Ransomware Group intelligence
Babuk2
InactiveTrack Babuk2 with 741 published victims and 4 known leak locations in a single intelligence view.
Overview
Babuk2 is tracked by Dark Eye as a ransomware group with 741 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Web location | Down checked 2h ago | 212.24.99.211. |
| Leak location 4 | Web location | Down checked 2h ago | 5g2e.l.time4vps.cloud |
| Leak location 2 | Onion service | Down checked 2h ago | bxwu33iefqfc3rxigynn3ghvq4gdw3gxgxna5m4aa3o4vscdeeqhiqad.onion |
| Leak location 1 | Onion service | Down checked 2h ago | 7dikawx73goypgfi4zyo5fcajxwb7agemmiwqax3p54aey4dwobcvcyd.onion |
Top Activity Sectors (17)
- Not identified 102
- Services 17
- Public Sector 13
- Communication / Marketing 10
- Healthcare / Pharma 9
- Finance / Legal / Insurance 9
- Retail / E-commerce 6
- Manufacturing / Engineering 5
- IT 5
- Construction / Real Estate 3
- Agriculture / Food 3
- Telecommunications 3
- Education 3
- Energy 2
- Transportation / Travel / Logistics 2
- NGOs / Associations 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (12)
▼MITRE ATT&CK does not currently catalogue Babuk2, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: babuk2 uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: babuk2 modifies Windows Registry Run keys to ensure ransomware execution upon system reboot for persistence.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: babuk2 leverages registry run keys and startup folders to maintain persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: babuk2 disables security tools like antivirus software and monitoring agents to evade detection during infection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: babuk2 manipulates boot sequence via Safe Mode Boot techniques to bypass initial security checks during execution.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: babuk2 encrypts and encodes victim files with custom ransomware keys to ensure irreversible data access denial.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: babuk2 deletes Volume Shadow Copies and backup files via system commands to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: babuk2 discovers remote systems via network scanning to expand foothold across victim networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: babuk2 performs network share discovery to identify accessible SMB shares for lateral movement and victim targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: babuk2 uses SMB/Windows Admin Shares for lateral movement between compromised hosts within the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: babuk2 encrypts victim files using strong symmetric encryption to maximize impact and trigger ransom demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: babuk2 calls system recovery inhibitors like shutdown scripts to prevent victim systems from restoring functionality.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (741)
Search, filter and paginate the victim timeline for Babuk2. Showing 201–300 of 741.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | 🚀 DB Market – Buy & Sell Databases Safely! id18571 View details | United States | Retail / E-commerce | — | ||
|
DB Market – Buy & Sell Databases Safely! is presented as a US-based retail and e-commerce entity, and its name suggests a business focused on the buying and selling of databases. In threat-intelligence context, Babuk2 has been documented by multiple analysts as a branding operation that recycles victim names and leak pages rather than a proven original Babuk ransomware revival. Public reporting describes Babuk2 as using copied victim entries and false extortion claims to create the appearance of active ransomware activity. DB Market – Buy & Sell Databases Safely! was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | 🚀 DB Market – Buy & Sell Databases Safely! id18571 View details | United States | Retail / E-commerce | — | ||
|
DB Market – Buy & Sell Databases Safely! is presented as a US-based retail and e-commerce entity, and its name suggests a business focused on the buying and selling of databases. In threat-intelligence context, Babuk2 has been documented by multiple analysts as a branding operation that recycles victim names and leak pages rather than a proven original Babuk ransomware revival. Public reporting describes Babuk2 as using copied victim entries and false extortion claims to create the appearance of active ransomware activity. DB Market – Buy & Sell Databases Safely! was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | The Ticktin Law Group id18570 View details | United States | Finance / Legal / Insurance | — | ||
|
The Ticktin Law Group By Babuk Locker 2.0 |
||||||
| Ransomware | The Ticktin Law Group id33023 View details | United States | Finance / Legal / Insurance | — | ||
|
The Ticktin Law Group is a legal, financial, and insurance services entity headquartered in the United States. Operating across finance, legal, and insurance sectors, the organization provides specialized advisory, compliance, and client-facing professional services within highly regulated markets. Within the threat-intelligence index, The Ticktin Law Group is classified as a ransomware victim associated with the babuk2 threat actor. This listing reflects the entity's documented relationship to babuk2 activity without disclosing unverified incident details such as data stolen, ransom demands, or confirmed breach specifics. The record serves to contextualize the organization's sector exposure and its placement within cybersecurity threat reporting frameworks. |
||||||
| Ransomware | The Ticktin Law Group id33023 View details | United States | Finance / Legal / Insurance | — | ||
|
The Ticktin Law Group By Babuk Locker 2.0 |
||||||
| Ransomware | The Ticktin Law Group id18570 View details | United States | Finance / Legal / Insurance | — | ||
|
The Ticktin Law Group By Babuk Locker 2.0 |
||||||
| Ransomware | Mpaj.gov.my id18569 View details | Malaysia | Other | — | ||
|
Mpaj.gov.my |
||||||
| Ransomware | Mpaj.gov.my id33024 View details | Malaysia | Other | — | ||
|
Mpaj.gov.my is a public sector organization located in Malaysia, operating within government services and administrative functions. The entity represents a government-linked infrastructure within the MY national context, providing public-oriented services and administrative capabilities. Within the threat-intelligence index, Mpaj.gov.my is cataloged specifically as a ransomware victim linked to the Babuk2 threat actor. Babuk2 is recognized as a malware family associated with ransomware activity targeting organizations across multiple sectors. This listing type documents the entity's association with this threat actor without disclosing unverified incident details such as stolen data, ransom demands, or confirmed breach specifics. The entry serves to contextualize Mpaj.gov.my within cybersecurity monitoring frameworks for public sector risk assessment. |
||||||
| Ransomware | Mpaj.gov.my id33024 View details | Malaysia | Other | — | ||
|
Mpaj.gov.my |
||||||
| Ransomware | Mpaj.gov.my id18569 View details | Malaysia | Other | — | ||
|
Mpaj.gov.my |
||||||
| Ransomware | exostar.com TOP Defense AS id18568 View details | Other | — | |||
|
exostar.com TOP Defense AS |
||||||
| Ransomware | exostar.com TOP Defense AS id33025 View details | Norway | Other | — | ||
|
exostar.com TOP Defense AS operates within the Manufacturing and Engineering sector and is situated in Norway. The entity provides defense-oriented services and solutions tailored to industrial and engineering applications, serving organizations requiring robust cybersecurity and operational resilience. Within the threat-intelligence index, this listing identifies exostar.com TOP Defense AS as a ransomware victim associated with the threat actor babuk2. This classification reflects the cybersecurity context in which the entity was documented, emphasizing its exposure to ransomware-related activity without disclosing unverified incident details. The entry serves catalog and analytical purposes for monitoring threat actor campaigns and affected sectors. |
||||||
| Ransomware | exostar.com TOP Defense AS id33025 View details | Norway | Other | — | ||
|
exostar.com TOP Defense AS |
||||||
| Ransomware | exostar.com TOP Defense AS id18568 View details | Other | — | |||
|
exostar.com TOP Defense AS |
||||||
| Ransomware | Our Official telegram channel babuk Locker 2.0 id18567 View details | United Kingdom | Other | — | ||
|
Our Official telegram channel babuk Locker 2.0 is a Telegram-based entity located in Great Britain operating within the Other sector. It functions as a platform associated with the Babuk Locker 2.0 ransomware group, which targets victims globally through Telegram channels. The channel is linked to threat actor babuk2, who has published it as a new victim in the ransomware ecosystem. Babuk Locker 2.0 is widely recognized by researchers as a deceptive operation using rebranded LockBit 3.0 code rather than a genuine return of the original group. It was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | Our Official telegram channel babuk Locker 2.0 id18567 View details | United Kingdom | Other | — | ||
|
Our Official telegram channel babuk Locker 2.0 is a Telegram-based entity located in Great Britain operating within the Other sector. It functions as a platform associated with the Babuk Locker 2.0 ransomware group, which targets victims globally through Telegram channels. The channel is linked to threat actor babuk2, who has published it as a new victim in the ransomware ecosystem. Babuk Locker 2.0 is widely recognized by researchers as a deceptive operation using rebranded LockBit 3.0 code rather than a genuine return of the original group. It was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | Standard Capital Securities (Pvt) Backoffice - Pakistan Stock Market Data Vault id18566 View details | Pakistan | Retail / E-commerce | — | ||
|
Standard Capital Securities (Pvt) Backoffice - Pakistan Stock Market Data Vault |
||||||
| Ransomware | Standard Capital Securities (Pvt) Backoffice - Pakistan Stock Market Data Vault id33026 View details | Pakistan | Retail / E-commerce | — | ||
|
Standard Capital Securities (Pvt) Backoffice - Pakistan Stock Market Data Vault operates within the finance, legal, and insurance sectors, providing backoffice services and data management specifically tied to Pakistan Stock Market operations. This entity serves institutional stakeholders requiring secure handling of market-related information and regulatory documentation within the Pakistani financial landscape. It has been formally cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor identified as babuk2. The classification reflects the cybersecurity posture and historical threat exposure of this organization without disclosing unverified incident details. |
||||||
| Ransomware | Standard Capital Securities (Pvt) Backoffice - Pakistan Stock Market Data Vault id33026 View details | Pakistan | Retail / E-commerce | — | ||
|
Standard Capital Securities (Pvt) Backoffice - Pakistan Stock Market Data Vault |
||||||
| Ransomware | Standard Capital Securities (Pvt) Backoffice - Pakistan Stock Market Data Vault id18566 View details | Pakistan | Retail / E-commerce | — | ||
|
Standard Capital Securities (Pvt) Backoffice - Pakistan Stock Market Data Vault |
||||||
| Ransomware | mohrss.gov.cn ( Ministry of Human Resources and Social Security ) id18564 View details | China | Public Sector | — | ||
|
mohrss.gov.cn ( Ministry of Human Resources and Social Security ) |
||||||
| Ransomware | mohrss.gov.cn ( Ministry of Human Resources and Social Security ) id33027 View details | China | Public Sector | — | ||
|
mohrss.gov.cn represents the Ministry of Human Resources and Social Security, a central Chinese government institution responsible for workforce policy, social security administration, labor regulations, pension systems, and employment services. Operating within the Public Sector and based in China, the entity provides critical national services to citizens and organizations across human resources and social welfare domains. This listing type identifies mohrss.gov.cn as a ransomware victim associated with the babuk2 threat actor, indicating a cybersecurity incident involving this government sector entity. The description adheres strictly to verified entity attributes and listing context without speculating on breach details, data exposure, or recovery specifics. |
||||||
| Ransomware | mohrss.gov.cn ( Ministry of Human Resources and Social Security ) id33027 View details | China | Public Sector | — | ||
|
mohrss.gov.cn ( Ministry of Human Resources and Social Security ) |
||||||
| Ransomware | mohrss.gov.cn ( Ministry of Human Resources and Social Security ) id18564 View details | China | Public Sector | — | ||
|
mohrss.gov.cn ( Ministry of Human Resources and Social Security ) |
||||||
| Ransomware | amazon.com id18563 View details | United States | Other | — | ||
|
amazon.com |
||||||
| Ransomware | amazon.com id33028 View details | United States | Other | — | ||
|
amazon.com is a major US-based e-commerce and retail platform offering online shopping, cloud services, advertising, and logistics solutions to consumers and businesses globally. Operating across multiple sectors within digital commerce, the entity provides product marketplaces, subscription services, and enterprise tools supporting large-scale commercial activity. This catalog entry classifies amazon.com as a ransomware victim associated with the threat actor babuk2. The listing reflects threat-intelligence indexing of this entity within the context of cyber incidents targeting retail and e-commerce infrastructure. Neutral documentation is provided per threat-intelligence standards without speculative claims regarding breach details. |
||||||
| Ransomware | amazon.com id33028 View details | United States | Other | — | ||
|
amazon.com |
||||||
| Ransomware | amazon.com id18563 View details | United States | Other | — | ||
|
amazon.com |
||||||
| Ransomware | fr.sodexo.com id18542 View details | France | Other | — | ||
|
fr.sodexo.com |
||||||
| Ransomware | fr.sodexo.com id33029 View details | France | Other | — | ||
|
fr.sodexo.com operates within the Services sector and is associated with France. The entity is documented in this threat-intelligence index under the listing type ransomware victim, specifically tied to the threat actor babuk2. This classification reflects the cybersecurity community's assessment of the entity's involvement in an incident attributed to babuk2. The entry provides neutral context for researchers and defenders analyzing ransomware campaigns targeting Services sector organizations in French-speaking regions. No additional incident specifics, such as data stolen, ransom demands, or confirmed breach details, are included per strict factual guidelines. |
||||||
| Ransomware | fr.sodexo.com id33029 View details | France | Other | — | ||
|
fr.sodexo.com |
||||||
| Ransomware | fr.sodexo.com id18542 View details | France | Other | — | ||
|
fr.sodexo.com |
||||||
| Ransomware | Corporate access, up to Shipping Apps in QATAR id18541 View details | Qatar | Transportation / Travel / Logistics | — | ||
|
Corporate access, up to Shipping Apps in QATAR |
||||||
| Ransomware | Corporate access, up to Shipping Apps in QATAR id33030 View details | Qatar | Transportation / Travel / Logistics | — | ||
|
Corporate access, up to Shipping Apps in QATAR describes an entity operating within the Transportation, Travel, and Logistics sector, located in Qatar (QA). It provides corporate-level access capabilities and shipping application functionalities relevant to supply chain and freight operations across the regional market. This listing type identifies the entity as a ransomware victim within the threat-intelligence index. The association is attributed to the threat actor babuk2. The description reflects the indexed classification without confirming specific incident details. This entry supports threat-aware cataloging for sector-focused security monitoring and intelligence analysis. |
||||||
| Ransomware | Corporate access, up to Shipping Apps in QATAR id33030 View details | Qatar | Transportation / Travel / Logistics | — | ||
|
Corporate access, up to Shipping Apps in QATAR |
||||||
| Ransomware | Corporate access, up to Shipping Apps in QATAR id18541 View details | Qatar | Transportation / Travel / Logistics | — | ||
|
Corporate access, up to Shipping Apps in QATAR |
||||||
| Ransomware | woqod.com id18540 View details | Qatar | Other | — | ||
|
woqod.com |
||||||
| Ransomware | woqod.com id33031 View details | Qatar | Other | — | ||
|
woqod.com operates within the IT sector and is associated with the country of Qatar. The entity is cataloged in the threat-intelligence index as a ransomware victim, with the associated threat actor identified as babuk2. This listing type reflects the cybersecurity context in which woqod.com appears within the index, indicating a connection to a ransomware incident tied to babuk2. The description avoids speculation regarding specific attack details, data impacts, or confirmed breach specifics. woqod.com was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | woqod.com id33031 View details | Qatar | Other | — | ||
|
woqod.com |
||||||
| Ransomware | woqod.com id18540 View details | Qatar | Other | — | ||
|
woqod.com |
||||||
| Ransomware | mof.go.th - Ministry of Finance (Thailand) id18539 View details | Thailand | Finance / Legal / Insurance | — | ||
|
mof.go.th - Ministry of Finance (Thailand) |
||||||
| Ransomware | mof.go.th - Ministry of Finance (Thailand) id33032 View details | Thailand | Finance / Legal / Insurance | — | ||
|
mof.go.th represents the Ministry of Finance of Thailand, a core public sector entity responsible for national fiscal policy, taxation administration, budget management, financial regulation, and government financial operations. As a critical government institution within Thailand's public sector infrastructure, its digital systems support essential state functions and require robust cyber defense. This listing identifies mof.go.th as a ransomware victim associated with the threat actor babuk2, reflecting a cybersecurity event documented within the threat-intelligence index. The entry provides neutral context regarding the entity's role and the associated threat without disclosing unverified incident details. |
||||||
| Ransomware | mof.go.th - Ministry of Finance (Thailand) id33032 View details | Thailand | Finance / Legal / Insurance | — | ||
|
mof.go.th - Ministry of Finance (Thailand) |
||||||
| Ransomware | mof.go.th - Ministry of Finance (Thailand) id18539 View details | Thailand | Finance / Legal / Insurance | — | ||
|
mof.go.th - Ministry of Finance (Thailand) |
||||||
| Ransomware | smic.mi.th (Thailand Intelligence Agency) id18534 View details | Thailand | Communication / Marketing | — | ||
|
smic.mi.th (Thailand Intelligence Agency) |
||||||
| Ransomware | smic.mi.th (Thailand Intelligence Agency) id33033 View details | Thailand | Communication / Marketing | — | ||
|
smic.mi.th represents the Thailand Intelligence Agency, a national intelligence body operating within Thailand focused on public sector security, threat monitoring, and analytical support for government and critical infrastructure. Its role encompasses intelligence collection, cyber threat assessment, and coordination relevant to national security objectives across the public sector. In this catalog entry, smic.mi.th is documented as a ransomware victim linked to the threat actor babuk2, reflecting an incident context within the public sector environment of Thailand. This listing type indicates the entity was identified within the threat-intelligence index as affected by this ransomware campaign, without disclosing unverified technical or operational details. The association is presented neutrally to support threat intelligence analysis and catalog integrity. |
||||||
| Ransomware | smic.mi.th (Thailand Intelligence Agency) id33033 View details | Thailand | Communication / Marketing | — | ||
|
smic.mi.th (Thailand Intelligence Agency) |
||||||
| Ransomware | smic.mi.th (Thailand Intelligence Agency) id18534 View details | Thailand | Communication / Marketing | — | ||
|
smic.mi.th (Thailand Intelligence Agency) |
||||||
| Ransomware | www.gob.ve id18532 View details | Venezuela, Bolivarian Republic of | Other | — | ||
|
www.gob.ve |
||||||
| Ransomware | www.gob.ve id33034 View details | Venezuela, Bolivarian Republic of | Other | — | ||
|
gob.ve is a services-sector organization located in Venezuela (VE), operating within the professional and service industries. The entity is cataloged within this threat-intelligence index under the listing type ransomware victim, linked to the threat actor babuk2. This designation reflects the intelligence assessment associating gob.ve with the activity profile of babuk2 without disclosing unverified incident details. The entry provides neutral context regarding the entity’s sector, geographic origin, and its classification alongside the identified threat actor for catalog and research purposes. No specific breach claims, data theft specifics, ransom terms, or incident timelines are included, preserving factual neutrality. |
||||||
| Ransomware | www.gob.ve id33034 View details | Venezuela, Bolivarian Republic of | Other | — | ||
|
www.gob.ve |
||||||
| Ransomware | www.gob.ve id18532 View details | Venezuela, Bolivarian Republic of | Other | — | ||
|
www.gob.ve |
||||||
| Ransomware | Access Panel Financial Technology Company (Thailand) id18531 View details | Thailand | IT | — | ||
|
Access Panel Financial Technology Company (Thailand) |
||||||
| Ransomware | Access Panel Financial Technology Company (Thailand) id33035 View details | Thailand | IT | — | ||
|
Access Panel Financial Technology Company (Thailand) operates within the Finance, Legal, and Insurance sectors, providing financial technology solutions and services tailored to institutional clients in Thailand. The entity functions as a service provider supporting digital financial infrastructure, regulatory compliance workflows, and technology-enabled financial operations across its regional market. This listing type identifies the company as a ransomware victim associated with the threat actor babuk2, reflecting a cybersecurity incident documented within the threat-intelligence index. The description maintains factual neutrality regarding the incident specifics, focusing solely on the entity's operational context and its classification in the intelligence catalog. |
||||||
| Ransomware | Access Panel Financial Technology Company (Thailand) id33035 View details | Thailand | IT | — | ||
|
Access Panel Financial Technology Company (Thailand) |
||||||
| Ransomware | Access Panel Financial Technology Company (Thailand) id18531 View details | Thailand | IT | — | ||
|
Access Panel Financial Technology Company (Thailand) |
||||||
| Ransomware | United States County Palm Beach Goverment id18530 View details | United States | Public Sector | — | ||
|
United States County Palm Beach Goverment |
||||||
| Ransomware | United States County Palm Beach Goverment id33036 View details | United States | Public Sector | — | ||
|
The United States County Palm Beach Government is a public-sector county administration located in Palm Beach County, Florida, United States. Its responsibilities encompass local governance, public services, infrastructure oversight, community planning, and operational management for residents within the county jurisdiction. As a Public Sector entity, it represents municipal and governmental services delivered under state and federal frameworks. This listing identifies the entity as a ransomware victim associated with the threat actor babuk2. The description remains neutral and avoids speculative claims regarding data exfiltration, ransom demands, or confirmed breach details. This catalog entry supports threat-intelligence indexing for tracking public-sector cybersecurity incidents and associated adversary activity. |
||||||
| Ransomware | United States County Palm Beach Goverment id33036 View details | United States | Public Sector | — | ||
|
United States County Palm Beach Goverment |
||||||
| Ransomware | United States County Palm Beach Goverment id18530 View details | United States | Public Sector | — | ||
|
United States County Palm Beach Goverment |
||||||
| Ransomware | Municipal taxation Secretariat Access - Brazil Goverment id18529 View details | Brazil | Public Sector | — | ||
|
Municipal taxation Secretariat Access - Brazil Goverment |
||||||
| Ransomware | Municipal taxation Secretariat Access - Brazil Goverment id33037 View details | Brazil | Public Sector | — | ||
|
Municipal taxation Secretariat Access - Brazil Goverment is a public-sector entity representing municipal taxation operations within the Brazilian government framework. It provides essential services related to local tax administration, regulatory compliance support, and fiscal governance for municipal authorities across Brazil. As categorized under the Public Sector, this entity handles critical governmental functions tied to taxation processes and administrative oversight. According to the threat-intelligence index, Municipal taxation Secretariat Access - Brazil Goverment is listed as a ransomware victim associated with the babuk2 threat actor. This designation reflects the cybersecurity risk profile observed for entities within this sector targeted by advanced persistent threats. |
||||||
| Ransomware | Municipal taxation Secretariat Access - Brazil Goverment id33037 View details | Brazil | Public Sector | — | ||
|
Municipal taxation Secretariat Access - Brazil Goverment |
||||||
| Ransomware | Municipal taxation Secretariat Access - Brazil Goverment id18529 View details | Brazil | Public Sector | — | ||
|
Municipal taxation Secretariat Access - Brazil Goverment |
||||||
| Ransomware | Intelligence Bureau of the Joint Staff Department of the Central Military Commission... id18528 View details | China | Public Sector | — | ||
|
Intelligence Bureau of the Joint Staff Department of the Central Military Commission China |
||||||
| Ransomware | Intelligence Bureau of the Joint Staff Department of the Central Military Commission... id33038 View details | China | Public Sector | — | ||
|
The Intelligence Bureau of the Joint Staff Department of the Central Military Commission is a state intelligence and security institution within China's military leadership structure, operating under the Central Military Commission and supporting national security, military readiness, and strategic oversight functions across public sector domains. Its role encompasses intelligence collection, analysis, and coordination relevant to defense and governmental operations. In the context of this threat-intelligence index listing, the entity is cataloged as a ransomware victim associated with the threat actor babuk2. This classification reflects the observed relationship between the organization and the malware campaign without confirming specific breach details. The listing aligns with Public Sector exposure patterns in the country of China. |
||||||
| Ransomware | Intelligence Bureau of the Joint Staff Department of the Central Military Commission... id33038 View details | China | Public Sector | — | ||
|
Intelligence Bureau of the Joint Staff Department of the Central Military Commission China |
||||||
| Ransomware | Intelligence Bureau of the Joint Staff Department of the Central Military Commission... id18528 View details | China | Public Sector | — | ||
|
Intelligence Bureau of the Joint Staff Department of the Central Military Commission China |
||||||
| Ransomware | rac.gov.my id18527 View details | Malaysia | Other | — | ||
|
rac.gov.my |
||||||
| Ransomware | rac.gov.my id33039 View details | Malaysia | Other | — | ||
|
rac.gov.my is a public sector entity located in Malaysia, operating within government administrative and service frameworks. Its role encompasses digital governance functions, public service delivery platforms, and institutional infrastructure supporting regional and national operational continuity. Within the threat-intelligence index, rac.gov.my is formally cataloged as a ransomware victim associated with the babuk2 threat actor. This classification reflects the entity's inclusion in cybersecurity monitoring records where babuk2 activity was observed targeting public sector environments in MY. The listing underscores the importance of sector-specific vigilance against evolving ransomware campaigns targeting government infrastructure. |
||||||
| Ransomware | rac.gov.my id33039 View details | Malaysia | Other | — | ||
|
rac.gov.my |
||||||
| Ransomware | rac.gov.my id18527 View details | Malaysia | Other | — | ||
|
rac.gov.my |
||||||
| Ransomware | nimapinfotech.com id18526 View details | India | IT | — | ||
|
nimapinfotech.com |
||||||
| Ransomware | nimapinfotech.com id33040 View details | India | IT | — | ||
|
nimapinfotech.com operates within the IT sector and is based in India. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor identified as babuk2. No specific incident details such as data stolen, records impacted, ransom demands, or confirmed breach evidence are included to maintain factual neutrality and avoid speculation beyond verified index classification. This entry serves to document the relationship between the organization and the identified cyber threat actor within the ransomware victim category. The classification reflects the assessed threat context without asserting unverified claims about the nature or scope of any potential compromise. |
||||||
| Ransomware | nimapinfotech.com id33040 View details | India | IT | — | ||
|
nimapinfotech.com |
||||||
| Ransomware | nimapinfotech.com id18526 View details | India | IT | — | ||
|
nimapinfotech.com |
||||||
| Ransomware | esaote.com id18503 View details | Italy | Other | — | ||
|
esaote.com |
||||||
| Ransomware | esaote.com id33041 View details | Italy | Other | — | ||
|
Esaote.com is an entity operating within the IT sector, with operational presence indicated in the IT country context. The domain represents an organization whose infrastructure was identified within a threat-intelligence index as a ransomware victim. This listing type signifies that the entity was affected by ransomware activity associated with the threat actor babuk2. The association highlights the cybersecurity exposure faced by IT-focused organizations under this specific threat profile. This description provides neutral catalog context for researchers and defenders analyzing ransomware incidents within the technology sector. |
||||||
| Ransomware | esaote.com id33041 View details | Italy | Other | — | ||
|
esaote.com |
||||||
| Ransomware | esaote.com id18503 View details | Italy | Other | — | ||
|
esaote.com |
||||||
| Ransomware | nstda.or.th id18502 View details | Thailand | Other | — | ||
|
nstda.or.th |
||||||
| Ransomware | nstda.or.th id33042 View details | Thailand | Other | — | ||
|
nstda.or.th is an entity located in Thailand within the Public Sector, associated with the threat actor babuk2 and cataloged as a ransomware victim in the threat-intelligence index. Its designation reflects observed security events impacting public-sector infrastructure under the influence of babuk2, a threat actor historically associated with ransomware campaigns targeting critical services and government entities. The entity name and sector context indicate involvement within national public systems, where security incidents can carry significant operational and reputational implications. This listing serves as a neutral record of the relationship between nstda.or.th and babuk2 within the ransomware victim classification framework. It was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | nstda.or.th id33042 View details | Thailand | Other | — | ||
|
nstda.or.th |
||||||
| Ransomware | nstda.or.th id18502 View details | Thailand | Other | — | ||
|
nstda.or.th |
||||||
| Ransomware | kominfo.go.id id18501 View details | Indonesia | Other | — | ||
|
kominfo.go.id |
||||||
| Ransomware | kominfo.go.id id33043 View details | Indonesia | Other | — | ||
|
kominfo.go.id is an entity operating within the IT sector located in Indonesia. Its domain identity and operational context align with technology services and infrastructure management within the national digital landscape. The entity has been cataloged within this threat-intelligence index specifically as a ransomware victim. This listing type indicates its documented association with the cyber threat actor babuk2, a known ransomware campaign. The entry provides contextual metadata on sector, geographic origin, and threat linkage without disclosing unverified incident details or confirming specific breach events. This neutral overview supports threat-intelligence professionals in understanding entity risk profiles and associated actor relationships. |
||||||
| Ransomware | kominfo.go.id id33043 View details | Indonesia | Other | — | ||
|
kominfo.go.id |
||||||
| Ransomware | kominfo.go.id id18501 View details | Indonesia | Other | — | ||
|
kominfo.go.id |
||||||
| Ransomware | pajak.go.id id18500 View details | Indonesia | Other | — | ||
|
pajak.go.id |
||||||
| Ransomware | pajak.go.id id33044 View details | Indonesia | Other | — | ||
|
pajak.go.id is an entity identified within the Public Sector of Indonesia. Its domain structure and contextual association indicate involvement in government or public administration services, with offerings or infrastructure relevant to tax and public service functions. The entity is cataloged specifically as a ransomware victim, linked to the threat actor babuk2. This listing type documents the relationship between the affected entity, the identified threat actor, and the geographic and sectoral context without disclosing unverified incident details. The entry serves threat-intelligence purposes by mapping victim attributes to active cyber threats. |
||||||
| Ransomware | pajak.go.id id33044 View details | Indonesia | Other | — | ||
|
pajak.go.id |
||||||
| Ransomware | pajak.go.id id18500 View details | Indonesia | Other | — | ||
|
pajak.go.id |
||||||
| Ransomware | dukcapil.kemendagri.go.id (SIAK DUKCAPIL MINISTRY OF HOME AFFAIRS OF INDONESIA) id18499 View details | Indonesia | Agriculture / Food | — | ||
|
dukcapil.kemendagri.go.id (SIAK DUKCAPIL MINISTRY OF HOME AFFAIRS OF INDONESIA) |
||||||
| Ransomware | dukcapil.kemendagri.go.id (SIAK DUKCAPIL MINISTRY OF HOME AFFAIRS OF INDONESIA) id33045 View details | Indonesia | Agriculture / Food | — | ||
|
dukcapi.kemendagri.go.id (SIAK DUKCAPIL MINISTRY OF HOME AFFAIRS OF INDONESIA) represents a government entity within Indonesia's Ministry of Home Affairs sector. This domain serves official administrative functions for the SIAK DUKCAPIL division, supporting public safety and internal governance operations. The entity is cataloged in the threat-intelligence index as a ransomware victim linked to the babuk2 threat actor. No specific incident details such as data stolen, affected systems, or ransom demands are confirmed by this listing. This entry documents the association between the Indonesian public sector entity and the babuk2 ransomware campaign for cybersecurity awareness and monitoring purposes. |
||||||
| Ransomware | dukcapil.kemendagri.go.id (SIAK DUKCAPIL MINISTRY OF HOME AFFAIRS OF INDONESIA) id33045 View details | Indonesia | Agriculture / Food | — | ||
|
dukcapil.kemendagri.go.id (SIAK DUKCAPIL MINISTRY OF HOME AFFAIRS OF INDONESIA) |
||||||
| Ransomware | dukcapil.kemendagri.go.id (SIAK DUKCAPIL MINISTRY OF HOME AFFAIRS OF INDONESIA) id18499 View details | Indonesia | Agriculture / Food | — | ||
|
dukcapil.kemendagri.go.id (SIAK DUKCAPIL MINISTRY OF HOME AFFAIRS OF INDONESIA) |
||||||
| Ransomware | whitecapcanada.com id18496 View details | Canada | Other | — | ||
|
whitecapcanada.com |
||||||
| Ransomware | whitecapcanada.com id33046 View details | Canada | Other | — | ||
|
whitecapcanada.com operates within the IT sector and is situated in Canada. The entity functions as a service provider or organization within information technology infrastructure, contributing to digital services relevant to enterprise environments. Within the threat-intelligence index, whitecapcanada.com is cataloged specifically as a ransomware victim linked to the threat actor babuk2. This listing type identifies the entity's relationship to a cyber threat campaign without disclosing unverified incident details such as data stolen, ransom demands, or specific breach timelines. The entry serves to document affected organizations for monitoring, risk assessment, and broader cybersecurity intelligence purposes. |
||||||
| Ransomware | whitecapcanada.com id33046 View details | Canada | Other | — | ||
|
whitecapcanada.com |
||||||
| Ransomware | whitecapcanada.com id18496 View details | Canada | Other | — | ||
|
whitecapcanada.com |
||||||