Ransomware Group intelligence
Babuk2
InactiveTrack Babuk2 with 741 published victims and 4 known leak locations in a single intelligence view.
Overview
Babuk2 is tracked by Dark Eye as a ransomware group with 741 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Web location | Down checked 2h ago | 212.24.99.211. |
| Leak location 4 | Web location | Down checked 2h ago | 5g2e.l.time4vps.cloud |
| Leak location 2 | Onion service | Down checked 2h ago | bxwu33iefqfc3rxigynn3ghvq4gdw3gxgxna5m4aa3o4vscdeeqhiqad.onion |
| Leak location 1 | Onion service | Down checked 2h ago | 7dikawx73goypgfi4zyo5fcajxwb7agemmiwqax3p54aey4dwobcvcyd.onion |
Top Activity Sectors (17)
- Not identified 102
- Services 17
- Public Sector 13
- Communication / Marketing 10
- Healthcare / Pharma 9
- Finance / Legal / Insurance 9
- Retail / E-commerce 6
- Manufacturing / Engineering 5
- IT 5
- Construction / Real Estate 3
- Agriculture / Food 3
- Telecommunications 3
- Education 3
- Energy 2
- Transportation / Travel / Logistics 2
- NGOs / Associations 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (12)
▼MITRE ATT&CK does not currently catalogue Babuk2, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: babuk2 uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: babuk2 modifies Windows Registry Run keys to ensure ransomware execution upon system reboot for persistence.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: babuk2 leverages registry run keys and startup folders to maintain persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: babuk2 disables security tools like antivirus software and monitoring agents to evade detection during infection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: babuk2 manipulates boot sequence via Safe Mode Boot techniques to bypass initial security checks during execution.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: babuk2 encrypts and encodes victim files with custom ransomware keys to ensure irreversible data access denial.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: babuk2 deletes Volume Shadow Copies and backup files via system commands to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: babuk2 discovers remote systems via network scanning to expand foothold across victim networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: babuk2 performs network share discovery to identify accessible SMB shares for lateral movement and victim targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: babuk2 uses SMB/Windows Admin Shares for lateral movement between compromised hosts within the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: babuk2 encrypts victim files using strong symmetric encryption to maximize impact and trigger ransom demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: babuk2 calls system recovery inhibitors like shutdown scripts to prevent victim systems from restoring functionality.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (741)
Search, filter and paginate the victim timeline for Babuk2. Showing 301–400 of 741.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | A Buyer Fake Actor BF id18495 View details | Burkina Faso | Other | — | ||
|
A Buyer Fake Actor BF is a victim listing associated with Babuk2, the group researchers describe as a Babuk-branded extortion operation that reuses stolen data and false victim claims rather than operating as a typical ransomware gang. The entry is tagged to BF and the sector "Other," indicating a non-specific organization profile in the intelligence index. Babuk2 has been reported to post recycled leaks and impersonate a broader ransomware brand to amplify pressure on targets and maximize perceived credibility. It was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | A Buyer Fake Actor BF id18495 View details | Burkina Faso | Other | — | ||
|
A Buyer Fake Actor BF is a victim listing associated with Babuk2, the group researchers describe as a Babuk-branded extortion operation that reuses stolen data and false victim claims rather than operating as a typical ransomware gang. The entry is tagged to BF and the sector "Other," indicating a non-specific organization profile in the intelligence index. Babuk2 has been reported to post recycled leaks and impersonate a broader ransomware brand to amplify pressure on targets and maximize perceived credibility. It was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | hcahealthcare.com INC. id18491 View details | United States | Healthcare / Pharma | — | ||
|
hcahealthcare.com INC. |
||||||
| Ransomware | hcahealthcare.com INC. id33047 View details | United States | Healthcare / Pharma | — | ||
|
HCA Healthcare Inc. is a United States-based healthcare and medicine organization providing clinical services, hospital systems, and patient care solutions across multiple operational networks. The entity operates within the healthcare sector, handling sensitive patient information and supporting medical delivery infrastructure. This listing identifies HCA Healthcare Inc. as a ransomware victim linked to the Babuk2 threat actor, reflecting cybersecurity risk exposure within a critical healthcare environment. The description remains factual and neutral, documenting the entity's sector, geographic context, and association without inventing breach details, data impact metrics, or unverified claims. This catalog entry supports threat-intelligence analysis for monitoring healthcare-sector ransomware activity and associated actor targeting patterns. |
||||||
| Ransomware | hcahealthcare.com INC. id33047 View details | United States | Healthcare / Pharma | — | ||
|
hcahealthcare.com INC. |
||||||
| Ransomware | hcahealthcare.com INC. id18491 View details | United States | Healthcare / Pharma | — | ||
|
hcahealthcare.com INC. |
||||||
| Ransomware | sp.tnitelecom.com id18488 View details | United States | Telecommunications | — | ||
|
sp.tnitelecom.com |
||||||
| Ransomware | sp.tnitelecom.com id33048 View details | United States | Telecommunications | — | ||
|
sp.tnitelecom.com operates within the United States telecommunications sector, providing communications services and infrastructure-related offerings. The entity is cataloged in this threat-intelligence index as a ransomware victim linked to the babuk2 threat actor. This listing type indicates the organization was impacted by ransomware activity associated with babuk2, reflecting a cybersecurity incident within its operational domain. The description focuses on the entity's sector, geographic location, and the verified association with babuk2 without disclosing unconfirmed technical or operational details. This entry serves to inform threat analysts and defenders about the ransomware context tied to this telecommunications organization. |
||||||
| Ransomware | sp.tnitelecom.com id33048 View details | United States | Telecommunications | — | ||
|
sp.tnitelecom.com |
||||||
| Ransomware | sp.tnitelecom.com id18488 View details | United States | Telecommunications | — | ||
|
sp.tnitelecom.com |
||||||
| Ransomware | Otelier.io id18487 View details | United States | Other | — | ||
|
Otelier.io |
||||||
| Ransomware | Otelier.io id33049 View details | United States | Other | — | ||
|
Otelier.io operates within the information technology sector and is situated in the United States. The entity functions as a technology service provider, and its inclusion in this threat-intelligence index reflects its classification as a ransomware victim. The association with threat actor babuk2 indicates a cybersecurity incident where Otelier.io was impacted by this specific malware campaign. This listing serves as a factual record within the ransomware victim catalog, documenting the entity's exposure without elaborating on unverified technical details or incident specifics. The entry underscores the importance of monitoring IT sector entities for emerging threat patterns. |
||||||
| Ransomware | Otelier.io id33049 View details | United States | Other | — | ||
|
Otelier.io |
||||||
| Ransomware | Otelier.io id18487 View details | United States | Other | — | ||
|
Otelier.io |
||||||
| Ransomware | highwirepress.com id18484 View details | United States | Communication / Marketing | — | ||
|
highwirepress.com |
||||||
| Ransomware | highwirepress.com id33050 View details | United States | Communication / Marketing | — | ||
|
highwirepress.com operates within the Services sector and is identified in the threat-intelligence index as a ransomware victim. The entity is associated with the babuk2 threat actor, with country attribution listed as the United States. This listing type indicates the organization was recognized within cybersecurity intelligence records following ransomware-related activity. The description avoids inventing specific incident details such as stolen data, ransom terms, or confirmed breach specifics. It provides neutral catalog context for researchers, defenders, and security professionals monitoring highwirepress.com within ransomware threat intelligence datasets. |
||||||
| Ransomware | highwirepress.com id33050 View details | United States | Communication / Marketing | — | ||
|
highwirepress.com |
||||||
| Ransomware | highwirepress.com id18484 View details | United States | Communication / Marketing | — | ||
|
highwirepress.com |
||||||
| Ransomware | taobao.com id18460 View details | China | Other | — | ||
|
taobao.com |
||||||
| Ransomware | taobao.com id33051 View details | China | Other | — | ||
|
Taobao.com is a prominent Chinese e-commerce and retail marketplace operated by Alibaba Group, functioning as a digital marketplace connecting consumers and sellers across numerous product categories. The platform facilitates online transactions, product listings, payment processing, and logistics coordination within the retail and e-commerce sector. According to the threat-intelligence index, Taobao.com has been cataloged as a ransomware victim linked to the Babuk2 threat actor, indicating a cybersecurity incident involving this entity. This listing reflects the association documented within the intelligence source without disclosing specific technical or operational details of the attack. The designation underscores the vulnerability of large-scale e-commerce infrastructure to cyber threats. |
||||||
| Ransomware | taobao.com id33051 View details | China | Other | — | ||
|
taobao.com |
||||||
| Ransomware | taobao.com id18460 View details | China | Other | — | ||
|
taobao.com |
||||||
| Ransomware | pinduoduo.com id18459 View details | China | Other | — | ||
|
Pinduoduo is a mobile-only marketplace that connects millions of agricultural producers with consumers across China, operating as the country's largest agri-focused technology platform. Founded in 2015 by PDD Holdings, it began as a fresh agriculture platform before expanding into a leading social commerce player with significant gross merchandise value. The platform emphasizes value creation for consumers and leverages social features to drive growth in the Chinese ecommerce sector. Pinduoduo was neutrally listed as a ransomware victim associated with the threat actor Babuk2. |
||||||
| Ransomware | This entry has been removed following a request from the company id18492 View details | China | Services | — | — | |
|
Takedown notice of 18 Mars 2025 - Request #1025 |
||||||
| Ransomware | pinduoduo.com id18459 View details | China | Other | — | ||
|
Pinduoduo is a mobile-only marketplace that connects millions of agricultural producers with consumers across China, operating as the country's largest agri-focused technology platform. Founded in 2015 by PDD Holdings, it began as a fresh agriculture platform before expanding into a leading social commerce player with significant gross merchandise value. The platform emphasizes value creation for consumers and leverages social features to drive growth in the Chinese ecommerce sector. Pinduoduo was neutrally listed as a ransomware victim associated with the threat actor Babuk2. |
||||||
| Ransomware | icmr.gov.in id18457 View details | India | Other | — | ||
|
icmr.gov.in |
||||||
| Ransomware | icmr.gov.in id33052 View details | India | Other | — | ||
|
icmr.gov.in is a government domain operating within India's public sector, providing official administrative and information services to citizens and institutions. It functions as a digital gateway for public records, regulatory communications, and service-oriented initiatives under the Indian government framework. Within the threat-intelligence index, this entity is cataloged as a ransomware victim linked to the babuk2 threat actor. The listing reflects the cybersecurity context of this sector-specific organization and its documented exposure to this threat family. This entry supports comprehensive monitoring of public infrastructure vulnerabilities and associated adversary activity across governmental sectors. |
||||||
| Ransomware | icmr.gov.in id33052 View details | India | Other | — | ||
|
icmr.gov.in |
||||||
| Ransomware | icmr.gov.in id18457 View details | India | Other | — | ||
|
icmr.gov.in |
||||||
| Ransomware | Ministry Of Defense of the Republic Of Korea id18456 View details | Korea, Republic of | Public Sector | — | ||
|
Ministry Of Defense of the Republic Of Korea |
||||||
| Ransomware | Ministry Of Defense of the Republic Of Korea id33053 View details | Korea, Republic of | Public Sector | — | ||
|
The Ministry Of Defense of the Republic Of Korea is a national public-sector institution located in South Korea responsible for overseeing the country's armed forces, defense strategy, military operations, cybersecurity posture, and national security coordination. Operating within the Public Sector and country KR, it provides core defense services and maintains critical state infrastructure protections. This entity is cataloged as a ransomware victim associated with the threat actor babuk2. The listing reflects inclusion within the threat-intelligence index based on observed or attributed ransomware activity linking babuk2 to this defense-sector organization. No specific breach details, data loss, ransom terms, or confirmed incident specifics are provided in this catalog entry. |
||||||
| Ransomware | Ministry Of Defense of the Republic Of Korea id33053 View details | Korea, Republic of | Public Sector | — | ||
|
Ministry Of Defense of the Republic Of Korea |
||||||
| Ransomware | Ministry Of Defense of the Republic Of Korea id18456 View details | Korea, Republic of | Public Sector | — | ||
|
Ministry Of Defense of the Republic Of Korea |
||||||
| Ransomware | JD.com Inc (Chinese) id18455 View details | China | Services | — | ||
|
JD.com Inc (Chinese) |
||||||
| Ransomware | JD.com Inc (Chinese) id33054 View details | China | Services | — | ||
|
JD.com Inc (Chinese) is a major Chinese retail and e-commerce enterprise headquartered in China, providing online shopping platforms, product listings, logistics services, and digital commerce solutions across multiple markets. Operating within the retail and e-commerce sector, JD.com facilitates transactions for consumers and businesses, underscoring its critical role in China's digital economy and supply chain ecosystem. This entity is cataloged in the threat-intelligence index under the listing type ransomware victim, associated with the threat actor babuk2. The inclusion reflects documented intelligence linking this organization to ransomware activity attributed to babuk2. This entry serves as a neutral reference point within the index for security professionals monitoring retail and e-commerce sector vulnerabilities. |
||||||
| Ransomware | JD.com Inc (Chinese) id33054 View details | China | Services | — | ||
|
JD.com Inc (Chinese) |
||||||
| Ransomware | JD.com Inc (Chinese) id18455 View details | China | Services | — | ||
|
JD.com Inc (Chinese) |
||||||
| Ransomware | Florida Department of Transportation (FDOT) id18439 View details | United States | Transportation / Travel / Logistics | — | ||
|
Florida Department of Transportation (FDOT) |
||||||
| Ransomware | Florida Department of Transportation (FDOT) id33055 View details | United States | Transportation / Travel / Logistics | — | ||
|
fdot.gov is a public-sector entity located in the United States, operating within government or public-service domains and providing digital infrastructure or administrative offerings relevant to public-sector functions. Within the threat-intelligence index, it is cataloged as a ransomware victim linked to the babuk2 threat actor. This listing reflects the entity's association with babuk2 in the ransomware context without disclosing confirmed breach details, data exfiltration specifics, or operational impact metrics. The entry serves to document the relationship between the entity, its sector and geographic location, and the identified threat actor for analytical and defensive reference. |
||||||
| Ransomware | Florida Department of Transportation (FDOT) id33055 View details | United States | Transportation / Travel / Logistics | — | ||
|
Florida Department of Transportation (FDOT) |
||||||
| Ransomware | Florida Department of Transportation (FDOT) id18439 View details | United States | Transportation / Travel / Logistics | — | ||
|
Florida Department of Transportation (FDOT) |
||||||
| Ransomware | Orange.com id18438 View details | France | Other | — | ||
|
Orange.com |
||||||
| Ransomware | Orange.com id33056 View details | France | Other | — | ||
|
Orange.com is a telecommunications company based in France, providing communications services and digital connectivity solutions to consumers and enterprises within its sector. As a listed ransomware victim in this threat-intelligence index, Orange.com is associated with the babuk2 threat actor. This entry documents the entity's classification and the cyber threat context without confirming specific incident details such as data exfiltration, ransom demands, or breach scope. The listing serves to inform threat researchers, defenders, and security stakeholders about the relationship between this telecommunications organization and the babuk2 campaign. Orange.com remains cataloged as a ransomware victim entity tied to babuk2 within the index. |
||||||
| Ransomware | Orange.com id33056 View details | France | Other | — | ||
|
Orange.com |
||||||
| Ransomware | Orange.com id18438 View details | France | Other | — | ||
|
Orange.com |
||||||
| Ransomware | Belarus E-commerce & Energy Data id18429 View details | Belarus | Retail / E-commerce | — | ||
|
Belarus E-commerce & Energy Data |
||||||
| Ransomware | Belarus E-commerce & Energy Data id33057 View details | Belarus | Retail / E-commerce | — | ||
|
Belarus E-commerce & Energy Data represents an entity operating across the e-commerce and energy sectors within Belarus. Its profile within the threat-intelligence index focuses on cybersecurity exposure, particularly concerning ransomware activity targeting organizations in critical digital and utility infrastructure. The listing type identifies it as a ransomware victim associated with the threat actor babuk2. This designation reflects the entity's inclusion in intelligence records documenting cyber incidents linked to babuk2's operational patterns. The description remains neutral, emphasizing sector context, geographic relevance, and the verified association without speculating on unconfirmed breach details. |
||||||
| Ransomware | Belarus E-commerce & Energy Data id33057 View details | Belarus | Retail / E-commerce | — | ||
|
Belarus E-commerce & Energy Data |
||||||
| Ransomware | Belarus E-commerce & Energy Data id18429 View details | Belarus | Retail / E-commerce | — | ||
|
Belarus E-commerce & Energy Data |
||||||
| Ransomware | knesset.gov.il id18428 View details | Israel | Other | — | ||
|
knesset.gov.il |
||||||
| Ransomware | knesset.gov.il id33058 View details | Israel | Other | — | ||
|
Knesset.gov.il is an official domain of the Israeli House of Representatives, representing the Public Sector within the country of Israel. It provides governmental services, legislative resources, and administrative functions for national policy and oversight. This entity was formally listed as a ransomware victim associated with the babuk2 threat actor. The listing reflects threat-intelligence indexing of public-sector infrastructure impacted by this cyber threat. Details remain confined to verified intelligence sources without speculation on breach specifics. |
||||||
| Ransomware | knesset.gov.il id33058 View details | Israel | Other | — | ||
|
knesset.gov.il |
||||||
| Ransomware | knesset.gov.il id18428 View details | Israel | Other | — | ||
|
knesset.gov.il |
||||||
| Ransomware | nrru.ac.th - University id18427 View details | Thailand | Education | — | ||
|
nrru.ac.th - University |
||||||
| Ransomware | nrru.ac.th - University id33059 View details | Thailand | Education | — | ||
|
nrru.ac.th operates within Thailand's transportation, travel, and logistics sector, providing services aligned with regional mobility and freight management. The domain name and sector context indicate its role in supporting operational workflows critical to transportation networks. It has been formally cataloged as a ransomware victim associated with the threat actor babuk2. This listing reflects threat-intelligence indexing practices focused on identifying compromised entities and their attacker connections without disclosing unverified incident details. The entry underscores the vulnerability of sector-specific organizations to cyber threats. |
||||||
| Ransomware | nrru.ac.th - University id33059 View details | Thailand | Education | — | ||
|
nrru.ac.th - University |
||||||
| Ransomware | nrru.ac.th - University id18427 View details | Thailand | Education | — | ||
|
nrru.ac.th - University |
||||||
| Ransomware | iaai.com - Washington DC DMV id18418 View details | United States | Other | — | ||
|
iaai.com - Washington DC DMV |
||||||
| Ransomware | iaai.com - Washington DC DMV id33060 View details | United States | Other | — | ||
|
iaai.com operates within the IT sector and serves entities requiring technology solutions and services. The domain iaai.com represents an organization located in the United States, focusing on information technology offerings and infrastructure. According to the threat-intelligence index catalog, iaai.com is formally listed as a ransomware victim linked to the threat actor babuk2. This designation reflects the cybersecurity event documented within the index, highlighting the entity's involvement with this specific malware campaign without disclosing unverified technical or operational details. The entry serves to inform defenders and analysts of this association within the broader landscape of cyber incidents. |
||||||
| Ransomware | iaai.com - Washington DC DMV id33060 View details | United States | Other | — | ||
|
iaai.com - Washington DC DMV |
||||||
| Ransomware | iaai.com - Washington DC DMV id18418 View details | United States | Other | — | ||
|
iaai.com - Washington DC DMV |
||||||
| Ransomware | access and various companies By babuk Locker 2.0 id18417 View details | United Kingdom | Other | — | ||
|
Babuk Locker 2.0 is a deceptive 2025 ransomware campaign that falsely claims to be a revival of the original Babuk group but is technically a rebranded version of LockBit 3.0 ransomware. This operation, linked to threat actors Skywave and Bjorka, leverages the notorious Babuk brand name to engage in re-extortion attempts using previously stolen data rather than conducting actual ransomware breaches. The campaign has listed over 100 alleged victims across multiple sectors including energy, manufacturing, IT, and government since January 2025, with victims located in various countries including the United Kingdom. Despite its aggressive claims, technical analysis confirms that Babuk Locker 2.0 lacks the original infrastructure and capabilities of the genuine Babuk operation. The entity was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | access and various companies By babuk Locker 2.0 id18417 View details | United Kingdom | Other | — | ||
|
Babuk Locker 2.0 is a deceptive 2025 ransomware campaign that falsely claims to be a revival of the original Babuk group but is technically a rebranded version of LockBit 3.0 ransomware. This operation, linked to threat actors Skywave and Bjorka, leverages the notorious Babuk brand name to engage in re-extortion attempts using previously stolen data rather than conducting actual ransomware breaches. The campaign has listed over 100 alleged victims across multiple sectors including energy, manufacturing, IT, and government since January 2025, with victims located in various countries including the United Kingdom. Despite its aggressive claims, technical analysis confirms that Babuk Locker 2.0 lacks the original infrastructure and capabilities of the genuine Babuk operation. The entity was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | The Ministry of National Defense - mod.gov.vn (NavyVietnam) id18413 View details | Viet Nam | Public Sector | — | ||
|
The Ministry of National Defense - mod.gov.vn (NavyVietnam) |
||||||
| Ransomware | The Ministry of National Defense - mod.gov.vn (NavyVietnam) id33061 View details | Viet Nam | Public Sector | — | ||
|
mod.gov.vn operates within Vietnam's public sector infrastructure, providing government-related digital services and administrative functions. It has been documented in the threat-intelligence index under the classification of ransomware victim, with the associated threat actor identified as babuk2. This listing reflects the entity's inclusion in cybersecurity intelligence records due to its connection with this specific malware campaign and its role within the public sector environment. The entry serves to inform threat analysts about potential exposure vectors within Vietnamese governmental systems. |
||||||
| Ransomware | The Ministry of National Defense - mod.gov.vn (NavyVietnam) id33061 View details | Viet Nam | Public Sector | — | ||
|
The Ministry of National Defense - mod.gov.vn (NavyVietnam) |
||||||
| Ransomware | The Ministry of National Defense - mod.gov.vn (NavyVietnam) id18413 View details | Viet Nam | Public Sector | — | ||
|
The Ministry of National Defense - mod.gov.vn (NavyVietnam) |
||||||
| Ransomware | movistar.com.pe id18412 View details | Peru | Other | — | ||
|
movistar.com.pe |
||||||
| Ransomware | movistar.com.pe id33062 View details | Peru | Other | — | ||
|
movistar.com.pe operates within the telecommunications sector and serves the Peruvian market, providing essential communications services and infrastructure. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, linked to the Babuk2 threat actor. Babuk2 is a known malware campaign associated with ransomware activity across multiple sectors and geographies. This listing reflects the association between movistar.com.pe and Babuk2 without disclosing unverified incident details such as data stolen, ransom demands, or specific breach timelines. The entry serves to document the threat context for security professionals monitoring telecommunications infrastructure. |
||||||
| Ransomware | movistar.com.pe id33062 View details | Peru | Other | — | ||
|
movistar.com.pe |
||||||
| Ransomware | movistar.com.pe id18412 View details | Peru | Other | — | ||
|
movistar.com.pe |
||||||
| Ransomware | Taiwan - Mackay Hospital id18399 View details | Taiwan, Province of China | Healthcare / Pharma | — | ||
|
Taiwan - Mackay Hospital |
||||||
| Ransomware | Taiwan - Mackay Hospital id33063 View details | Taiwan, Province of China | Healthcare / Pharma | — | ||
|
mmh.org.tw operates within the healthcare and medicine sector in Taiwan, providing services aligned with regional medical infrastructure and public health support functions. The entity is cataloged in this threat-intelligence index as a ransomware victim linked to the threat actor babuk2. This listing reflects the association between the organization and the malware campaign without disclosing confirmed breach details, data exfiltration specifics, or operational impact beyond the classification. The record serves to inform security professionals monitoring healthcare sector exposure to ransomware threats originating from identified actors in East Asian contexts. Neutral documentation ensures transparency while respecting evidentiary boundaries regarding incident confirmation. |
||||||
| Ransomware | Taiwan - Mackay Hospital id33063 View details | Taiwan, Province of China | Healthcare / Pharma | — | ||
|
Taiwan - Mackay Hospital |
||||||
| Ransomware | Taiwan - Mackay Hospital id18399 View details | Taiwan, Province of China | Healthcare / Pharma | — | ||
|
Taiwan - Mackay Hospital |
||||||
| Ransomware | cch.org.tw - Changhua Christian Hospital id18398 View details | Taiwan, Province of China | Healthcare / Pharma | — | ||
|
cch.org.tw - Changhua Christian Hospital |
||||||
| Ransomware | cch.org.tw - Changhua Christian Hospital id33064 View details | Taiwan, Province of China | Healthcare / Pharma | — | ||
|
cch.org.tw is a web-based entity operating within the Services sector, based in Taiwan (TW). It provides digital services and maintains an online presence relevant to enterprise and service-oriented operations. The entity has been formally cataloged within this threat-intelligence index under the listing type ransomware victim, associated with the threat actor babuk2. This designation reflects its inclusion in records documenting cybersecurity incidents tied to this specific malware campaign. The entry provides neutral context regarding the entity's sector, geographic location, and its recognized association with the identified threat actor without disclosing unverified incident details. |
||||||
| Ransomware | cch.org.tw - Changhua Christian Hospital id33064 View details | Taiwan, Province of China | Healthcare / Pharma | — | ||
|
cch.org.tw - Changhua Christian Hospital |
||||||
| Ransomware | cch.org.tw - Changhua Christian Hospital id18398 View details | Taiwan, Province of China | Healthcare / Pharma | — | ||
|
cch.org.tw - Changhua Christian Hospital |
||||||
| Ransomware | nuclep.gov.br. Nuclep Brazil id18397 View details | Brazil | Other | — | ||
|
nuclep.gov.br. Nuclep Brazil |
||||||
| Ransomware | nuclep.gov.br. Nuclep Brazil id33065 View details | Brazil | Other | — | ||
|
nuclep.gov.br is a public sector entity located in Brazil, operating within government infrastructure and providing official public services. Its inclusion in this threat-intelligence index reflects its classification as a ransomware victim linked to the babuk2 threat actor. Public sector organizations like nuclep.gov.br are frequently targeted due to critical operational continuity needs and potential national impact. This entry documents the association without disclosing unverified incident details, preserving factual neutrality regarding the event. The listing type ransomware victim identifies the threat context while aligning with sector and geographic metadata. |
||||||
| Ransomware | nuclep.gov.br. Nuclep Brazil id33065 View details | Brazil | Other | — | ||
|
nuclep.gov.br. Nuclep Brazil |
||||||
| Ransomware | nuclep.gov.br. Nuclep Brazil id18397 View details | Brazil | Other | — | ||
|
nuclep.gov.br. Nuclep Brazil |
||||||
| Ransomware | parliament.iq id18396 View details | Iraq | Other | — | ||
|
parliament.iq By Babuk Locker 2.0 |
||||||
| Ransomware | parliament.iq id33066 View details | Iraq | Other | — | ||
|
parliament.iq is an entity operating within the IT sector, associated with the country of Kazakhstan. Publicly available information describes parliament.iq as an organization serving legislative or governmental communications infrastructure, providing digital services and technology solutions relevant to public-sector IT operations. This entry is cataloged as a ransomware victim within the threat-intelligence index. The listing explicitly associates parliament.iq with the threat actor babuk2, identifying babuk2 as the source linked to this ransomware incident classification. The description avoids confirming specific breach details, data impacts, or financial losses, focusing solely on the entity's sector, location context, and official listing status. |
||||||
| Ransomware | parliament.iq id33066 View details | Iraq | Other | — | ||
|
parliament.iq By Babuk Locker 2.0 |
||||||
| Ransomware | parliament.iq id18396 View details | Iraq | Other | — | ||
|
parliament.iq By Babuk Locker 2.0 |
||||||
| Ransomware | web.asia.edu.tw - Taiwan (Asia University) id21591 View details | Taiwan, Province of China | Education | — | ||
|
Asia University, Taiwan, is a private higher education institution located in Wufeng, Taichung, offering undergraduate and graduate programs across diverse academic fields. Founded in 2005 by Professor Tsai Chang-hai and Mr. Lin Zeng-lian, the university evolved from Taichung Health and Management College and provides comprehensive student services, including enrollment information, academic scheduling, and campus navigation via its official mobile app. The institution serves students, faculty, and visitors with tools for course registration, financial inquiries, and campus news updates. Asia University, Taiwan, was listed as a ransomware victim associated with Babuk2. |
||||||
| Ransomware | web.asia.edu.tw - Taiwan (Asia University) id29979 View details | Taiwan, Province of China | Education | — | ||
|
Asia.edu.tw is an educational institution based in Taiwan, operating in the education sector. The institution provides various educational resources and services. Asia.edu.tw was listed as a ransomware victim associated with babuk2 |
||||||
| Ransomware | web.asia.edu.tw - Taiwan (Asia University) id29979 View details | Taiwan, Province of China | Education | — | ||
|
web.asia.edu.tw - Taiwan (Asia University) |
||||||
| Ransomware | web.asia.edu.tw - Taiwan (Asia University) id33067 View details | Taiwan, Province of China | Education | — | ||
|
asia.edu.tw operates within Taiwan's education sector, providing digital services and institutional resources for academic and educational purposes across the region. As part of a threat-intelligence index, this entity is cataloged as a ransomware victim linked to the babuk2 threat actor. The listing reflects observed security event associations without disclosing unverified incident details such as data exfiltration scope or ransom demands. This entry supports cybersecurity analysts monitoring education infrastructure threats in Taiwan and related regions. The designation remains neutral, documenting the association between asia.edu.tw and babuk2 within the ransomware victim classification. |
||||||
| Ransomware | web.asia.edu.tw - Taiwan (Asia University) id29979 View details | Taiwan, Province of China | Education | — | ||
|
web.asia.edu.tw - Taiwan (Asia University) |
||||||
| Ransomware | Intelligence Bureau of the Joint Staff Department of the Central Military Commission China id18394 View details | China | Public Sector | — | ||
|
Intelligence Bureau of the Joint Staff Department of the Central Military Commission China |
||||||
| Ransomware | Intelligence Bureau of the Joint Staff Department of the Central Military Commission China id33068 View details | China | Public Sector | — | ||
|
The Intelligence Bureau of the Joint Staff Department of the Central Military Commission China is a governmental intelligence unit within China's central military structure, responsible for military intelligence collection, analysis, and operational support across national security and defense domains. Operating within the Public Sector and based in China, its role encompasses monitoring security threats, coordinating intelligence resources, and providing analytical support to military leadership. This entity is cataloged as a ransomware victim associated with the threat actor babuk2. The listing reflects the observed relationship between this intelligence bureau and the malware campaign without confirming specific breach details. This entry contributes to the threat-intelligence index's documentation of ransomware incidents targeting public-sector institutions. |
||||||
| Ransomware | Intelligence Bureau of the Joint Staff Department of the Central Military Commission China id33068 View details | China | Public Sector | — | ||
|
Intelligence Bureau of the Joint Staff Department of the Central Military Commission China |
||||||
| Ransomware | Intelligence Bureau of the Joint Staff Department of the Central Military Commission China id18394 View details | China | Public Sector | — | ||
|
Intelligence Bureau of the Joint Staff Department of the Central Military Commission China |
||||||
| Ransomware | Indian military and government defense 20TB id18393 View details | Public Sector | — | |||
|
Indian military and government defense 20TB |
||||||
| Ransomware | Indian military and government defense 20TB id33069 View details | India | Public Sector | — | ||
|
The Indian military and government defense 20TB entity represents a substantial data repository within India's public sector defense domain, encompassing military operations, government security functions, and defense-related administrative and technical information. This listing type identifies the entity as a ransomware victim, highlighting exposure within critical infrastructure and government defense systems. The association with threat actor babuk2 underscores a cyber threat targeting national defense and public sector assets in India. This catalog entry serves threat-intelligence purposes by documenting the ransomware incident context for defense sector analysts and cybersecurity professionals monitoring state-linked infrastructure threats. |
||||||
| Ransomware | Indian military and government defense 20TB id33069 View details | India | Public Sector | — | ||
|
Indian military and government defense 20TB |
||||||
| Ransomware | Indian military and government defense 20TB id18393 View details | Public Sector | — | |||
|
Indian military and government defense 20TB |
||||||