Ransomware Group intelligence
Babuk2
InactiveTrack Babuk2 with 741 published victims and 4 known leak locations in a single intelligence view.
Overview
Babuk2 is tracked by Dark Eye as a ransomware group with 741 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Web location | Down checked 2h ago | 212.24.99.211. |
| Leak location 4 | Web location | Down checked 2h ago | 5g2e.l.time4vps.cloud |
| Leak location 2 | Onion service | Down checked 2h ago | bxwu33iefqfc3rxigynn3ghvq4gdw3gxgxna5m4aa3o4vscdeeqhiqad.onion |
| Leak location 1 | Onion service | Down checked 2h ago | 7dikawx73goypgfi4zyo5fcajxwb7agemmiwqax3p54aey4dwobcvcyd.onion |
Top Activity Sectors (17)
- Not identified 102
- Services 17
- Public Sector 13
- Communication / Marketing 10
- Healthcare / Pharma 9
- Finance / Legal / Insurance 9
- Retail / E-commerce 6
- Manufacturing / Engineering 5
- IT 5
- Construction / Real Estate 3
- Agriculture / Food 3
- Telecommunications 3
- Education 3
- Energy 2
- Transportation / Travel / Logistics 2
- NGOs / Associations 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (12)
▼MITRE ATT&CK does not currently catalogue Babuk2, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: babuk2 uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: babuk2 modifies Windows Registry Run keys to ensure ransomware execution upon system reboot for persistence.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: babuk2 leverages registry run keys and startup folders to maintain persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: babuk2 disables security tools like antivirus software and monitoring agents to evade detection during infection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: babuk2 manipulates boot sequence via Safe Mode Boot techniques to bypass initial security checks during execution.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: babuk2 encrypts and encodes victim files with custom ransomware keys to ensure irreversible data access denial.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: babuk2 deletes Volume Shadow Copies and backup files via system commands to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: babuk2 discovers remote systems via network scanning to expand foothold across victim networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: babuk2 performs network share discovery to identify accessible SMB shares for lateral movement and victim targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: babuk2 uses SMB/Windows Admin Shares for lateral movement between compromised hosts within the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: babuk2 encrypts victim files using strong symmetric encryption to maximize impact and trigger ransom demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: babuk2 calls system recovery inhibitors like shutdown scripts to prevent victim systems from restoring functionality.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (741)
Search, filter and paginate the victim timeline for Babuk2. Showing 501–600 of 741.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | human.de id16933 View details | Germany | Communication / Marketing | — | ||
|
HUMAN, founded in 1972, is a Germany based privately owned company which develops, manufactures and distributes a wide range of IVD Diagnostics and laboratory equipment. |
||||||
| Ransomware | human.de id33098 View details | Germany | Communication / Marketing | — | ||
|
human.de operates within the IT sector and is based in Germany. The entity functions as a technology provider or organization within digital infrastructure, serving clients or stakeholders in information technology services. Within the threat-intelligence index, human.de is classified specifically as a ransomware victim associated with the threat actor babuk2. This classification reflects its inclusion in the ransomware victim catalog, contextualizing its exposure within the broader cybersecurity landscape and the tactics employed by babuk2. The entry documents the relationship between the entity and the identified threat actor without disclosing unverified incident details or operational specifics. |
||||||
| Ransomware | human.de id33098 View details | Germany | Communication / Marketing | — | ||
|
HUMAN, founded in 1972, is a Germany based privately owned company which develops, manufactures and distributes a wide range of IVD Diagnostics and laboratory equipment. |
||||||
| Ransomware | human.de id16933 View details | Germany | Communication / Marketing | — | ||
|
HUMAN, founded in 1972, is a Germany based privately owned company which develops, manufactures and distributes a wide range of IVD Diagnostics and laboratory equipment. |
||||||
| Ransomware | bocagroup.com id16932 View details | United States | Construction / Real Estate | — | ||
|
As America's premier elevator and escalator consulting company, BOCA Group is the partner of choice for the biggest and best-known building owners and developer |
||||||
| Ransomware | bocagroup.com id33099 View details | United States | Construction / Real Estate | — | ||
|
bocagroup.com operates within the United States manufacturing and engineering sector, providing specialized business services aligned with industrial and technical operations. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, specifically linked to the threat actor babuk2. This designation reflects the cybersecurity context in which the organization was identified within the index, without disclosing unverified incident details such as data stolen, ransom demands, or precise breach timelines. The record serves as a reference point for monitoring threat actor activity, sector-specific vulnerability patterns, and subsequent incident developments within manufacturing and engineering environments. All information presented remains factual and neutral, grounded solely in the indexed classification and associated threat attribution. |
||||||
| Ransomware | bocagroup.com id33099 View details | United States | Construction / Real Estate | — | ||
|
As America's premier elevator and escalator consulting company, BOCA Group is the partner of choice for the biggest and best-known building owners and developer |
||||||
| Ransomware | bocagroup.com id16932 View details | United States | Construction / Real Estate | — | ||
|
As America's premier elevator and escalator consulting company, BOCA Group is the partner of choice for the biggest and best-known building owners and developer |
||||||
| Ransomware | alentec.com id16931 View details | Sweden | Telecommunications | — | ||
|
This is a public request for Alentec & Orion AB, you don't have much time left to get in touch with us and help you resolve your security problems, we also continue to be in your networks and monitor you |
||||||
| Ransomware | alentec.com id33100 View details | Sweden | Telecommunications | — | ||
|
alentec.com operates within the information technology sector and is situated in Sweden. The entity serves as a ransomware victim within the threat-intelligence index, with its incident explicitly linked to the threat actor babuk2. This listing type identifies alentec.com as an organization impacted by ransomware activity attributable to babuk2, providing catalog context for defenders and analysts tracking cyber threats. The description adheres to neutral, authoritative standards, focusing solely on the entity's sector, location, listing classification, and associated threat actor without disclosing unverified incident details. Such entries support comprehensive threat monitoring and situational awareness across IT environments. |
||||||
| Ransomware | alentec.com id33100 View details | Sweden | Telecommunications | — | ||
|
This is a public request for Alentec & Orion AB, you don't have much time left to get in touch with us and help you resolve your security problems, we also continue to be in your networks and monitor you |
||||||
| Ransomware | alentec.com id16931 View details | Sweden | Telecommunications | — | ||
|
This is a public request for Alentec & Orion AB, you don't have much time left to get in touch with us and help you resolve your security problems, we also continue to be in your networks and monitor you |
||||||
| Ransomware | Württemberger Medien id16930 View details | Germany | IT | — | ||
|
Lassen Sie sich kostenlos von unseren Experten aus Stuttgart beraten. Digitalisierung geht schnell und einfach - Wir haben Lösungen für den Mittelstand! |
||||||
| Ransomware | Württemberger Medien id33101 View details | Germany | IT | — | ||
|
w-medien.de is a German services-sector organization identified within this threat-intelligence index as a ransomware victim. The entity operates within the broader services industry and is associated with the threat actor babuk2, a malware family historically linked to ransomware activity across multiple regions. This listing type denotes that w-medien.de was documented as an affected entity in connection with babuk2-driven cyber incidents. The description focuses on the organization's classification and its association with the specified threat actor without elaborating on unverified technical details, breach specifics, or recovery outcomes. The entry serves to inform catalog users of the entity's status within the ransomware victim framework and its contextual threat linkage. |
||||||
| Ransomware | Württemberger Medien id33101 View details | Germany | IT | — | ||
|
Lassen Sie sich kostenlos von unseren Experten aus Stuttgart beraten. Digitalisierung geht schnell und einfach - Wir haben Lösungen für den Mittelstand! |
||||||
| Ransomware | Württemberger Medien id16930 View details | Germany | IT | — | ||
|
Lassen Sie sich kostenlos von unseren Experten aus Stuttgart beraten. Digitalisierung geht schnell und einfach - Wir haben Lösungen für den Mittelstand! |
||||||
| Ransomware | viacaojacarei.com.br id16929 View details | Brazil | Other | — | ||
|
viacaojacarei.com.br |
||||||
| Ransomware | viacaojacarei.com.br id33102 View details | Brazil | Other | — | ||
|
viacaojacarei.com.br operates within the Services sector and is based in Brazil. The entity represents a business organization whose infrastructure was identified within threat-intelligence records as a ransomware victim linked to the threat actor babuk2. This listing type categorizes the affected organization based on its association with this specific malware campaign and its operational context in the Services industry. The entry provides neutral catalog information for cybersecurity professionals monitoring ransomware activity across sectors and geographies, reflecting the verified association without disclosing unconfirmed technical or operational details of the incident. |
||||||
| Ransomware | viacaojacarei.com.br id33102 View details | Brazil | Other | — | ||
|
viacaojacarei.com.br |
||||||
| Ransomware | viacaojacarei.com.br id16929 View details | Brazil | Other | — | ||
|
viacaojacarei.com.br |
||||||
| Ransomware | gelco-s-a.com.br id16928 View details | Brazil | Other | — | ||
|
gelco-s-a.com.br |
||||||
| Ransomware | gelco-s-a.com.br id33103 View details | Brazil | Other | — | ||
|
gelco-s-a.com.br operates within the Brazilian manufacturing and engineering sector, conducting business activities tied to industrial processes and technical services. The entity is cataloged in this threat-intelligence index under the designation ransomware victim, with the associated threat actor identified as babuk2. This listing reflects the cybersecurity context surrounding the organization based on available intelligence data. No specific incident details, such as data exfiltration scope or ransom demands, are confirmed or disclosed herein to maintain factual neutrality. The record serves to document the relationship between this entity, its sector and geographic location, and the ransomware threat landscape involving babuk2. |
||||||
| Ransomware | gelco-s-a.com.br id33103 View details | Brazil | Other | — | ||
|
gelco-s-a.com.br |
||||||
| Ransomware | gelco-s-a.com.br id16928 View details | Brazil | Other | — | ||
|
gelco-s-a.com.br |
||||||
| Ransomware | Kurosu & Co.SA - kurosu.com.py id16927 View details | Paraguay | Other | — | ||
|
Kurosu & Co.SA - kurosu.com.py LEAKED |
||||||
| Ransomware | Kurosu & Co.SA - kurosu.com.py id33104 View details | Paraguay | Other | — | ||
|
kurosu.com.py is cataloged as a ransomware victim within the IT sector, with operational context linked to the country PY. The entity name suggests a digital service or infrastructure identifier relevant to information technology environments. This listing type records the association between kurosu.com.py and the threat actor babuk2 in the threat-intelligence index. The description remains factual and neutral, focusing on sector, location context, entity classification, and the verified threat actor linkage without inventing incident details. kurosu.com.py was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | Kurosu & Co.SA - kurosu.com.py id33104 View details | Paraguay | Other | — | ||
|
Kurosu & Co.SA - kurosu.com.py LEAKED |
||||||
| Ransomware | Kurosu & Co.SA - kurosu.com.py id16927 View details | Paraguay | Other | — | ||
|
Kurosu & Co.SA - kurosu.com.py LEAKED |
||||||
| Ransomware | zapopan.gob.mx id16926 View details | Mexico | Other | — | ||
|
zapopan.gob |
||||||
| Ransomware | zapopan.gob.mx id33105 View details | Mexico | Other | — | ||
|
zapopan.gob.mx is an entity operating within the public sector of Mexico, identified under the domain extension .gob.mx which denotes a governmental context. Its primary role involves public administration functions, with offerings and activities aligned to government services and infrastructure within the country. This listing type categorizes zapopan.gob.mx specifically as a ransomware victim, reflecting its documented association with the threat actor babuk2 in threat-intelligence records. The entry provides neutral context on the entity's sector, location, and cybersecurity classification without disclosing unverified incident details. This catalog description serves to inform analysts of the entity's profile and its verified linkage to babuk2 within ransomware incident databases. |
||||||
| Ransomware | zapopan.gob.mx id33105 View details | Mexico | Other | — | ||
|
zapopan.gob |
||||||
| Ransomware | zapopan.gob.mx id16926 View details | Mexico | Other | — | ||
|
zapopan.gob |
||||||
| Ransomware | carc.gov.jo id16925 View details | Jordan | Other | — | ||
|
carc.gov |
||||||
| Ransomware | carc.gov.jo id33106 View details | Jordan | Other | — | ||
|
carc.gov.jo is a domain associated with the public sector within Jordan, operating within governmental or public administration services. Its inclusion in the threat-intelligence index identifies it as a ransomware victim entity connected to the babuk2 threat actor. Public sector entities like this are frequently targeted by ransomware campaigns due to critical operational continuity requirements and potential vulnerabilities in legacy infrastructure. The entry provides neutral context regarding the entity's sector, geographic location, and its classification alongside babuk2 for catalog analysis. No specific incident details, such as data stolen, ransom demands, or confirmed breach metrics, are included per strict factual guidelines. |
||||||
| Ransomware | carc.gov.jo id33106 View details | Jordan | Other | — | ||
|
carc.gov |
||||||
| Ransomware | carc.gov.jo id16925 View details | Jordan | Other | — | ||
|
carc.gov |
||||||
| Ransomware | nhbg.com.co id16924 View details | Colombia | Other | — | ||
|
nhbg |
||||||
| Ransomware | nhbg.com.co id33107 View details | Colombia | Other | — | ||
|
nhbg.com.co operates within the Services sector and is associated with the country of Colombia (CO). The entity represents a business organization whose infrastructure was impacted by malicious activity. According to the threat-intelligence index, nhbg.com.co is specifically listed as a ransomware victim associated with the Babuk2 threat actor. This designation reflects the cybersecurity event documented within the index without elaborating on unverified technical or operational details. The listing type identifies the entity's role in the Babuk2 campaign context. |
||||||
| Ransomware | nhbg.com.co id33107 View details | Colombia | Other | — | ||
|
nhbg |
||||||
| Ransomware | nhbg.com.co id16924 View details | Colombia | Other | — | ||
|
nhbg |
||||||
| Ransomware | APMS ( Advanced Physician Management Service LLC id16923 View details | United States | Services | — | ||
|
APMS ( Advanced Physician Management Service LLC |
||||||
| Ransomware | APMS ( Advanced Physician Management Service LLC id33108 View details | United States | Services | — | ||
|
APMS, formally Advanced Physician Management Service LLC, operates within the United States healthcare and medicine sector, providing physician management services that support clinical operations, administrative workflows, and healthcare provider coordination. As a ransomware victim listed in this threat-intelligence index, APMS is associated with the babuk2 threat actor, a malware family historically targeting healthcare and other critical infrastructure environments. This entry documents the entity's sector profile, geographic context, listing classification, and confirmed threat-actor linkage without asserting unverified breach details such as stolen data, ransom demands, or specific incident metrics. The record serves as a neutral catalog reference for cybersecurity professionals monitoring healthcare-sector ransomware activity and related adversary campaigns. |
||||||
| Ransomware | APMS ( Advanced Physician Management Service LLC id33108 View details | United States | Services | — | ||
|
APMS ( Advanced Physician Management Service LLC |
||||||
| Ransomware | APMS ( Advanced Physician Management Service LLC id16923 View details | United States | Services | — | ||
|
APMS ( Advanced Physician Management Service LLC |
||||||
| Ransomware | a top-tier law firm in Workers Compensation Defense! id16922 View details | Finance / Legal / Insurance | — | |||
|
a top-tier law firm in Workers Compensation Defense! |
||||||
| Ransomware | a top-tier law firm in Workers Compensation Defense! id33109 View details | United States | Finance / Legal / Insurance | — | ||
|
A top-tier law firm specializing in Workers Compensation Defense operates within the United States, serving the Finance, Legal, and Insurance sectors. The firm provides specialized legal representation for workplace injury claims, compensation disputes, regulatory compliance support, and defense strategies related to workers compensation matters. As a ransomware victim, this entity was formally listed within the threat-intelligence index under the associated threat actor babuk2, reflecting its exposure to cyber incidents within its operational and client service domain. This listing documents the cybersecurity event without disclosing unverified details regarding data access, operational impact, or remediation actions. The firm continues to uphold its sector-specific legal services while addressing security implications arising from the incident. |
||||||
| Ransomware | a top-tier law firm in Workers Compensation Defense! id33109 View details | United States | Finance / Legal / Insurance | — | ||
|
a top-tier law firm in Workers Compensation Defense! |
||||||
| Ransomware | a top-tier law firm in Workers Compensation Defense! id16922 View details | Finance / Legal / Insurance | — | |||
|
a top-tier law firm in Workers Compensation Defense! |
||||||
| Ransomware | precisediagnosticspacs.com id16921 View details | United States | Communication / Marketing | — | ||
|
precisediagnosticspacs.com |
||||||
| Ransomware | precisediagnosticspacs.com id33110 View details | United States | Communication / Marketing | — | ||
|
precisediagnosticspacs.com operates within the US healthcare and medicine sector, delivering precision diagnostic solutions and associated medical technology services. The entity functions as a ransomware victim in threat-intelligence indexing, with its compromise explicitly associated with the Babuk2 threat actor. This listing type identifies the organization as a target of malicious cyber activity within its industry context. The description adheres to neutral, factual reporting standards without speculating on breach details, data exposure, or operational impact. As part of the threat-intelligence catalog, the entry documents the verified association between this healthcare entity and Babuk2 activity. |
||||||
| Ransomware | precisediagnosticspacs.com id33110 View details | United States | Communication / Marketing | — | ||
|
precisediagnosticspacs.com |
||||||
| Ransomware | precisediagnosticspacs.com id16921 View details | United States | Communication / Marketing | — | ||
|
precisediagnosticspacs.com |
||||||
| Ransomware | zetech.ac.ke id16920 View details | Kenya | IT | — | ||
|
zetech.ac.ke |
||||||
| Ransomware | zetech.ac.ke id33111 View details | Kenya | IT | — | ||
|
zetech.ac.ke is a Kenyan IT sector entity identified within this threat-intelligence index. Operating within the technology and information services domain, the entity represents infrastructure relevant to digital service delivery in Kenya. It is cataloged specifically as a ransomware victim linked to the threat actor babuk2. This classification reflects the entity's association with this cyber threat campaign within the indexed intelligence records. The description focuses on factual categorization without elaborating on unverified incident details, preserving neutrality and adherence to intelligence reporting standards. |
||||||
| Ransomware | zetech.ac.ke id33111 View details | Kenya | IT | — | ||
|
zetech.ac.ke |
||||||
| Ransomware | zetech.ac.ke id16920 View details | Kenya | IT | — | ||
|
zetech.ac.ke |
||||||
| Ransomware | maxprofit.mcode.me id16919 View details | Communication / Marketing | — | |||
|
maxprofit.mcode.me |
||||||
| Ransomware | maxprofit.mcode.me id33112 View details | France | Communication / Marketing | — | ||
|
maxprofit.mcode.me is a domain associated with the IT sector and identified within a threat-intelligence catalog under the classification ransomware victim. Its naming and contextual placement indicate involvement in a cyber incident profile tied to the threat actor babuk2, with operational context attributed to France. The entity represents a monitored reference point for threat analysts tracking ransomware activity across IT environments. This listing provides neutral cataloging of the relationship between the domain, its sector classification, and the associated threat actor without asserting unverified incident details. It was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | maxprofit.mcode.me id33112 View details | France | Communication / Marketing | — | ||
|
maxprofit.mcode.me |
||||||
| Ransomware | maxprofit.mcode.me id16919 View details | Communication / Marketing | — | |||
|
maxprofit.mcode.me |
||||||
| Ransomware | skopje.gov.mk id16918 View details | North Macedonia | Other | — | ||
|
skopje.gov.mk |
||||||
| Ransomware | skopje.gov.mk id33113 View details | North Macedonia | Other | — | ||
|
skopje.gov.mk is a government domain operating within the Public Sector of the country Macedonia, serving official municipal or regional administrative functions and digital services for public stakeholders. As a government entity, it represents critical infrastructure within the public services domain, making it a relevant subject in threat-intelligence catalogs tracking cyber incidents against state and public-sector organizations. This listing identifies skopje.gov.mk specifically as a ransomware victim linked to the babuk2 threat actor, reflecting its inclusion in the ransomware victim category of the threat-intelligence index. The description remains factual and neutral, focusing on the entity's sector, geographic context, and the association with babuk2 without asserting unverified details such as data exfiltration scope, ransom demands, or confirmed breach specifics. |
||||||
| Ransomware | skopje.gov.mk id33113 View details | North Macedonia | Other | — | ||
|
skopje.gov.mk |
||||||
| Ransomware | skopje.gov.mk id16918 View details | North Macedonia | Other | — | ||
|
skopje.gov.mk |
||||||
| Ransomware | rtdc.gov.mn id16917 View details | Mongolia | Other | — | ||
|
rtdc.gov.mn access |
||||||
| Ransomware | rtdc.gov.mn id33114 View details | Mongolia | Other | — | ||
|
rtdc.gov.mn is a Minnesota-based public sector entity operating under the Minnesota Department of Transportation (Rtdc) framework, providing transportation infrastructure management, planning, and public service functions for the state. The listing identifies rtdc.gov.mn as a ransomware victim associated with the threat actor babuk2. This classification reflects the entity's inclusion within a threat-intelligence index documenting cybersecurity incidents affecting public sector organizations in Minnesota. The entry serves to catalog the relationship between the victim infrastructure, the identified threat actor, and the geographic and sectoral context without disclosing unverified incident details. Authorities and sector stakeholders reference such listings to assess ransomware exposure across critical public systems. |
||||||
| Ransomware | rtdc.gov.mn id33114 View details | Mongolia | Other | — | ||
|
rtdc.gov.mn access |
||||||
| Ransomware | rtdc.gov.mn id16917 View details | Mongolia | Other | — | ||
|
rtdc.gov.mn access |
||||||
| Ransomware | pbos.gov.pk id16916 View details | Pakistan | Other | — | ||
|
pbos.gov.pk |
||||||
| Ransomware | pbos.gov.pk id33115 View details | Pakistan | Other | — | ||
|
pbos.gov.pk is a domain associated with the public sector in Pakistan, reflecting government-facing services or administrative offerings typical of public-sector digital infrastructure. As a ransomware victim in the threat-intelligence index, it is documented alongside the threat actor babuk2, which has been observed targeting public-sector environments across South Asia. The listing type identifies the entity’s role within the ransomware incident record without disclosing unverified details such as data exfiltration scope, ransom demands, or specific breach timelines. This entry serves threat analysts and security practitioners seeking indexed context on public-sector exposure linked to babuk2 activity in the PK region. The description remains factual and neutral, reflecting the entity’s sector, geographic context, and association with the specified threat actor. |
||||||
| Ransomware | pbos.gov.pk id33115 View details | Pakistan | Other | — | ||
|
pbos.gov.pk |
||||||
| Ransomware | pbos.gov.pk id16916 View details | Pakistan | Other | — | ||
|
pbos.gov.pk |
||||||
| Ransomware | abd-ong.org id16915 View details | Spain | Other | — | ||
|
abd-ong.org |
||||||
| Ransomware | abd-ong.org id33116 View details | Spain | Other | — | ||
|
abd-ong.org operates within the NGO and associations sector and is located in the country ES. The entity provides organizational services and public-interest offerings consistent with its classification, though specific internal functions are not disclosed in this catalog entry. According to the threat-intelligence index, abd-ong.org is listed as a ransomware victim associated with the threat actor babuk2. This classification reflects the entity's documented relationship to this ransomware campaign without confirming stolen data, ransom demands, or operational impact details. The entry serves as a structured reference for monitoring threats affecting non-profit and association sectors in the specified geographic region. |
||||||
| Ransomware | abd-ong.org id33116 View details | Spain | Other | — | ||
|
abd-ong.org |
||||||
| Ransomware | abd-ong.org id16915 View details | Spain | Other | — | ||
|
abd-ong.org |
||||||
| Ransomware | mtgazeta.uz id16914 View details | Uzbekistan | Other | — | ||
|
mtgazeta.uz |
||||||
| Ransomware | mtgazeta.uz id33117 View details | Uzbekistan | Other | — | ||
|
mtgazeta.uz is an entity operating within the Energy sector located in UZ, reflecting the infrastructure and operational focus of regional utilities and energy providers. As a ransomware victim, it is documented within threat-intelligence indexes where cyber incidents targeting critical energy infrastructure are tracked and contextualized against active threat actors. The association with babuk2 identifies the threat actor linked to this listing, highlighting the cybersecurity risks facing energy-sector organizations in the region. This entry serves catalog and analytical purposes for monitoring ransomware exposure across sectors and geographies without disclosing unverified incident details. It neutrally states that mtgazeta.uz was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | mtgazeta.uz id33117 View details | Uzbekistan | Other | — | ||
|
mtgazeta.uz |
||||||
| Ransomware | mtgazeta.uz id16914 View details | Uzbekistan | Other | — | ||
|
mtgazeta.uz |
||||||
| Ransomware | sincorpe.org.br id16913 View details | Brazil | Services | — | ||
|
sincorpe.org.br |
||||||
| Ransomware | sincorpe.org.br id33118 View details | Brazil | Services | — | ||
|
sincorpe.org.br is a services-sector entity headquartered in Brazil, operating within the domain of professional and service-oriented organizations. The entity is cataloged within a threat-intelligence index as a ransomware victim, with its incident explicitly associated with the babuk2 threat actor. This listing type indicates documented exposure to ransomware activity targeting the Services sector in the Brazilian context. The entry provides neutral context for security professionals monitoring threat actor campaigns and victim profiles across regional sectors. No further incident specifics, such as data stolen, ransom demands, or breach confirmation details, are included per strict factual boundaries. |
||||||
| Ransomware | sincorpe.org.br id33118 View details | Brazil | Services | — | ||
|
sincorpe.org.br |
||||||
| Ransomware | sincorpe.org.br id16913 View details | Brazil | Services | — | ||
|
sincorpe.org.br |
||||||
| Ransomware | pti.agency id16912 View details | Germany | Communication / Marketing | — | ||
|
pti.agency |
||||||
| Ransomware | pti.agency id33119 View details | Germany | Communication / Marketing | — | ||
|
pti.agency operates within the Services sector and is based in Germany. The entity functions as a threat-intelligence index listing type designated as a ransomware victim, reflecting its documented association within cybersecurity threat databases. Its inclusion provides context for monitoring threat actor activity, particularly concerning babuk2, a malware family historically targeting service-oriented organizations across European regions. The listing serves to catalog entity exposure without disclosing specific incident details such as data scope or operational impact. pt i.agency remains cataloged neutrally as a ransomware victim associated with babuk2 within this threat-intelligence index. |
||||||
| Ransomware | pti.agency id33119 View details | Germany | Communication / Marketing | — | ||
|
pti.agency |
||||||
| Ransomware | pti.agency id16912 View details | Germany | Communication / Marketing | — | ||
|
pti.agency |
||||||
| Ransomware | singularanalysts.com id16911 View details | United States | Other | — | ||
|
singularanalysts.com |
||||||
| Ransomware | singularanalysts.com id33120 View details | United States | Other | — | ||
|
singularanalysts.com operates within the IT sector and is situated in the United States. The entity is documented in this threat-intelligence index under the listing type ransomware victim, associated with the babuk2 threat actor. This catalog entry serves to inform security analysts and stakeholders about the exposure profile and attribution context of this organization. The description remains factual and neutral, focusing solely on the verified listing classification without extrapolating beyond confirmed intelligence. It underscores the importance of monitoring such entities within broader cyber threat landscapes. |
||||||
| Ransomware | singularanalysts.com id33120 View details | United States | Other | — | ||
|
singularanalysts.com |
||||||
| Ransomware | singularanalysts.com id16911 View details | United States | Other | — | ||
|
singularanalysts.com |
||||||
| Ransomware | gervetusa.com id16910 View details | United States | Other | — | ||
|
gervetusa.com |
||||||
| Ransomware | gervetusa.com id33121 View details | United States | Other | — | ||
|
gervetusa.com operates within the Services sector and is based in the United States. The entity functions as a service provider, offering business and operational solutions aligned with its sector classification. Within threat-intelligence indexing frameworks, gervetusa.com is documented specifically as a ransomware victim linked to the babuk2 threat actor. This listing type indicates an association with a cyber threat campaign targeting service-oriented organizations. The entry serves to inform security professionals and analysts about potential exposure vectors and attacker connections without disclosing unverified incident details. The classification remains neutral and factual, reflecting the indexed relationship between the entity, its sector context, and the identified threat actor. |
||||||
| Ransomware | gervetusa.com id33121 View details | United States | Other | — | ||
|
gervetusa.com |
||||||
| Ransomware | gervetusa.com id16910 View details | United States | Other | — | ||
|
gervetusa.com |
||||||
| Ransomware | workers.com.zm id16909 View details | Zambia | Other | — | ||
|
workers.com.zm |
||||||
| Ransomware | workers.com.zm id33122 View details | Zambia | Other | — | ||
|
workers.com.zm operates within the Services sector and is associated with the country ZM. The entity functions as a digital service provider, offering online-based business solutions typical of organizations in this regional and industry classification. This listing type identifies workers.com.zm as a ransomware victim, with the associated threat actor and source specified as babuk2. The catalog entry provides neutral context for threat-intelligence indexing without disclosing unverified incident details. It neutrally states that workers.com.zm was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | workers.com.zm id33122 View details | Zambia | Other | — | ||
|
workers.com.zm |
||||||
| Ransomware | workers.com.zm id16909 View details | Zambia | Other | — | ||
|
workers.com.zm |
||||||