverified details regarding breach scope, data accessed, or operational impact. The entry provides neutral, authoritative context for researchers and defenders monitoring service-sector entities in Brazil against ransomware threats. brune.com.br was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | brune.com.br - Group MC (conglomerate) id32995 View details | Brazil | Services | — | ||
|
brune.com.br - Group MC (conglomerate) |
||||||
| Ransomware | brune.com.br - Group MC (conglomerate) id18781 View details | Brazil | Services | — | ||
|
brune.com.br - Group MC (conglomerate) |
||||||