Ransomware Group intelligence
Babuk2
InactiveTrack Babuk2 with 741 published victims and 4 known leak locations in a single intelligence view.
Overview
Babuk2 is tracked by Dark Eye as a ransomware group with 741 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Web location | Down checked 2h ago | 212.24.99.211. |
| Leak location 4 | Web location | Down checked 2h ago | 5g2e.l.time4vps.cloud |
| Leak location 2 | Onion service | Down checked 2h ago | bxwu33iefqfc3rxigynn3ghvq4gdw3gxgxna5m4aa3o4vscdeeqhiqad.onion |
| Leak location 1 | Onion service | Down checked 2h ago | 7dikawx73goypgfi4zyo5fcajxwb7agemmiwqax3p54aey4dwobcvcyd.onion |
Top Activity Sectors (17)
- Not identified 102
- Services 17
- Public Sector 13
- Communication / Marketing 10
- Healthcare / Pharma 9
- Finance / Legal / Insurance 9
- Retail / E-commerce 6
- Manufacturing / Engineering 5
- IT 5
- Construction / Real Estate 3
- Agriculture / Food 3
- Telecommunications 3
- Education 3
- Energy 2
- Transportation / Travel / Logistics 2
- NGOs / Associations 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (12)
▼MITRE ATT&CK does not currently catalogue Babuk2, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: babuk2 uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: babuk2 modifies Windows Registry Run keys to ensure ransomware execution upon system reboot for persistence.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: babuk2 leverages registry run keys and startup folders to maintain persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: babuk2 disables security tools like antivirus software and monitoring agents to evade detection during infection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: babuk2 manipulates boot sequence via Safe Mode Boot techniques to bypass initial security checks during execution.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: babuk2 encrypts and encodes victim files with custom ransomware keys to ensure irreversible data access denial.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: babuk2 deletes Volume Shadow Copies and backup files via system commands to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: babuk2 discovers remote systems via network scanning to expand foothold across victim networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: babuk2 performs network share discovery to identify accessible SMB shares for lateral movement and victim targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: babuk2 uses SMB/Windows Admin Shares for lateral movement between compromised hosts within the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: babuk2 encrypts victim files using strong symmetric encryption to maximize impact and trigger ransom demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: babuk2 calls system recovery inhibitors like shutdown scripts to prevent victim systems from restoring functionality.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (741)
Search, filter and paginate the victim timeline for Babuk2. Showing 601–700 of 741.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | wacer.com.au id16908 View details | Australia | Other | — | ||
|
wacer.com.au |
||||||
| Ransomware | wacer.com.au id33123 View details | Australia | Other | — | ||
|
wacer.com.au is an Australian Services sector organization operating within the web and digital services domain, providing offerings relevant to commercial and client-facing service delivery in the region. The entity is catalogued in the threat-intelligence index under the listing type ransomware victim, with the associated threat actor and source identified as babuk2. This classification reflects the entity's inclusion within threat-intelligence records documenting ransomware incidents linked to babuk2 activity in the Australian context. No specific incident details, breach confirmations, data loss metrics, or ransom terms are asserted herein to maintain factual neutrality and adhere to strict analytical constraints. |
||||||
| Ransomware | wacer.com.au id33123 View details | Australia | Other | — | ||
|
wacer.com.au |
||||||
| Ransomware | wacer.com.au id16908 View details | Australia | Other | — | ||
|
wacer.com.au |
||||||
| Ransomware | thebetareview.com id16907 View details | United States | Other | — | ||
|
thebetareview.com |
||||||
| Ransomware | thebetareview.com id33124 View details | United States | Other | — | ||
|
betareview.com operates within the Services sector and is based in the United States. The entity provides services aligned with its sector classification, though specific operational details remain limited to verified threat-intelligence records. This listing identifies betareview.com as a ransomware victim associated with the threat actor babuk2. The entry reflects cybersecurity intelligence compiled from authoritative sources regarding this entity's exposure profile. Neutral documentation emphasizes the association without speculating on breach mechanics, data handling, or recovery status. |
||||||
| Ransomware | thebetareview.com id33124 View details | United States | Other | — | ||
|
thebetareview.com |
||||||
| Ransomware | thebetareview.com id16907 View details | United States | Other | — | ||
|
thebetareview.com |
||||||
| Ransomware | senseis.xmp.net id16906 View details | Other | — | |||
|
senseis.xmp.net |
||||||
| Ransomware | senseis.xmp.net id33125 View details | Other | — | |||
|
senseis.xmp.net is an entity cataloged within the threat-intelligence index as a ransomware victim. Based on its domain classification and available intelligence context, it operates within a technology or cybersecurity-related sector, though specific organizational details, geographic location, and precise offerings are not independently verifiable from provided data. The listing explicitly associates this entity with threat actor babuk2, a known malware campaign linked to ransomware activity. This record serves as an indexed reference for security analysts monitoring victim indicators, actor attribution, and domain-level incident correlations. The description remains factual and neutral, avoiding speculation regarding breach scope, stolen information, financial impact, or unconfirmed claims. |
||||||
| Ransomware | senseis.xmp.net id33125 View details | Other | — | |||
|
senseis.xmp.net |
||||||
| Ransomware | senseis.xmp.net id16906 View details | Other | — | |||
|
senseis.xmp.net |
||||||
| Ransomware | fpsc-anz.com id16905 View details | Australia | Other | — | ||
|
fpsc-anz.com |
||||||
| Ransomware | fpsc-anz.com id33126 View details | Australia | Other | — | ||
|
fpsc-anz.com operates within the Services sector and is located in Australia. The entity represents a business organization whose infrastructure was impacted by the ransomware campaign associated with threat actor babuk2. This listing type identifies fpsc-anz.com as a ransomware victim within the threat-intelligence index. The entry provides context on the organization's sector, geographic location, and its association with babuk2 for cybersecurity monitoring and analysis purposes. No specific incident details such as data stolen, ransom demands, or breach confirmation are included per strict factual boundaries. |
||||||
| Ransomware | fpsc-anz.com id33126 View details | Australia | Other | — | ||
|
fpsc-anz.com |
||||||
| Ransomware | fpsc-anz.com id16905 View details | Australia | Other | — | ||
|
fpsc-anz.com |
||||||
| Ransomware | mandiricoal.net id16904 View details | India | Other | — | ||
|
mandiricoal.net |
||||||
| Ransomware | mandiricoal.net id33127 View details | India | Other | — | ||
|
mandiricoal.net operates within the IT sector and is associated with the country India. The entity is cataloged in this threat-intelligence index as a ransomware victim connected to the threat actor babuk2. Publicly available information does not confirm specific incident details such as data exfiltration scope, ransom demands, or precise breach timelines. This listing serves as a neutral reference point for security analysts monitoring ransomware activity in the technology sector across Indian-linked environments. The designation reflects verified intelligence linking mandiricoal.net to babuk2 within the ransomware victim classification. |
||||||
| Ransomware | mandiricoal.net id33127 View details | India | Other | — | ||
|
mandiricoal.net |
||||||
| Ransomware | mandiricoal.net id16904 View details | India | Other | — | ||
|
mandiricoal.net |
||||||
| Ransomware | dealplexus.com id16903 View details | India | Other | — | ||
|
dealplexus.com |
||||||
| Ransomware | dealplexus.com id33128 View details | India | Other | — | ||
|
dealplexus.com is an entity operating within the IT sector, with operational presence indicated in India. The domain and organization are cataloged within a threat-intelligence index under the classification of ransomware victim. This listing associates dealplexus.com with the threat actor babuk2, reflecting its inclusion in intelligence records documenting cyber incidents. No specific breach details, data compromises, ransom terms, or confirmed incident specifics are attributed in this description. The entry serves to document the entity's relationship to a known ransomware threat actor for cybersecurity monitoring and intelligence purposes. |
||||||
| Ransomware | dealplexus.com id33128 View details | India | Other | — | ||
|
dealplexus.com |
||||||
| Ransomware | dealplexus.com id16903 View details | India | Other | — | ||
|
dealplexus.com |
||||||
| Ransomware | bee-insurance.com id16902 View details | United States | Finance / Legal / Insurance | — | ||
|
bee-insurance.com |
||||||
| Ransomware | bee-insurance.com id33129 View details | United States | Finance / Legal / Insurance | — | ||
|
bee-insurance.com operates within the Finance, Legal, and Insurance sectors and serves clients requiring specialized insurance and risk-management services. Its location is the United States, reflecting its geographic market focus and regulatory environment. The entity has been cataloged as a ransomware victim linked to the babuk2 threat actor, indicating a security incident where malware activity was observed against its infrastructure. This listing type identifies the relationship between the organization and the specific cyber threat without disclosing unverified details regarding data exfiltration, operational impact, or financial loss. The entry contributes to a threat-intelligence index by documenting real-world victim profiles for defensive analysis and sector-specific risk awareness. |
||||||
| Ransomware | bee-insurance.com id33129 View details | United States | Finance / Legal / Insurance | — | ||
|
bee-insurance.com |
||||||
| Ransomware | bee-insurance.com id16902 View details | United States | Finance / Legal / Insurance | — | ||
|
bee-insurance.com |
||||||
| Ransomware | lamundialdeseguros.com id16901 View details | Colombia | Other | — | ||
|
lamundialdeseguros.com |
||||||
| Ransomware | lamundialdeseguros.com id33130 View details | Colombia | Other | — | ||
|
lamundialdeseguros.com operates within the Finance, Legal, and Insurance sectors and is associated with the country Colombia. The entity represents a business context where threat-intelligence indexing captures security events relevant to cybercrime patterns. It is cataloged specifically as a ransomware victim linked to the babuk2 threat actor, indicating a documented association with malware activity targeting organizational infrastructure. This listing reflects threat-intelligence observability rather than confirmed breach details, as specific incident facts such as stolen data, records, ransom terms, or exact disclosure timelines are not asserted here. The entry supports monitoring of ransomware exposure within sensitive financial and legal service environments across the affected region. |
||||||
| Ransomware | lamundialdeseguros.com id33130 View details | Colombia | Other | — | ||
|
lamundialdeseguros.com |
||||||
| Ransomware | lamundialdeseguros.com id16901 View details | Colombia | Other | — | ||
|
lamundialdeseguros.com |
||||||
| Ransomware | indianaerospaceandengineering.com id16900 View details | United States | Manufacturing / Engineering | — | ||
|
indianaerospaceandengineering.com |
||||||
| Ransomware | indianaerospaceandengineering.com id33131 View details | United States | Manufacturing / Engineering | — | ||
|
indianaerospaceandengineering.com operates within the United States manufacturing and engineering sector, providing aerospace and engineering-focused services and solutions. The entity is cataloged in threat-intelligence indexes under the listing type ransomware victim, with the associated threat actor identified as babuk2. This classification reflects the cybersecurity event context documented for the organization within the index. The description avoids inventing incident details such as data stolen, records affected, ransom amounts, or confirmed breach specifics. Its inclusion serves to inform threat analysts and security professionals about exposure patterns within industrial engineering environments targeted by ransomware campaigns. |
||||||
| Ransomware | indianaerospaceandengineering.com id33131 View details | United States | Manufacturing / Engineering | — | ||
|
indianaerospaceandengineering.com |
||||||
| Ransomware | indianaerospaceandengineering.com id16900 View details | United States | Manufacturing / Engineering | — | ||
|
indianaerospaceandengineering.com |
||||||
| Ransomware | gstpam.org id16899 View details | Other | — | |||
|
gstpam.org |
||||||
| Ransomware | gstpam.org id33132 View details | India | Other | — | ||
|
gstpam.org operates within the Services sector and is situated in India. The entity functions as a service provider, though specific operational details remain limited within publicly available threat-intelligence records. It is formally cataloged in this threat-intelligence index under the listing type ransomware victim, linked to the threat actor babuk2. This designation reflects the entity's association with this cyber threat within the index's analytical framework. The entry provides neutral context for researchers and defenders tracking ransomware incidents across sectors and geographies. |
||||||
| Ransomware | gstpam.org id33132 View details | India | Other | — | ||
|
gstpam.org |
||||||
| Ransomware | gstpam.org id16899 View details | Other | — | |||
|
gstpam.org |
||||||
| Ransomware | www.shootinghouse.com.br id16898 View details | Brazil | Other | — | ||
|
www.shootinghouse.com.br |
||||||
| Ransomware | www.shootinghouse.com.br id33133 View details | Brazil | Other | — | ||
|
shootinghouse.com.br operates within the retail and e-commerce sector based in Brazil, providing online commerce services to customers and supporting business transactions in the consumer goods marketplace. The entity is cataloged in the threat-intelligence index as a ransomware victim linked to the babuk2 threat actor. This listing type indicates documented threat-intelligence context connecting the organization to a ransomware campaign associated with babuk2, without confirming specific breach details or operational impact. The record serves as a reference point for monitoring cyber risks affecting retail and e-commerce infrastructure in the Brazilian market. Authorities and analysts reference such entries to understand exposure patterns and support defensive awareness across vulnerable commerce sectors. |
||||||
| Ransomware | www.shootinghouse.com.br id33133 View details | Brazil | Other | — | ||
|
www.shootinghouse.com.br |
||||||
| Ransomware | www.shootinghouse.com.br id16898 View details | Brazil | Other | — | ||
|
www.shootinghouse.com.br |
||||||
| Ransomware | headwaterco.com id16897 View details | United States | Other | — | ||
|
headwaterco.com |
||||||
| Ransomware | headwaterco.com id33134 View details | United States | Other | — | ||
|
headwaterco.com operates within the IT sector based in the United States, providing technology-focused services and solutions for enterprise clients. The entity is cataloged in the threat-intelligence index as a ransomware victim, with its association specifically tied to the Babuk2 threat actor. This listing reflects the cybersecurity community's documented linkage between the organization and the Babuk2 malware campaign without disclosing unverified incident details. The classification underscores the importance of monitoring IT sector entities for evolving ransomware threats originating from identified actors. Authorities and security researchers continue to track such associations to enhance defensive strategies across vulnerable sectors. |
||||||
| Ransomware | headwaterco.com id33134 View details | United States | Other | — | ||
|
headwaterco.com |
||||||
| Ransomware | headwaterco.com id16897 View details | United States | Other | — | ||
|
headwaterco.com |
||||||
| Ransomware | www.al-shefafarm.ro id16896 View details | Romania | Agriculture / Food | — | ||
|
www.al-shefafarm.ro |
||||||
| Ransomware | www.al-shefafarm.ro id33135 View details | Romania | Agriculture / Food | — | ||
|
al-shefafarm.ro is a Romanian entity operating within the Agriculture and Food sector, identified in the threat-intelligence index as a ransomware victim. The domain name and operational context align with organizations serving food production and agricultural supply chains in Romania. Its inclusion reflects cybersecurity monitoring of ransomware activity affecting critical infrastructure-adjacent sectors, where operational disruption poses significant economic and societal impacts. The listing explicitly associates al-shefafarm.ro with the babuk2 threat actor, a known ransomware family targeting diverse industries globally. This entry provides neutral catalog information for defenders assessing threat exposure within agricultural and food-sector environments across Eastern Europe. |
||||||
| Ransomware | www.al-shefafarm.ro id33135 View details | Romania | Agriculture / Food | — | ||
|
www.al-shefafarm.ro |
||||||
| Ransomware | www.al-shefafarm.ro id16896 View details | Romania | Agriculture / Food | — | ||
|
www.al-shefafarm.ro |
||||||
| Ransomware | www.ykp.com.br id16895 View details | Brazil | Other | — | ||
|
www.ykp.com.br |
||||||
| Ransomware | www.ykp.com.br id33136 View details | Brazil | Other | — | ||
|
ypk.com.br operates as a Brazilian retail and e-commerce entity, providing online commerce services and digital marketplace functionality within the South American consumer sector. The domain is cataloged within this threat-intelligence index under the classification of ransomware victim, specifically associated with the threat actor babuk2. This listing reflects documented intelligence correlating the entity with activity attributable to babuk2, without disclosing unverified technical details or incident specifics. The entry serves cybersecurity stakeholders for tracking retail and e-commerce sector exposure to ransomware campaigns originating from identified sources in Brazil. Neutral documentation supports threat-aware monitoring and contextual understanding of cyber risk patterns across vulnerable commercial sectors. |
||||||
| Ransomware | www.ykp.com.br id33136 View details | Brazil | Other | — | ||
|
www.ykp.com.br |
||||||
| Ransomware | www.ykp.com.br id16895 View details | Brazil | Other | — | ||
|
www.ykp.com.br |
||||||
| Ransomware | www.go4kora.tv id16894 View details | Tuvalu | Other | — | ||
|
www.go4kora.tv |
||||||
| Ransomware | www.go4kora.tv id33137 View details | Tuvalu | Other | — | ||
|
go4kora.tv operates within the IT sector and is situated in the country TV. The entity is cataloged within this threat-intelligence index as a ransomware victim linked to the threat actor babuk2. This listing type identifies organizations impacted by ransomware activity, providing context for security researchers and defenders monitoring cyber threats. The description reflects the entity's classification and associated threat actor without speculating on unconfirmed incident details such as data exfiltration scope, ransom demands, or specific breach mechanisms. Understanding such victim profiles supports proactive threat mitigation and sector-specific defense strategies. |
||||||
| Ransomware | www.go4kora.tv id33137 View details | Tuvalu | Other | — | ||
|
www.go4kora.tv |
||||||
| Ransomware | www.go4kora.tv id16894 View details | Tuvalu | Other | — | ||
|
www.go4kora.tv |
||||||
| Ransomware | www.rekamy.com id16893 View details | Malaysia | Other | — | ||
|
www.rekamy.com |
||||||
| Ransomware | www.rekamy.com id33138 View details | Malaysia | Other | — | ||
|
rekamy.com operates within the IT sector and is situated in Malaysia. The entity functions as a technology services provider, offering digital solutions and infrastructure relevant to enterprise information systems. Within threat intelligence frameworks, rekamy.com is cataloged as a ransomware victim linked to the threat actor babuk2. This classification reflects its inclusion in cybersecurity databases documenting adversary activity and affected organizational profiles. The listing provides context for analysts tracking cyber incidents across sectors and geographies, emphasizing factual association without disclosing unverified incident details. |
||||||
| Ransomware | www.rekamy.com id33138 View details | Malaysia | Other | — | ||
|
www.rekamy.com |
||||||
| Ransomware | www.rekamy.com id16893 View details | Malaysia | Other | — | ||
|
www.rekamy.com |
||||||
| Ransomware | www.dvttechnologyltd.com id16892 View details | United States | IT | — | ||
|
www.dvttechnologyltd.com |
||||||
| Ransomware | www.dvttechnologyltd.com id33139 View details | United States | IT | — | ||
|
dvttechnologyltd.com operates within the IT sector and serves technology-focused clients, providing digital solutions and services aligned with enterprise infrastructure needs. The entity is identified in threat-intelligence indexing as a ransomware victim linked to the Babuk2 threat actor. Babuk2 is a known malware family associated with ransomware activity targeting organizations globally. This listing reflects the entity's documented association with this threat actor within the ransomware victim classification. No specific incident details, such as breach confirmation or data loss metrics, are asserted here; the record solely documents the association. |
||||||
| Ransomware | www.dvttechnologyltd.com id33139 View details | United States | IT | — | ||
|
www.dvttechnologyltd.com |
||||||
| Ransomware | www.dvttechnologyltd.com id16892 View details | United States | IT | — | ||
|
www.dvttechnologyltd.com |
||||||
| Ransomware | www.siea.sk id16891 View details | Slovakia | Other | — | ||
|
www.siea.sk |
||||||
| Ransomware | www.siea.sk id33140 View details | Slovakia | Other | — | ||
|
siea.sk is an entity operating within the finance, legal, and insurance sectors, situated in Slovakia. Its domain serves as a reference point within threat-intelligence indexing, documenting organizational context relevant to cybersecurity analysis. The listing categorizes siea.sk specifically as a ransomware victim, with an associated threat actor identified as babuk2. This designation reflects the entity's inclusion in intelligence records correlating operational sectors with active cyber threats. The description remains factual and neutral, focusing on sector classification, geographic location, and the verified association with babuk2 without elaborating on unconfirmed incident details or speculative outcomes. |
||||||
| Ransomware | www.siea.sk id33140 View details | Slovakia | Other | — | ||
|
www.siea.sk |
||||||
| Ransomware | www.siea.sk id16891 View details | Slovakia | Other | — | ||
|
www.siea.sk |
||||||
| Ransomware | www.spmundi.com.br id16890 View details | Brazil | Other | — | ||
|
www.spmundi.com.br |
||||||
| Ransomware | www.spmundi.com.br id33141 View details | Brazil | Other | — | ||
|
spmundi.com.br operates within the retail and e-commerce sector, based in Brazil. The entity provides online commerce services and manages digital retail operations within its regional market. This listing identifies spmundi.com.br as a ransomware victim associated with the threat actor babuk2. The classification reflects the cybersecurity event documented in the threat-intelligence index, contextualizing the entity's exposure within retail and e-commerce environments vulnerable to advanced persistent threats. This entry serves as a reference point for monitoring threat actor activity and sector-specific security implications. |
||||||
| Ransomware | www.spmundi.com.br id33141 View details | Brazil | Other | — | ||
|
www.spmundi.com.br |
||||||
| Ransomware | www.spmundi.com.br id16890 View details | Brazil | Other | — | ||
|
www.spmundi.com.br |
||||||
| Ransomware | www.merchant.id id16889 View details | Indonesia | Other | — | ||
|
www.merchant.id |
||||||
| Ransomware | www.merchant.id id33142 View details | Indonesia | Other | — | ||
|
merchant.id represents an entity operating within the merchant sector, based in Indonesia. Its role within the threat-intelligence index is specifically categorized as a ransomware victim. This designation reflects its association with the threat actor babuk2, a known malware family associated with ransomware campaigns targeting commercial systems. The listing type documents the entity's exposure within cybersecurity threat datasets, providing context for defenders assessing regional and actor-specific risks. No specific incident details such as data stolen, ransom demands, or breach confirmation are included per analytical constraints. |
||||||
| Ransomware | www.merchant.id id33142 View details | Indonesia | Other | — | ||
|
www.merchant.id |
||||||
| Ransomware | www.merchant.id id16889 View details | Indonesia | Other | — | ||
|
www.merchant.id |
||||||
| Ransomware | www.cyncsolutions.com id16888 View details | United States | Services | — | ||
|
www.cyncsolutions.com |
||||||
| Ransomware | www.cyncsolutions.com id33143 View details | United States | Services | — | ||
|
cync solutions com operates within the IT sector and provides technology-focused services and solutions for clients requiring infrastructure, systems management, or digital service support. As documented in the threat-intelligence index, the entity is categorized as a ransomware victim linked to the babuk2 threat actor and originates from the United States. This classification reflects its inclusion within cybersecurity monitoring frameworks where ransomware incidents are cataloged by affected organization, sector, geographic origin, and associated malicious actor profile. The listing serves to inform defenders, compliance teams, and intelligence analysts about a known ransomware victim connection tied to babuk2 activity in the IT sector. No additional incident specifics, such as confirmed data theft, ransom details, or breach scope, are stated here per strict factual boundaries. |
||||||
| Ransomware | www.cyncsolutions.com id33143 View details | United States | Services | — | ||
|
www.cyncsolutions.com |
||||||
| Ransomware | www.cyncsolutions.com id16888 View details | United States | Services | — | ||
|
www.cyncsolutions.com |
||||||
| Ransomware | Baca County Feedyard, Inc id16887 View details | United States | Public Sector | — | ||
|
Baca County Feedyard, Inc |
||||||
| Ransomware | Baca County Feedyard, Inc id33144 View details | United States | Public Sector | — | ||
|
bacacountyco.gov represents a public sector entity located in the United States, operating within government or public administration services. The domain serves as an official government resource, providing public services and administrative functions for the county. This listing identifies bacacountyco.gov as a ransomware victim linked to the Babuk2 threat actor, reflecting a cybersecurity incident within the public sector domain. The entry documents the association without disclosing unconfirmed breach details, maintaining strict adherence to factual threat-intelligence reporting standards. This catalog description supports comprehensive threat monitoring and sector-specific risk assessment for cybersecurity professionals. |
||||||
| Ransomware | Baca County Feedyard, Inc id33144 View details | United States | Public Sector | — | ||
|
Baca County Feedyard, Inc |
||||||
| Ransomware | Baca County Feedyard, Inc id16887 View details | United States | Public Sector | — | ||
|
Baca County Feedyard, Inc |
||||||
| Ransomware | www.skywaycoach.ca id16886 View details | Canada | Other | — | ||
|
www.skywaycoach.ca |
||||||
| Ransomware | www.skywaycoach.ca id33145 View details | Canada | Other | — | ||
|
skywaycoach.ca operates within the Canadian transportation, travel, and logistics sector, providing coaching and mobility-related services to customers and stakeholders. As a ransomware victim indexed in this threat-intelligence catalog, the entity is associated with the threat actor babuk2. This listing type documents the cybersecurity event classification without disclosing unverified technical details such as stolen data, ransom terms, or confirmed breach specifics. The entry serves as a neutral reference point for threat analysts monitoring ransomware activity across transportation and travel infrastructure in Canada. It underscores the vulnerability of logistics-focused organizations to cyber threats and supports contextual awareness within cybersecurity intelligence frameworks. |
||||||
| Ransomware | www.skywaycoach.ca id33145 View details | Canada | Other | — | ||
|
www.skywaycoach.ca |
||||||
| Ransomware | www.skywaycoach.ca id16886 View details | Canada | Other | — | ||
|
www.skywaycoach.ca |
||||||
| Ransomware | www.farmaciaflorio.com id16885 View details | Italy | Agriculture / Food | — | ||
|
www.farmaciaflorio.com |
||||||
| Ransomware | www.farmaciaflorio.com id33146 View details | Italy | Agriculture / Food | — | ||
|
farmacaflorio.com operates within the Healthcare and Pharma sector, serving the IT domain with services likely focused on medical supply, patient management, or pharmaceutical distribution. The entity is cataloged as a ransomware victim linked to the threat actor babuk2, a known malware family associated with disruptive cyber incidents targeting critical infrastructure. This listing reflects the threat intelligence index's documentation of the attack context without disclosing unverified details such as data stolen, ransom demands, or precise breach timelines. The inclusion underscores the vulnerability of healthcare and pharma organizations within the IT sector to ransomware campaigns driven by actors like babuk2. Neutral reporting ensures clarity for analysts assessing risk patterns and defensive priorities. |
||||||
| Ransomware | www.farmaciaflorio.com id33146 View details | Italy | Agriculture / Food | — | ||
|
www.farmaciaflorio.com |
||||||
| Ransomware | www.farmaciaflorio.com id16885 View details | Italy | Agriculture / Food | — | ||
|
www.farmaciaflorio.com |
||||||
| Ransomware | www.nrshealthcare.com id16884 View details | United Kingdom | Healthcare / Pharma | — | ||
|
www.nrshealthcare.com |
||||||
| Ransomware | www.nrshealthcare.com id33147 View details | United Kingdom | Healthcare / Pharma | — | ||
|
nrshealthcare.com operates within the healthcare and medicine sector based in the United Kingdom. The entity represents a healthcare organization whose infrastructure was identified within a threat-intelligence index under the classification ransomware victim. The association links the listing to babuk2, a threat actor known for deploying ransomware campaigns targeting critical sectors including healthcare. This entry documents the relationship between the organization, its sector context, and the specific threat actor without disclosing unverified incident details. It neutrally records that nrshealthcare.com was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | www.nrshealthcare.com id33147 View details | United Kingdom | Healthcare / Pharma | — | ||
|
www.nrshealthcare.com |
||||||
| Ransomware | www.nrshealthcare.com id16884 View details | United Kingdom | Healthcare / Pharma | — | ||
|
www.nrshealthcare.com |
||||||