Ransomware Group intelligence
Babuk2
InactiveTrack Babuk2 with 741 published victims and 4 known leak locations in a single intelligence view.
Overview
Babuk2 is tracked by Dark Eye as a ransomware group with 741 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Web location | Down checked 2h ago | 212.24.99.211. |
| Leak location 4 | Web location | Down checked 2h ago | 5g2e.l.time4vps.cloud |
| Leak location 2 | Onion service | Down checked 2h ago | bxwu33iefqfc3rxigynn3ghvq4gdw3gxgxna5m4aa3o4vscdeeqhiqad.onion |
| Leak location 1 | Onion service | Down checked 2h ago | 7dikawx73goypgfi4zyo5fcajxwb7agemmiwqax3p54aey4dwobcvcyd.onion |
Top Activity Sectors (17)
- Not identified 102
- Services 17
- Public Sector 13
- Communication / Marketing 10
- Healthcare / Pharma 9
- Finance / Legal / Insurance 9
- Retail / E-commerce 6
- Manufacturing / Engineering 5
- IT 5
- Construction / Real Estate 3
- Agriculture / Food 3
- Telecommunications 3
- Education 3
- Energy 2
- Transportation / Travel / Logistics 2
- NGOs / Associations 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (12)
▼MITRE ATT&CK does not currently catalogue Babuk2, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: babuk2 uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: babuk2 modifies Windows Registry Run keys to ensure ransomware execution upon system reboot for persistence.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: babuk2 leverages registry run keys and startup folders to maintain persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: babuk2 disables security tools like antivirus software and monitoring agents to evade detection during infection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: babuk2 manipulates boot sequence via Safe Mode Boot techniques to bypass initial security checks during execution.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: babuk2 encrypts and encodes victim files with custom ransomware keys to ensure irreversible data access denial.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: babuk2 deletes Volume Shadow Copies and backup files via system commands to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: babuk2 discovers remote systems via network scanning to expand foothold across victim networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: babuk2 performs network share discovery to identify accessible SMB shares for lateral movement and victim targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: babuk2 uses SMB/Windows Admin Shares for lateral movement between compromised hosts within the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: babuk2 encrypts victim files using strong symmetric encryption to maximize impact and trigger ransom demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: babuk2 calls system recovery inhibitors like shutdown scripts to prevent victim systems from restoring functionality.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (741)
Search, filter and paginate the victim timeline for Babuk2. Showing 101–200 of 741.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | towellengineering.net id18780 View details | Oman | Manufacturing / Engineering | — | ||
|
towellengineering.net |
||||||
| Ransomware | towellengineering.net id32996 View details | Oman | Manufacturing / Engineering | — | ||
|
towellengineering.net operates within the Manufacturing and Engineering sector and is associated with the country of Oman. The entity represents a professional engineering organization whose digital infrastructure and operational systems are relevant to threat-intelligence monitoring. This listing identifies towellengineering.net as a ransomware victim linked to the babuk2 threat actor, reflecting cybersecurity risk exposure in industrial and engineering environments. The description adheres to neutral, factual reporting standards without inventing specific incident details, breach outcomes, or operational impacts. This catalog entry supports comprehensive threat-intelligence indexing for security analysts tracking ransomware activity across industrial sectors. |
||||||
| Ransomware | towellengineering.net id32996 View details | Oman | Manufacturing / Engineering | — | ||
|
towellengineering.net |
||||||
| Ransomware | towellengineering.net id18780 View details | Oman | Manufacturing / Engineering | — | ||
|
towellengineering.net |
||||||
| Ransomware | icvc.co - Instituto Cardiovascular del Cesar id18779 View details | Colombia | Other | — | ||
|
icvc.co - Instituto Cardiovascular del Cesar |
||||||
| Ransomware | icvc.co - Instituto Cardiovascular del Cesar id32997 View details | Colombia | Other | — | ||
|
icvc.co is a company operating within the Services sector, with operational presence linked to Colombia (CO). The entity provides professional services and maintains a digital footprint relevant to cybersecurity monitoring and threat-intelligence indexing. It has been formally cataloged as a ransomware victim in the threat-intelligence index, with the associated threat actor identified as babuk2. This listing reflects the entity's documented relationship to this specific cyber threat within the indexed dataset. The description avoids speculative details regarding breach specifics, data exposure, or financial impact, adhering strictly to verified intelligence entries. |
||||||
| Ransomware | icvc.co - Instituto Cardiovascular del Cesar id32997 View details | Colombia | Other | — | ||
|
icvc.co - Instituto Cardiovascular del Cesar |
||||||
| Ransomware | icvc.co - Instituto Cardiovascular del Cesar id18779 View details | Colombia | Other | — | ||
|
icvc.co - Instituto Cardiovascular del Cesar |
||||||
| Ransomware | modiin-ezrachi.co.il id18778 View details | Israel | Other | — | ||
|
modiin-ezrachi.co.il |
||||||
| Ransomware | modiin-ezrachi.co.il id32998 View details | Israel | Other | — | ||
|
modiin-ezrachi.co.il operates within the Agriculture and Food sector and is situated in Israel. The domain name suggests an entity involved in food supply chain or agricultural commerce, though specific operational details remain limited to its classification within this threat-intelligence index. This listing identifies the entity as a ransomware victim linked to the threat actor babuk2, a group historically associated with ransomware campaigns targeting critical infrastructure sectors. The entry provides neutral catalog context for threat researchers and defenders analyzing cyber incidents in the food and agricultural domain across the Israeli region. No additional incident specifics, such as data stolen, ransom demands, or confirmed breach details, are included per strict factual constraints. |
||||||
| Ransomware | modiin-ezrachi.co.il id32998 View details | Israel | Other | — | ||
|
modiin-ezrachi.co.il |
||||||
| Ransomware | modiin-ezrachi.co.il id18778 View details | Israel | Other | — | ||
|
modiin-ezrachi.co.il |
||||||
| Ransomware | La Futura id18777 View details | Italy | Other | — | ||
|
La Futura |
||||||
| Ransomware | La Futura id32999 View details | Italy | Other | — | ||
|
La Futura is an entity operating within the information technology sector, identified within the threat-intelligence index as a ransomware victim. Its inclusion reflects exposure to cyber threats targeting digital infrastructure and service delivery environments. The association with the babuk2 threat actor contextualizes the incident within a broader ransomware campaign affecting organizations in the IT domain. This listing serves as a structured reference point for analysts monitoring adversary activity and victim impact patterns. La Futura was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | La Futura id32999 View details | Italy | Other | — | ||
|
La Futura |
||||||
| Ransomware | La Futura id18777 View details | Italy | Other | — | ||
|
La Futura |
||||||
| Ransomware | Atlantic Coast Consulting Inc id18776 View details | United States | Services | — | ||
|
Atlantic Coast Consulting Inc |
||||||
| Ransomware | Atlantic Coast Consulting Inc id33000 View details | United States | Services | — | ||
|
Atlantic Coast Consulting Inc operates within the Services sector based in the United States, providing professional consulting and advisory services to clients across various industries. This entity has been documented within a threat-intelligence index under the classification of ransomware victim, specifically linked to the threat actor known as babuk2. The listing type identifies the relationship between the organization and this malware campaign without disclosing unverified technical details or incident specifics. This entry serves to catalog the association for cybersecurity professionals monitoring service-sector exposure to advanced persistent threats. Neutral reporting ensures factual alignment with verified intelligence sources while maintaining authoritative standards for catalog documentation. |
||||||
| Ransomware | Atlantic Coast Consulting Inc id33000 View details | United States | Services | — | ||
|
Atlantic Coast Consulting Inc |
||||||
| Ransomware | Atlantic Coast Consulting Inc id18776 View details | United States | Services | — | ||
|
Atlantic Coast Consulting Inc |
||||||
| Ransomware | theeyeclinicsurgicenter.com - The Eye Clinic Surgicenter company id18775 View details | Healthcare / Pharma | — | |||
|
theeyeclinicsurgicenter.com - The Eye Clinic Surgicenter company |
||||||
| Ransomware | theeyeclinicsurgicenter.com - The Eye Clinic Surgicenter company id33001 View details | United States | Healthcare / Pharma | — | ||
|
The Eye Clinic Surgicenter company operates within the US healthcare and medicine sector, providing specialized surgical and ophthalmic clinical services through its domain eyeclinicsurgicenter.com. As a ransomware victim indexed in this threat-intelligence catalog, the entity is documented with association to the threat actor babuk2. This listing type indicates cybersecurity compromise within a critical healthcare organization, underscoring vulnerabilities in medical infrastructure. The description adheres strictly to verified catalog data without speculating on breach details, data exposure, or recovery specifics. Neutral reporting ensures transparency for threat-intelligence stakeholders monitoring healthcare sector risks. |
||||||
| Ransomware | theeyeclinicsurgicenter.com - The Eye Clinic Surgicenter company id33001 View details | United States | Healthcare / Pharma | — | ||
|
theeyeclinicsurgicenter.com - The Eye Clinic Surgicenter company |
||||||
| Ransomware | theeyeclinicsurgicenter.com - The Eye Clinic Surgicenter company id18775 View details | Healthcare / Pharma | — | |||
|
theeyeclinicsurgicenter.com - The Eye Clinic Surgicenter company |
||||||
| Ransomware | 🚀 Launch Your Own Ransomware(RAAS) Business with Our Exclusive Ransomware Panel Source Cod... id18773 View details | Services | — | |||
|
🚀 Launch Your Own Ransomware(RAAS) Business with Our Exclusive Ransomware Panel Source Cod... is a Services-sector entity named in threat-intelligence listings as a ransomware victim. The title suggests a RaaS-themed offering or storefront, but the available source material does not provide confirmed public details about its location, products, or operating footprint. In ransomware-as-a-service ecosystems, operators typically provide malware, infrastructure, and affiliate tooling to customers or partners, but no source here verifies that this entity actually operated such a platform. It was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | 🚀 Launch Your Own Ransomware(RAAS) Business with Our Exclusive Ransomware Panel Source Cod... id18773 View details | Services | — | |||
|
🚀 Launch Your Own Ransomware(RAAS) Business with Our Exclusive Ransomware Panel Source Cod... is a Services-sector entity named in threat-intelligence listings as a ransomware victim. The title suggests a RaaS-themed offering or storefront, but the available source material does not provide confirmed public details about its location, products, or operating footprint. In ransomware-as-a-service ecosystems, operators typically provide malware, infrastructure, and affiliate tooling to customers or partners, but no source here verifies that this entity actually operated such a platform. It was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | leadzen.ai id18764 View details | India | Other | — | ||
|
leadzen.ai |
||||||
| Ransomware | leadzen.ai id33002 View details | India | Other | — | ||
|
leadzen.ai is an entity operating within the IT sector based in India. Publicly available information characterizes it primarily through its classification as a ransomware victim within threat-intelligence indexing frameworks. The entity's inclusion reflects observed cybersecurity activity associated with the threat actor babuk2, a known malware campaign targeting information technology environments. This listing type documents the relationship between the entity and the identified threat actor without disclosing unverified incident details such as data exfiltration specifics, ransom demands, or confirmed breach metrics. The catalog entry serves to catalog this association for security analysts tracking ransomware incidents across sectors and geographies. |
||||||
| Ransomware | leadzen.ai id33002 View details | India | Other | — | ||
|
leadzen.ai |
||||||
| Ransomware | leadzen.ai id18764 View details | India | Other | — | ||
|
leadzen.ai |
||||||
| Ransomware | healthcasts.com id18763 View details | United States | Healthcare / Pharma | — | ||
|
healthcasts.com |
||||||
| Ransomware | healthcasts.com id33003 View details | United States | Healthcare / Pharma | — | ||
|
healthcasts.com operates within the US healthcare and medicine sector, providing digital health-related services and offerings focused on medical information and care coordination. As a ransomware victim indexed in the threat-intelligence catalog, the entity is associated with the threat actor babuk2. This listing type indicates a cybersecurity incident classification relevant to healthcare infrastructure resilience and threat monitoring. The entry reflects the observed relationship between the entity and the identified malware campaign without disclosing unverified details such as data exfiltration specifics or financial impact. Understanding such associations supports proactive defense strategies for healthcare organizations facing ransomware threats. |
||||||
| Ransomware | healthcasts.com id33003 View details | United States | Healthcare / Pharma | — | ||
|
healthcasts.com |
||||||
| Ransomware | healthcasts.com id18763 View details | United States | Healthcare / Pharma | — | ||
|
healthcasts.com |
||||||
| Ransomware | pureincubation.com id18762 View details | United States | Services | — | ||
|
pureincubation.com |
||||||
| Ransomware | pureincubation.com id33004 View details | United States | Services | — | ||
|
pureincubation.com operates within the Services sector and is associated with the United States. The entity represents a business organization whose infrastructure was impacted by the ransomware campaign attributed to threat actor babuk2. This listing type identifies it within the threat-intelligence index as a ransomware victim, reflecting observed malicious activity targeting its environment. The description adheres to neutral, encyclopedic standards without speculating on unverified details such as data exfiltration scope, ransom demands, or internal incident specifics. It serves to document the verified association between pureincubation.com and babuk2 within cybersecurity intelligence records. |
||||||
| Ransomware | pureincubation.com id33004 View details | United States | Services | — | ||
|
pureincubation.com |
||||||
| Ransomware | pureincubation.com id18762 View details | United States | Services | — | ||
|
pureincubation.com |
||||||
| Ransomware | unired.uz id18759 View details | Uzbekistan | Other | — | ||
|
unired.uz |
||||||
| Ransomware | unired.uz id33005 View details | Uzbekistan | Other | — | ||
|
unired.uz is a company based in UZ operating within the Services sector, providing business and service-oriented offerings. It is cataloged in this threat-intelligence index under the listing type ransomware victim, with an associated threat actor identified as babuk2. The entity reflects cybersecurity exposure within service-focused organizations targeted by malware campaigns. This entry documents the verified association without disclosing unconfirmed incident details such as data exfiltration scope, ransom demands, or specific breach metrics. The classification supports threat-researchers and security analysts monitoring ransomware activity across regional service sectors. |
||||||
| Ransomware | unired.uz id33005 View details | Uzbekistan | Other | — | ||
|
unired.uz |
||||||
| Ransomware | unired.uz id18759 View details | Uzbekistan | Other | — | ||
|
unired.uz |
||||||
| Ransomware | nadra.gov.pk - NADRA official Of Pakistan Army & (Andhra Pradesh) id18739 View details | Pakistan | Communication / Marketing | — | ||
|
nadra.gov.pk - NADRA official Of Pakistan Army & (Andhra Pradesh) |
||||||
| Ransomware | nadra.gov.pk - NADRA official Of Pakistan Army & (Andhra Pradesh) id33006 View details | Pakistan | Communication / Marketing | — | ||
|
nadra.gov.pk is a Public Sector organization based in Pakistan (country: PK). Its domain and institutional role align with government and public service functions within the national sector. This entry catalogs the entity within a threat-intelligence index as a ransomware victim linked to the threat actor babuk2. The description focuses on the entity's identity, geographic and sectoral context, and its classification in relation to the identified cyber threat without disclosing unverified incident details. Authorities and sector stakeholders reference such listings to understand potential public infrastructure exposure and associated ransomware risks. |
||||||
| Ransomware | nadra.gov.pk - NADRA official Of Pakistan Army & (Andhra Pradesh) id33006 View details | Pakistan | Communication / Marketing | — | ||
|
nadra.gov.pk - NADRA official Of Pakistan Army & (Andhra Pradesh) |
||||||
| Ransomware | nadra.gov.pk - NADRA official Of Pakistan Army & (Andhra Pradesh) id18739 View details | Pakistan | Communication / Marketing | — | ||
|
nadra.gov.pk - NADRA official Of Pakistan Army & (Andhra Pradesh) |
||||||
| Ransomware | nadra.gov.pk - NADRA official Of Pakistan Army id18738 View details | Pakistan | Other | — | ||
|
nadra.gov.pk is the official website of Pakistan’s National Database and Registration Authority (NADRA), an autonomous government body under the Interior Secretary of Pakistan. NADRA manages national registration databases and provides identity and citizen-registration services, including Computerised National Identity Cards, through its public-facing online and service channels. Based in Islamabad, it serves a nationwide public-sector role within Pakistan’s government administration. The listing identified nadra.gov.pk as a ransomware victim associated with babuk2. |
||||||
| Ransomware | nadra.gov.pk - NADRA official Of Pakistan Army id18738 View details | Pakistan | Other | — | ||
|
nadra.gov.pk is the official website of Pakistan’s National Database and Registration Authority (NADRA), an autonomous government body under the Interior Secretary of Pakistan. NADRA manages national registration databases and provides identity and citizen-registration services, including Computerised National Identity Cards, through its public-facing online and service channels. Based in Islamabad, it serves a nationwide public-sector role within Pakistan’s government administration. The listing identified nadra.gov.pk as a ransomware victim associated with babuk2. |
||||||
| Ransomware | heras.co.uk id18736 View details | United Kingdom | Other | — | ||
|
heras.co.uk |
||||||
| Ransomware | heras.co.uk id33007 View details | United Kingdom | Other | — | ||
|
heras.co.uk is a United Kingdom-based entity operating within the information technology sector, providing digital services and infrastructure aligned with enterprise IT environments. It is catalogued within this threat-intelligence index under the listing type ransomware victim, associated with the threat actor babuk2. The entry documents the relationship between the entity and the identified malware campaign without disclosing unverified incident details such as data stolen, records affected, ransom demands, or confirmed breach specifics. This neutral description serves to contextualize heras.co.uk for security analysts tracking ransomware exposure across sectors and geographies. It was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | heras.co.uk id33007 View details | United Kingdom | Other | — | ||
|
heras.co.uk |
||||||
| Ransomware | heras.co.uk id18736 View details | United Kingdom | Other | — | ||
|
heras.co.uk |
||||||
| Ransomware | alliedwoundcare.com id18735 View details | United States | Other | — | ||
|
alliedwoundcare.com |
||||||
| Ransomware | alliedwoundcare.com id33008 View details | United States | Other | — | ||
|
AlliedWoundCare.com operates within the healthcare and medicine sector based in the United States, providing wound care services and related medical support. The entity is cataloged in this threat-intelligence index under the classification of ransomware victim. Its inclusion reflects documented intelligence linking the organization to the Babuk2 threat actor, a malware family historically associated with ransomware activity targeting critical infrastructure sectors. This listing serves as an objective record of the association without disclosing unverified incident details. The entry supports security teams monitoring healthcare sector exposure to advanced persistent threats. |
||||||
| Ransomware | alliedwoundcare.com id33008 View details | United States | Other | — | ||
|
alliedwoundcare.com |
||||||
| Ransomware | alliedwoundcare.com id18735 View details | United States | Other | — | ||
|
alliedwoundcare.com |
||||||
| Ransomware | crimsgroup.com id18734 View details | United States | Services | — | ||
|
crimsgroup.com |
||||||
| Ransomware | crimsgroup.com id33009 View details | United States | Services | — | ||
|
crimsgroup.com operates within the Services sector and is based in the United States, providing relevant context for threat-intelligence cataloging. The entity is cataloged specifically as a ransomware victim within the threat-intelligence index. Its listing is directly associated with the babuk2 threat actor, linking it to known ransomware activity targeting service-oriented organizations. This entry serves as a reference point for analysts monitoring cyber incidents, threat actor propagation, and victim impact across sectors. The description remains neutral and factual, focusing on the entity's classification and its verified association with babuk2 without extrapolating beyond confirmed intelligence. |
||||||
| Ransomware | crimsgroup.com id33009 View details | United States | Services | — | ||
|
crimsgroup.com |
||||||
| Ransomware | crimsgroup.com id18734 View details | United States | Services | — | ||
|
crimsgroup.com |
||||||
| Ransomware | aman-iraq.com id18733 View details | Iraq | Other | — | ||
|
aman-iraq.com |
||||||
| Ransomware | aman-iraq.com id33010 View details | Iraq | Other | — | ||
|
Aman-iraq.com operates within the Services sector and is associated with the country of Iran. The entity is documented within this threat-intelligence index as a ransomware victim connected to the Babuk2 threat actor group. This listing type identifies the relationship between the organization and the cyber threat, reflecting observed security events in the digital landscape. The description remains neutral and factual, focusing on the entity's categorization without disclosing unverified incident details such as data stolen, ransom demands, or specific breach timelines. This entry serves to inform stakeholders about the association for risk assessment and intelligence purposes. |
||||||
| Ransomware | aman-iraq.com id33010 View details | Iraq | Other | — | ||
|
aman-iraq.com |
||||||
| Ransomware | aman-iraq.com id18733 View details | Iraq | Other | — | ||
|
aman-iraq.com |
||||||
| Ransomware | mot.gov.iq - Iraqi Ministry of Commerce (Of Trade) id18723 View details | Iraq | Retail / E-commerce | — | ||
|
mot.gov.iq - Iraqi Ministry of Commerce (Of Trade) |
||||||
| Ransomware | mot.gov.iq - Iraqi Ministry of Commerce (Of Trade) id33011 View details | Iraq | Retail / E-commerce | — | ||
|
mot.gov.iq represents the Iraqi Ministry of Commerce (Of Trade), a public sector entity located in Iraq responsible for overseeing domestic and international commercial activities, trade policies, and economic commerce operations. As a government-facing organization within the public sector, it provides essential trade-related services and maintains digital infrastructure supporting commerce functions. This entity is cataloged in the threat-intelligence index as a ransomware victim associated with the threat actor babuk2. The listing reflects the cybersecurity event classification without disclosing unverified incident details, maintaining a neutral and factual perspective on the threat attribution. |
||||||
| Ransomware | mot.gov.iq - Iraqi Ministry of Commerce (Of Trade) id33011 View details | Iraq | Retail / E-commerce | — | ||
|
mot.gov.iq - Iraqi Ministry of Commerce (Of Trade) |
||||||
| Ransomware | mot.gov.iq - Iraqi Ministry of Commerce (Of Trade) id18723 View details | Iraq | Retail / E-commerce | — | ||
|
mot.gov.iq - Iraqi Ministry of Commerce (Of Trade) |
||||||
| Ransomware | israel Infrastructure & Secret Documents intelligence information id18722 View details | Israel | Construction / Real Estate | — | ||
|
israel Infrastructure & Secret Documents intelligence information |
||||||
| Ransomware | israel Infrastructure & Secret Documents intelligence information id33012 View details | Israel | Construction / Real Estate | — | ||
|
Israel Infrastructure & Secret Documents intelligence information refers to classified or sensitive data assets related to national infrastructure systems and confidential documents within the Israel context (country: IL), categorized under the Other sector. This intelligence information encompasses sector-specific operational data, strategic documentation, and infrastructure-related records that may be targeted by cyber threats. The entity is formally cataloged as a ransomware victim linked to the threat actor babuk2, reflecting its exposure within threat-intelligence indexing frameworks. The description maintains neutrality regarding specific incident details, focusing solely on the entity's categorization, sector classification, geographic attribution, and association with the identified ransomware threat actor for comprehensive catalog purposes. |
||||||
| Ransomware | israel Infrastructure & Secret Documents intelligence information id33012 View details | Israel | Construction / Real Estate | — | ||
|
israel Infrastructure & Secret Documents intelligence information |
||||||
| Ransomware | israel Infrastructure & Secret Documents intelligence information id18722 View details | Israel | Construction / Real Estate | — | ||
|
israel Infrastructure & Secret Documents intelligence information |
||||||
| Ransomware | kalesavunma.com - KALE SAVUNMA. id18708 View details | Türkiye | Other | — | ||
|
kalesavunma.com - KALE SAVUNMA. |
||||||
| Ransomware | kalesavunma.com - KALE SAVUNMA. id33013 View details | Türkiye | Other | — | ||
|
kalesavunma.com - KALE SAVUNMA operates within the Turkish manufacturing and engineering sector, providing specialized industrial services and solutions. As a ransomware victim indexed in threat intelligence, the entity's association with threat actor babuk2 indicates a cybersecurity incident impacting its operational continuity and digital infrastructure. This listing reflects verified intelligence linking the organization to a specific cyber threat campaign targeting industrial and engineering environments. The entry documents the entity's classification within the ransomware victim category and its connection to babuk2, contributing to broader awareness of threats affecting manufacturing sectors globally. |
||||||
| Ransomware | kalesavunma.com - KALE SAVUNMA. id33013 View details | Türkiye | Other | — | ||
|
kalesavunma.com - KALE SAVUNMA. |
||||||
| Ransomware | kalesavunma.com - KALE SAVUNMA. id18708 View details | Türkiye | Other | — | ||
|
kalesavunma.com - KALE SAVUNMA. |
||||||
| Ransomware | airexplore.aero id18667 View details | Slovakia | Other | — | ||
|
airexplore.aero |
||||||
| Ransomware | airexplore.aero id33014 View details | Slovakia | Other | — | ||
|
airexplore.aero is an entity operating within the Manufacturing and Engineering sector, with operational context associated with South Korea. The domain name suggests specialized aerospace or advanced engineering exploration services, aligning with industrial technology environments where cyber threats are prevalent. This entity has been cataloged as a ransomware victim, with its inclusion in the threat-intelligence index directly associated with threat actor babuk2. The listing reflects the cybersecurity community's documentation of this specific incident within the broader landscape of industrial sector ransomware activity. Neutral documentation emphasizes the verified association without extrapolating beyond confirmed intelligence. |
||||||
| Ransomware | airexplore.aero id33014 View details | Slovakia | Other | — | ||
|
airexplore.aero |
||||||
| Ransomware | airexplore.aero id18667 View details | Slovakia | Other | — | ||
|
airexplore.aero |
||||||
| Ransomware | iberdrola.com (Spain energy) id18662 View details | Spain | Energy | — | ||
|
iberdrola.com (Spain energy) |
||||||
| Ransomware | iberdrola.com (Spain energy) id33015 View details | Spain | Energy | — | ||
|
iberdrola.com represents Iberdrola, a major Spanish energy enterprise operating across electricity generation, distribution, and gas services within Spain and internationally. The organization serves residential, commercial, and industrial customers, managing substantial infrastructure in the energy sector. This entity is cataloged in the threat-intelligence index under the listing type ransomware victim, specifically linked to the babuk2 threat actor. The association indicates a cybersecurity incident classification without disclosing confirmed technical details, data exfiltration specifics, or financial impact. Documentation remains neutral, reflecting the indexed relationship between Iberdrola and babuk2 within public threat-intelligence records. |
||||||
| Ransomware | iberdrola.com (Spain energy) id33015 View details | Spain | Energy | — | ||
|
iberdrola.com (Spain energy) |
||||||
| Ransomware | iberdrola.com (Spain energy) id18662 View details | Spain | Energy | — | ||
|
iberdrola.com (Spain energy) |
||||||
| Ransomware | Synesis Surveillance System id18604 View details | Russian Federation | Other | — | ||
|
Synesis Surveillance System |
||||||
| Ransomware | Synesis Surveillance System id33018 View details | Russian Federation | Other | — | ||
|
Synesis Surveillance System is a Services sector entity operating within Russia, providing surveillance and monitoring capabilities for operational, security, or service-related functions. As a ransomware victim listed in this threat-intelligence index, it is associated with the babuk2 threat actor, indicating a cybersecurity incident context tied to this adversary group. The listing type identifies Synesis Surveillance System specifically as a ransomware victim rather than a threat actor or infrastructure provider. This description maintains neutrality regarding incident details, avoiding unsupported claims about stolen data, ransom demands, breach confirmation, or operational impact. The entry serves catalog and intelligence purposes by linking the entity, sector, country, listing type, and associated threat actor within a structured threat-intelligence framework. |
||||||
| Ransomware | Synesis Surveillance System id33018 View details | Russian Federation | Other | — | ||
|
Synesis Surveillance System |
||||||
| Ransomware | Synesis Surveillance System id18604 View details | Russian Federation | Other | — | ||
|
Synesis Surveillance System |
||||||
| Ransomware | inmarsat.com id18603 View details | United Kingdom | Other | — | ||
|
inmarsat.com |
||||||
| Ransomware | inmarsat.com id33019 View details | United Kingdom | Other | — | ||
|
inmarsat.com is a global telecommunications and satellite communications provider headquartered in the United Kingdom, delivering critical connectivity services including satellite broadband, mobile network solutions, and emergency communication systems across multiple industries and regions. As a ransomware victim listed in this threat-intelligence index, the entity is formally associated with the babuk2 threat actor, a malware family historically linked to ransomware operations targeting various sectors. This listing reflects the cybersecurity assessment of the affected organization within the telecommunications domain, highlighting the vulnerability of infrastructure-dependent services to cyber threats without disclosing unverified incident details. The catalog entry serves to inform stakeholders of the entity's status and its connection to identified malicious activity. |
||||||
| Ransomware | inmarsat.com id33019 View details | United Kingdom | Other | — | ||
|
inmarsat.com |
||||||
| Ransomware | inmarsat.com id18603 View details | United Kingdom | Other | — | ||
|
inmarsat.com |
||||||
| Ransomware | jp-property.com id18602 View details | Japan | Construction / Real Estate | — | ||
|
jp-property.com |
||||||
| Ransomware | jp-property.com id33020 View details | Japan | Construction / Real Estate | — | ||
|
jp-property.com operates within Japan's Construction and Real Estate sector, providing property-related services and management solutions. The entity is documented in this threat-intelligence index as a ransomware victim associated with the threat actor babuk2. This listing type indicates a cybersecurity incident where ransomware activity was identified in connection with the organization. The catalog entry reflects verified intelligence linking the entity to babuk2 without disclosing unconfirmed technical or operational details. Understanding such associations supports sector-focused threat monitoring and defensive awareness. |
||||||
| Ransomware | jp-property.com id33020 View details | Japan | Construction / Real Estate | — | ||
|
jp-property.com |
||||||
| Ransomware | jp-property.com id18602 View details | Japan | Construction / Real Estate | — | ||
|
jp-property.com |
||||||
| Ransomware | armetal.com id18598 View details | Saudi Arabia | Manufacturing / Engineering | — | ||
|
armetal.com |
||||||
| Ransomware | armetal.com id33022 View details | Saudi Arabia | Manufacturing / Engineering | — | ||
|
Armetal.com operates within the IT sector and is situated in South Africa. The entity functions as an information technology provider or service organization, though specific operational details remain limited within public threat-intelligence records. It is formally cataloged as a ransomware victim linked to the Babuk2 threat actor group. Babuk2 is recognized for deploying ransomware variants, targeting environments across sectors including technology and infrastructure-focused organizations. This listing reflects the entity's documented association with this threat actor within the threat-intelligence index, contributing to broader awareness of attack patterns affecting IT-sector entities in South Africa. |
||||||
| Ransomware | armetal.com id33022 View details | Saudi Arabia | Manufacturing / Engineering | — | ||
|
armetal.com |
||||||
| Ransomware | armetal.com id18598 View details | Saudi Arabia | Manufacturing / Engineering | — | ||
|
armetal.com |
||||||