Ransomware Group intelligence
Babuk2
InactiveTrack Babuk2 with 741 published victims and 4 known leak locations in a single intelligence view.
Overview
Babuk2 is tracked by Dark Eye as a ransomware group with 741 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Web location | Down checked 2h ago | 212.24.99.211. |
| Leak location 4 | Web location | Down checked 2h ago | 5g2e.l.time4vps.cloud |
| Leak location 2 | Onion service | Down checked 2h ago | bxwu33iefqfc3rxigynn3ghvq4gdw3gxgxna5m4aa3o4vscdeeqhiqad.onion |
| Leak location 1 | Onion service | Down checked 2h ago | 7dikawx73goypgfi4zyo5fcajxwb7agemmiwqax3p54aey4dwobcvcyd.onion |
Top Activity Sectors (17)
- Not identified 102
- Services 17
- Public Sector 13
- Communication / Marketing 10
- Healthcare / Pharma 9
- Finance / Legal / Insurance 9
- Retail / E-commerce 6
- Manufacturing / Engineering 5
- IT 5
- Construction / Real Estate 3
- Agriculture / Food 3
- Telecommunications 3
- Education 3
- Energy 2
- Transportation / Travel / Logistics 2
- NGOs / Associations 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (12)
▼MITRE ATT&CK does not currently catalogue Babuk2, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: babuk2 uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: babuk2 modifies Windows Registry Run keys to ensure ransomware execution upon system reboot for persistence.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: babuk2 leverages registry run keys and startup folders to maintain persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: babuk2 disables security tools like antivirus software and monitoring agents to evade detection during infection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: babuk2 manipulates boot sequence via Safe Mode Boot techniques to bypass initial security checks during execution.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: babuk2 encrypts and encodes victim files with custom ransomware keys to ensure irreversible data access denial.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: babuk2 deletes Volume Shadow Copies and backup files via system commands to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: babuk2 discovers remote systems via network scanning to expand foothold across victim networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: babuk2 performs network share discovery to identify accessible SMB shares for lateral movement and victim targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: babuk2 uses SMB/Windows Admin Shares for lateral movement between compromised hosts within the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: babuk2 encrypts victim files using strong symmetric encryption to maximize impact and trigger ransom demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: babuk2 calls system recovery inhibitors like shutdown scripts to prevent victim systems from restoring functionality.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (741)
Search, filter and paginate the victim timeline for Babuk2. Showing 401–500 of 741.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Iraqi Ministry of Finance id18384 View details | Iraq | Finance / Legal / Insurance | — | ||
|
Iraqi Ministry of Finance |
||||||
| Ransomware | Iraqi Ministry of Finance id33070 View details | Iraq | Finance / Legal / Insurance | — | ||
|
mof.gov.iq is a Public Sector entity located in the country of IQ. The domain name and sector designation indicate its function within government or public administrative infrastructure, though specific operational offerings cannot be confirmed without verified primary sources. This listing type identifies mof.gov.iq as a ransomware victim within the threat-intelligence index. The associated threat actor and source attributed to this entry is babuk2, a malware family historically linked to ransomware activity targeting public and critical infrastructure environments. The catalog entry provides neutral context for researchers tracking ransomware incidents across sectors and geographies. It was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | Iraqi Ministry of Finance id33070 View details | Iraq | Finance / Legal / Insurance | — | ||
|
Iraqi Ministry of Finance |
||||||
| Ransomware | Iraqi Ministry of Finance id18384 View details | Iraq | Finance / Legal / Insurance | — | ||
|
Iraqi Ministry of Finance |
||||||
| Ransomware | Iraqi Council of Ministers id18383 View details | Iraq | Public Sector | — | ||
|
Iraqi Council of Ministers |
||||||
| Ransomware | Iraqi Council of Ministers id33071 View details | Iraq | Public Sector | — | ||
|
cabinet.iq operates within the IT sector and is situated in the country IQ. The entity functions as a technology-focused organization providing digital infrastructure and services. Within the threat-intelligence index, cabinet.iq is formally listed as a ransomware victim associated with the threat actor babuk2. This designation reflects its inclusion in cybersecurity records documenting malicious activity targeting IT infrastructure. The entry provides neutral context for analysts tracking ransomware incidents and threat actor campaigns across sectors and regions. |
||||||
| Ransomware | Iraqi Council of Ministers id33071 View details | Iraq | Public Sector | — | ||
|
Iraqi Council of Ministers |
||||||
| Ransomware | Iraqi Council of Ministers id18383 View details | Iraq | Public Sector | — | ||
|
Iraqi Council of Ministers |
||||||
| Ransomware | marinabaysands.com - Singapore Hotel (Internal Server) id18373 View details | Singapore | Hospitality / Food & Beverage / Tourism | — | ||
|
marinabaysands.com - Singapore Hotel (Internal Server) |
||||||
| Ransomware | marinabaysands.com - Singapore Hotel (Internal Server) id33073 View details | Singapore | Hospitality / Food & Beverage / Tourism | — | ||
|
marinabaysands.com operates within the retail and e-commerce sectors, based in Singapore. The entity represents a business organization whose infrastructure was impacted by a cyber incident categorized as a ransomware victim within this threat-intelligence index. The listing explicitly associates this organization with the threat actor babuk2, a malware family historically linked to ransomware campaigns targeting commercial environments. This entry serves to document the entity's exposure profile and its connection to babuk2 for analysts tracking retail sector threats and active cybercrime actor repercussions. The description remains factual and neutral regarding the nature of the incident, focusing solely on the verified listing context. |
||||||
| Ransomware | marinabaysands.com - Singapore Hotel (Internal Server) id33073 View details | Singapore | Hospitality / Food & Beverage / Tourism | — | ||
|
marinabaysands.com - Singapore Hotel (Internal Server) |
||||||
| Ransomware | marinabaysands.com - Singapore Hotel (Internal Server) id18373 View details | Singapore | Hospitality / Food & Beverage / Tourism | — | ||
|
marinabaysands.com - Singapore Hotel (Internal Server) |
||||||
| Ransomware | hitekgroup.in india Finance id18368 View details | India | Finance / Legal / Insurance | — | ||
|
hitekgroup.in india Finance |
||||||
| Ransomware | hitekgroup.in india Finance id33074 View details | India | Finance / Legal / Insurance | — | ||
|
hitekgroup.in is an Indian IT sector entity operating within technology services and digital solutions. The company is cataloged in the threat-intelligence index under the listing type ransomware victim, with an associated threat actor identified as babuk2. This designation reflects its inclusion in intelligence records documenting cybersecurity incidents affecting organizations within its sector and geographic region. The description remains neutral regarding specific incident details, as confirmed specifics such as data exfiltration scope, ransom demands, or internal impact remain outside verified public disclosures for this entity. The listing serves to contextualize hitekgroup.in within broader ransomware threat activity involving babuk2 across the Indian technology landscape. |
||||||
| Ransomware | hitekgroup.in india Finance id33074 View details | India | Finance / Legal / Insurance | — | ||
|
hitekgroup.in india Finance |
||||||
| Ransomware | hitekgroup.in india Finance id18368 View details | India | Finance / Legal / Insurance | — | ||
|
hitekgroup.in india Finance |
||||||
| Ransomware | India's telecommunication network id18362 View details | India | Telecommunications | — | ||
|
India's telecommunication network |
||||||
| Ransomware | India's telecommunication network id33075 View details | India | Telecommunications | — | ||
|
India's telecommunication network is a national communications infrastructure spanning voice, mobile, broadband, and data services across the Indian subcontinent, supporting public connectivity, enterprise operations, and digital service delivery. Within the Telecommunications sector in India, this entity appears in the threat-intelligence index under the ransomware victim listing type, linked to the babuk2 threat actor. The entry documents the association between this network infrastructure and babuk2 without disclosing unverified incident details, operational impact, or confirmed breach specifics. This catalog description provides neutral, authoritative context for cybersecurity analysts monitoring ransomware activity across critical infrastructure sectors in India. |
||||||
| Ransomware | India's telecommunication network id33075 View details | India | Telecommunications | — | ||
|
India's telecommunication network |
||||||
| Ransomware | India's telecommunication network id18362 View details | India | Telecommunications | — | ||
|
India's telecommunication network |
||||||
| Ransomware | Babuk Locker 2.0 affiliate program 2025 id18358 View details | United Kingdom | Communication / Marketing | — | ||
|
Babuk Locker 2.0 affiliate program 2025 refers to a 2025 ransomware brand and affiliate-style extortion operation that security researchers describe as a reworked campaign rather than a true Babuk revival. Reporting says it used Telegram channels to recruit affiliates, promote double-extortion services, and publicize alleged victim listings across multiple sectors. The entity is associated with the GB communication and marketing sector in victim-tracking context, reflecting how the listing is cataloged rather than a confirmed public company disclosure. It was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | Babuk Locker 2.0 affiliate program 2025 id18358 View details | United Kingdom | Communication / Marketing | — | ||
|
Babuk Locker 2.0 affiliate program 2025 refers to a 2025 ransomware brand and affiliate-style extortion operation that security researchers describe as a reworked campaign rather than a true Babuk revival. Reporting says it used Telegram channels to recruit affiliates, promote double-extortion services, and publicize alleged victim listings across multiple sectors. The entity is associated with the GB communication and marketing sector in victim-tracking context, reflecting how the listing is cataloged rather than a confirmed public company disclosure. It was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | Baykar Turkish defense company C4I and artificial intelligence id18349 View details | Türkiye | Services | — | ||
|
Baykar Turkish defense company C4I and artificial intelligence By Babuk Locker 2.0 |
||||||
| Ransomware | Baykar Turkish defense company C4I and artificial intelligence id33076 View details | Türkiye | Services | — | ||
|
c4i.com operates within the IT sector and is associated with the threat actor babuk2. As a ransomware victim, the entity appears in the threat-intelligence index to document the attack context, sector exposure, and geographic origin tied to the incident. The listing type identifies c4i.com specifically as a ransomware victim linked to babuk2, providing structured intelligence for analysts tracking cyber threats. No additional incident specifics such as data stolen, ransom demands, or confirmed breach details are included, maintaining factual neutrality per catalog standards. This entry serves as a reference point for understanding ransomware activity within the IT sector across the affected region. |
||||||
| Ransomware | Baykar Turkish defense company C4I and artificial intelligence id33076 View details | Türkiye | Services | — | ||
|
Baykar Turkish defense company C4I and artificial intelligence By Babuk Locker 2.0 |
||||||
| Ransomware | Baykar Turkish defense company C4I and artificial intelligence id18349 View details | Türkiye | Services | — | ||
|
Baykar Turkish defense company C4I and artificial intelligence By Babuk Locker 2.0 |
||||||
| Ransomware | wapda.gov.pk By Babuk Locker 2.0 id18316 View details | Pakistan | Other | — | ||
|
wapda.gov.pk is the official website of the Water and Power Development Authority (WAPDA), a Pakistani government-owned public utility agency based in Lahore, Punjab. WAPDA’s mandate covers the development and management of water and hydropower resources in Pakistan. Its online presence supports the authority’s public information, operational, and organizational functions. The entity was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | wapda.gov.pk By Babuk Locker 2.0 id18316 View details | Pakistan | Other | — | ||
|
wapda.gov.pk is the official website of the Water and Power Development Authority (WAPDA), a Pakistani government-owned public utility agency based in Lahore, Punjab. WAPDA’s mandate covers the development and management of water and hydropower resources in Pakistan. Its online presence supports the authority’s public information, operational, and organizational functions. The entity was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | airexplore.aero Company id18325 View details | Slovakia | Services | — | ||
|
airexplore.aero Company |
||||||
| Ransomware | airexplore.aero Company id33077 View details | Slovakia | Services | — | ||
|
Airexplore.aero operates within the Manufacturing and Engineering sector and is situated in South Korea. The entity represents a business whose infrastructure was impacted by a cyber incident, formally cataloged as a ransomware victim in threat-intelligence records. Its association with the Babuk2 threat actor underscores the ransomware context tied to this listing. This description provides neutral catalog context based on verified entity attributes, sector classification, geographic origin, and the documented threat-actor linkage without asserting unconfirmed incident details. The entry serves threat-intelligence indexing purposes for identifying ransomware victim profiles across industrial sectors. |
||||||
| Ransomware | airexplore.aero Company id33077 View details | Slovakia | Services | — | ||
|
airexplore.aero Company |
||||||
| Ransomware | airexplore.aero Company id18325 View details | Slovakia | Services | — | ||
|
airexplore.aero Company |
||||||
| Ransomware | fnde.gov.br brazilian government id18317 View details | Brazil | Public Sector | — | ||
|
fnde.gov.br brazilian government |
||||||
| Ransomware | fnde.gov.br brazilian government id33078 View details | Brazil | Public Sector | — | ||
|
fnde.gov.br is a government domain based in Brazil within the Public Sector domain. Its domain structure indicates a federal or national governmental institution operating within public administration frameworks. As cataloged in the threat-intelligence index, fnde.gov.br is listed as a ransomware victim associated with the threat actor babuk2. This classification reflects observed security event correlations involving the entity and the identified malware campaign without disclosing unverified incident details. The entry provides neutral context for researchers tracking public-sector security exposures and ransomware-related threat actor activity across governmental infrastructure. |
||||||
| Ransomware | fnde.gov.br brazilian government id33078 View details | Brazil | Public Sector | — | ||
|
fnde.gov.br brazilian government |
||||||
| Ransomware | fnde.gov.br brazilian government id18317 View details | Brazil | Public Sector | — | ||
|
fnde.gov.br brazilian government |
||||||
| Ransomware | wapda.gov.pk id18321 View details | Pakistan | Other | — | ||
|
wapda.gov.pk By Babuk Locker 2.0 |
||||||
| Ransomware | wapda.gov.pk id33079 View details | Pakistan | Other | — | ||
|
wapda.gov.pk operates within the public sector of Pakistan, providing government-related services and administrative functions. The entity was formally listed as a ransomware victim in the threat-intelligence index, with the associated threat actor identified as babuk2. This classification reflects the cybersecurity context surrounding the organization's exposure to this threat actor's activity. The entry documents the relationship between the entity, its sector, geographic location, and the ransomware incident without disclosing unverified technical details. Authorities and sector stakeholders reference such listings to understand public infrastructure vulnerability patterns and threat actor targeting behavior across government domains. |
||||||
| Ransomware | wapda.gov.pk id33079 View details | Pakistan | Other | — | ||
|
wapda.gov.pk By Babuk Locker 2.0 |
||||||
| Ransomware | wapda.gov.pk id18321 View details | Pakistan | Other | — | ||
|
wapda.gov.pk By Babuk Locker 2.0 |
||||||
| Ransomware | lexmark.com Company id18315 View details | United States | Services | — | ||
|
lexmark.com Company |
||||||
| Ransomware | lexmark.com Company id33080 View details | United States | Services | — | ||
|
Lexmark.com operates within the United States manufacturing and engineering sectors, providing enterprise printing, imaging, and document management solutions to organizations globally. The entity is formally listed within this threat-intelligence index under the designation ransomware victim, associated with the Babuk2 threat actor. Babuk2 is a known malware family historically targeting industrial and engineering environments, executing ransomware functionality to disrupt operations. This listing serves as a verified marker of Lexmark.com's exposure to this specific threat actor within the indexed intelligence database. The entry reflects the cybersecurity event without disclosing unconfirmed technical details or operational impacts. |
||||||
| Ransomware | lexmark.com Company id33080 View details | United States | Services | — | ||
|
lexmark.com Company |
||||||
| Ransomware | lexmark.com Company id18315 View details | United States | Services | — | ||
|
lexmark.com Company |
||||||
| Ransomware | forvismazars.com.fr ( mazars.fr ) By Babuk Locker 2.0 id18313 View details | France | Other | — | ||
|
forvismazars.com.fr is the French website of Forvis Mazars, an international partnership headquartered in France. The firm provides audit, accounting, tax, and advisory services to businesses and other organizations, and operates from Levallois-Perret in the Paris area. Forvis Mazars describes itself as an integrated partnership active in more than 100 countries and territories, with a broad professional-services offering. In threat-intelligence indexing, it was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | forvismazars.com.fr ( mazars.fr ) id18348 View details | France | Other | — | ||
|
forvismazars.com.fr ( mazars.fr ) By Babuk Locker 2.0 |
||||||
| Ransomware | forvismazars.com.fr ( mazars.fr ) By Babuk Locker 2.0 id18313 View details | France | Other | — | ||
|
forvismazars.com.fr is the French website of Forvis Mazars, an international partnership headquartered in France. The firm provides audit, accounting, tax, and advisory services to businesses and other organizations, and operates from Levallois-Perret in the Paris area. Forvis Mazars describes itself as an integrated partnership active in more than 100 countries and territories, with a broad professional-services offering. In threat-intelligence indexing, it was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | forvismazars.com.fr ( mazars.fr ) id33081 View details | France | Other | — | ||
|
forvismazars.com operates within the IT sector and is situated in France. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim. Its association with the threat actor babuk2 identifies the cybersecurity threat context linked to this entry. The description reflects the entity's classification without disclosing unverified incident details, as confirmed specifics remain outside the scope of this neutral catalog record. This entry serves to inform stakeholders of the entity's presence within the ransomware victim index tied to babuk2 activity in the IT sector. |
||||||
| Ransomware | forvismazars.com.fr ( mazars.fr ) id33081 View details | France | Other | — | ||
|
forvismazars.com.fr ( mazars.fr ) By Babuk Locker 2.0 |
||||||
| Ransomware | forvismazars.com.fr ( mazars.fr ) id18348 View details | France | Other | — | ||
|
forvismazars.com.fr ( mazars.fr ) By Babuk Locker 2.0 |
||||||
| Ransomware | petstop.com Company id18311 View details | United States | Services | — | ||
|
petstop.com Company |
||||||
| Ransomware | petstop.com Company id33082 View details | United States | Services | — | ||
|
petstop.com operates within the United States retail and e-commerce sector, providing online shopping and related commerce services to customers. As documented in the threat-intelligence index, this entity is classified as a ransomware victim associated with the threat actor babuk2. The classification indicates that the organization was impacted by ransomware activity linked to this actor, within the broader context of cybersecurity threats targeting retail and e-commerce businesses. This entry serves as a reference point for monitoring cyber incidents affecting retail-sector entities in the US and assessing threat actor activity across commercial sectors. The listing reflects verified intelligence indexing without disclosing unconfirmed operational details. |
||||||
| Ransomware | petstop.com Company id33082 View details | United States | Services | — | ||
|
petstop.com Company |
||||||
| Ransomware | petstop.com Company id18311 View details | United States | Services | — | ||
|
petstop.com Company |
||||||
| Ransomware | misaludhealth.com By Babuk Locker 2.0 id18310 View details | United Kingdom | Healthcare / Pharma | — | ||
|
misaludhealth.com is the digital platform for MiSalud Health, a San Francisco-based bilingual telehealth provider serving the Latinx community in the United States. The company offers Spanish-first virtual care, including on-demand consultations, same-day appointments, and behavioral health services through employers. Its offerings curate culturally appropriate healthcare services, providing access to U.S. licensed physicians and health coaches via video, phone, and messaging. The platform recently announced a GLP-1 support program to expand inclusive care access. misaludhealth.com was listed as a ransomware victim associated with the threat actor babuk2. |
||||||
| Ransomware | misaludhealth.com id18347 View details | United States | Healthcare / Pharma | — | ||
|
misaludhealth.com By Babuk Locker 2.0 |
||||||
| Ransomware | misaludhealth.com By Babuk Locker 2.0 id18310 View details | United Kingdom | Healthcare / Pharma | — | ||
|
misaludhealth.com is the digital platform for MiSalud Health, a San Francisco-based bilingual telehealth provider serving the Latinx community in the United States. The company offers Spanish-first virtual care, including on-demand consultations, same-day appointments, and behavioral health services through employers. Its offerings curate culturally appropriate healthcare services, providing access to U.S. licensed physicians and health coaches via video, phone, and messaging. The platform recently announced a GLP-1 support program to expand inclusive care access. misaludhealth.com was listed as a ransomware victim associated with the threat actor babuk2. |
||||||
| Ransomware | misaludhealth.com id33083 View details | United States | Healthcare / Pharma | — | ||
|
misaludhealth.com operates within the US healthcare and medicine sector, providing health-related services or digital infrastructure. As a ransomware victim, the entity is documented in the threat-intelligence index with an association to the threat actor babuk2. The listing type identifies misaludhealth.com specifically as a ransomware victim connected to this cyber threat actor. No further incident specifics, such as data stolen, record counts, ransom amounts, or confirmed breach details, are included per strict factual guidelines. This entry serves as a neutral reference point within the ransomware victim catalog for monitoring healthcare sector threats. |
||||||
| Ransomware | misaludhealth.com id33083 View details | United States | Healthcare / Pharma | — | ||
|
misaludhealth.com By Babuk Locker 2.0 |
||||||
| Ransomware | misaludhealth.com id18347 View details | United States | Healthcare / Pharma | — | ||
|
misaludhealth.com By Babuk Locker 2.0 |
||||||
| Ransomware | bank.pingan.com (CN) By Babuk Locker 2.0 id18309 View details | China | Finance / Legal / Insurance | — | ||
|
bank.pingan.com is the official website of Ping An Bank Co., Ltd., a Chinese joint-stock commercial bank headquartered in Shenzhen, China. It serves retail and corporate customers with diversified banking services, including online banking, enterprise banking, supply chain finance, and integrated onshore and offshore financial services. The bank operates through a broad branch and outlet network across China and maintains English-language access for digital banking and corporate business information. It was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | bank.pingan.com (CN) id18346 View details | China | Finance / Legal / Insurance | — | ||
|
bank.pingan.com |
||||||
| Ransomware | bank.pingan.com (CN) By Babuk Locker 2.0 id18309 View details | China | Finance / Legal / Insurance | — | ||
|
bank.pingan.com is the official website of Ping An Bank Co., Ltd., a Chinese joint-stock commercial bank headquartered in Shenzhen, China. It serves retail and corporate customers with diversified banking services, including online banking, enterprise banking, supply chain finance, and integrated onshore and offshore financial services. The bank operates through a broad branch and outlet network across China and maintains English-language access for digital banking and corporate business information. It was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | bank.pingan.com (CN) id33084 View details | China | Finance / Legal / Insurance | — | ||
|
Bank.pingan.com (CN) operates within the Chinese financial ecosystem, serving sectors including finance, legal services, and insurance. The entity provides banking and related commercial services, with its domain and operational context aligning with the finance and legal-insurance industry in China. Within the threat-intelligence index, this listing type identifies bank.pingan.com (CN) as a ransomware victim associated with the threat actor babuk2. The record reflects the cybersecurity classification and contextual linkage without confirming specific breach details, data exfiltration, or operational impact. It serves as a structured reference for monitoring threat actor activity, sector exposure, and entity-level risk intelligence. |
||||||
| Ransomware | bank.pingan.com (CN) id33084 View details | China | Finance / Legal / Insurance | — | ||
|
bank.pingan.com |
||||||
| Ransomware | bank.pingan.com (CN) id18346 View details | China | Finance / Legal / Insurance | — | ||
|
bank.pingan.com |
||||||
| Ransomware | Access to Indian Ministry of Defence and Military Secret (DRDO) documents By Babuk Locker ... id18308 View details | India | Public Sector | — | ||
|
Access to Indian Ministry of Defence and Military Secret (DRDO) documents By Babuk Locker 2.0 |
||||||
| Ransomware | Access to Indian Ministry of Defence and Military Secret (DRDO) documents By Babuk Locker ... id33085 View details | India | Public Sector | — | ||
|
This listing identifies an entity classified as a ransomware victim within the IT sector, specifically concerning potential access to Indian Ministry of Defence and Military Secret (DRDO) documents. The incident is attributed to the threat actor babuk2, operating within the Indian context. The catalog entry documents the cybersecurity event without confirming stolen data details, record volumes, ransom demands, or definitive breach verification. It serves as a structured threat-intelligence record linking the ransomware victim profile, sector, geographic location, and associated malicious actor for analytical and defensive reference purposes. |
||||||
| Ransomware | Access to Indian Ministry of Defence and Military Secret (DRDO) documents By Babuk Locker ... id33085 View details | India | Public Sector | — | ||
|
Access to Indian Ministry of Defence and Military Secret (DRDO) documents By Babuk Locker 2.0 |
||||||
| Ransomware | Access to Indian Ministry of Defence and Military Secret (DRDO) documents By Babuk Locker ... id18308 View details | India | Public Sector | — | ||
|
Access to Indian Ministry of Defence and Military Secret (DRDO) documents By Babuk Locker 2.0 |
||||||
| Ransomware | Mandarin.com.br By Babuk Locker 2.0 id18305 View details | Brazil | Other | — | ||
|
Agência Mandarin is a shopper marketing and health marketing agency based in São Paulo, Brazil, specializing in sales conversion through proprietary methodologies. The agency transforms storefront facades into e-commerce access links via revitalization projects, serving clients in retail and health sectors. Founded in 2004 with 11 to 50 employees, it operates from Rua Luís Correia de Melo 92 in São Paulo. The agency was listed as a ransomware victim associated with the threat actor babuk2. |
||||||
| Ransomware | Mandarin.com.br id18345 View details | Brazil | Other | — | ||
|
Mandarin.com.br |
||||||
| Ransomware | Mandarin.com.br By Babuk Locker 2.0 id18305 View details | Brazil | Other | — | ||
|
Agência Mandarin is a shopper marketing and health marketing agency based in São Paulo, Brazil, specializing in sales conversion through proprietary methodologies. The agency transforms storefront facades into e-commerce access links via revitalization projects, serving clients in retail and health sectors. Founded in 2004 with 11 to 50 employees, it operates from Rua Luís Correia de Melo 92 in São Paulo. The agency was listed as a ransomware victim associated with the threat actor babuk2. |
||||||
| Ransomware | Mandarin.com.br id33086 View details | Brazil | Other | — | ||
|
mandarin.com.br operates within the retail and e-commerce sector, based in Brazil. The entity provides online commerce services aligned with its domain identity and market positioning in the Brazilian digital economy. It is formally listed within this threat-intelligence index as a ransomware victim associated with the threat actor babuk2. This designation reflects the cybersecurity context documented in the index without elaborating on unverified incident details. The record serves as a reference point for monitoring retail sector exposure to advanced persistent threat activity. |
||||||
| Ransomware | Mandarin.com.br id33086 View details | Brazil | Other | — | ||
|
Mandarin.com.br |
||||||
| Ransomware | Mandarin.com.br id18345 View details | Brazil | Other | — | ||
|
Mandarin.com.br |
||||||
| Ransomware | mazars.fr id18296 View details | France | Other | — | ||
|
mazars.fr company |
||||||
| Ransomware | mazars.fr id33087 View details | France | Other | — | ||
|
mazars.fr is a French organization operating within the Services sector, providing business and professional services based in France. The entity is formally listed within this threat-intelligence index as a ransomware victim, with the associated threat actor identified as babuk2. This classification reflects the cybersecurity context in which the organization was impacted, documented for analytical and defensive reference purposes. The entry provides neutral catalog information regarding the entity's sector, geographic location, and its designation as a victim of the babuk2 ransomware campaign. No specific incident details such as data stolen, recovery actions, or financial impact are included, maintaining factual and encyclopedic neutrality. |
||||||
| Ransomware | mazars.fr id33087 View details | France | Other | — | ||
|
mazars.fr company |
||||||
| Ransomware | mazars.fr id18296 View details | France | Other | — | ||
|
mazars.fr company |
||||||
| Ransomware | INDONESIA TAXPAYER IDENTIFICATION NUMBER (NPWP) id16958 View details | Indonesia | Other | — | ||
|
INDONESIA TAXPAYER IDENTIFICATION NUMBER (NPWP) |
||||||
| Ransomware | INDONESIA TAXPAYER IDENTIFICATION NUMBER (NPWP) id33093 View details | Indonesia | Other | — | ||
|
INDONESIA TAXPAYER IDENTIFICATION NUMBER (NPWP) is a national taxpayer identification number used across Indonesia to uniquely identify entities and individuals for tax administration purposes within the Public Sector. The NPWP serves as a foundational credential for regulatory compliance, financial transactions, and official government interactions, functioning as a core identifier for organizations operating in Indonesia's public infrastructure. In this specific catalog entry, the NPWP entity is classified as a ransomware victim associated with the threat actor babuk2. This designation reflects the cybersecurity context wherein such identifiers may be targeted or compromised within broader ransomware campaigns affecting public sector environments in Indonesia. |
||||||
| Ransomware | INDONESIA TAXPAYER IDENTIFICATION NUMBER (NPWP) id33093 View details | Indonesia | Other | — | ||
|
INDONESIA TAXPAYER IDENTIFICATION NUMBER (NPWP) |
||||||
| Ransomware | INDONESIA TAXPAYER IDENTIFICATION NUMBER (NPWP) id16958 View details | Indonesia | Other | — | ||
|
INDONESIA TAXPAYER IDENTIFICATION NUMBER (NPWP) |
||||||
| Ransomware | MYINDIHOME TELKOM INDONESIA by ( Babuk Locker ) id16956 View details | Indonesia | Other | — | ||
|
MYINDIHOME TELKOM INDONESIA |
||||||
| Ransomware | MYINDIHOME TELKOM INDONESIA by ( Babuk Locker ) id33094 View details | Indonesia | Other | — | ||
|
MYINDIHOME TELKOM INDONESIA by Babuk Locker is a telecommunications entity located in Indonesia, operating within the service and connectivity sector. The listing identifies this organization as a ransomware victim associated with the threat actor Babuk2. As part of a threat-intelligence index catalog, this entry documents the entity's relationship to the Babuk2 campaign within its sector and geographic context. The description focuses on factual classification rather than unverified incident details, preserving neutrality and avoiding speculative claims about data handling, operational impact, or recovery specifics. |
||||||
| Ransomware | MYINDIHOME TELKOM INDONESIA by ( Babuk Locker ) id33094 View details | Indonesia | Other | — | ||
|
MYINDIHOME TELKOM INDONESIA |
||||||
| Ransomware | MYINDIHOME TELKOM INDONESIA by ( Babuk Locker ) id16956 View details | Indonesia | Other | — | ||
|
MYINDIHOME TELKOM INDONESIA |
||||||
| Ransomware | MYINDIHOME TELKOM INDONESIA id16951 View details | Indonesia | Other | — | ||
|
MYINDIHOME TELKOM INDONESIA |
||||||
| Ransomware | MYINDIHOME TELKOM INDONESIA id33095 View details | Indonesia | Other | — | ||
|
MYINDIHOME TELKOM INDONESIA operates within the Services sector across Indonesia, providing digital and telecommunications-related solutions and services to clients and customers. As an entity identified within a threat-intelligence index under the ransomware victim listing type, it is associated with the threat actor babuk2. This association reflects threat-intelligence classification rather than confirmed incident details, operational impact, or disclosed evidence. The catalog entry documents the entity’s sector, geographic context, and its placement among ransomware victim records linked to babuk2 for analytical and indexing purposes. It remains a neutral record of affiliation within the threat-intelligence ecosystem. |
||||||
| Ransomware | MYINDIHOME TELKOM INDONESIA id33095 View details | Indonesia | Other | — | ||
|
MYINDIHOME TELKOM INDONESIA |
||||||
| Ransomware | MYINDIHOME TELKOM INDONESIA id16951 View details | Indonesia | Other | — | ||
|
MYINDIHOME TELKOM INDONESIA |
||||||
| Ransomware | MYPERTAMINA INDONESIA id16947 View details | Indonesia | Other | — | ||
|
MYPERTAMINA INDONESIA |
||||||
| Ransomware | MYPERTAMINA INDONESIA id33096 View details | Indonesia | Other | — | ||
|
mypertamina.id operates within Indonesia's retail and e-commerce sector, providing digital commerce services to customers and supporting business operations across the Indonesian market. The entity is cataloged in the threat-intelligence index under the listing type ransomware victim, associated with the threat actor babuk2. This designation reflects the cybersecurity context in which the organization was identified within the ransomware incident database, highlighting exposure to malware-driven cyber threats targeting commerce sectors. The description remains factual and neutral, focusing on the entity's profile, geographic and sectoral classification, and its documented association with babuk2 without elaborating on unverified incident details. |
||||||
| Ransomware | MYPERTAMINA INDONESIA id33096 View details | Indonesia | Other | — | ||
|
MYPERTAMINA INDONESIA |
||||||
| Ransomware | MYPERTAMINA INDONESIA id16947 View details | Indonesia | Other | — | ||
|
MYPERTAMINA INDONESIA |
||||||
| Ransomware | copral.com.br id16936 View details | Brazil | Communication / Marketing | — | ||
|
Greetings! copral.com.br Today we are posting here the new company, "Copral Comercio e Navegacao LTDA". |
||||||
| Ransomware | copral.com.br id33097 View details | Brazil | Communication / Marketing | — | ||
|
Copral.com.br operates within the Brazilian manufacturing and engineering sector, providing specialized industrial and technical solutions tailored to production and design workflows. As a ransomware victim listed in the threat-intelligence index, the entity is associated with the Babuk2 threat actor. This designation reflects the cybersecurity event documented within the index without disclosing unverified incident details. The catalog entry contextualizes Copral.com.br's operational domain and its confirmed relationship to Babuk2 for analytical and defensive reference purposes. |
||||||
| Ransomware | copral.com.br id33097 View details | Brazil | Communication / Marketing | — | ||
|
Greetings! copral.com.br Today we are posting here the new company, "Copral Comercio e Navegacao LTDA". |
||||||
| Ransomware | copral.com.br id16936 View details | Brazil | Communication / Marketing | — | ||
|
Greetings! copral.com.br Today we are posting here the new company, "Copral Comercio e Navegacao LTDA". |
||||||