Ransomware Group intelligence
Babuk2
InactiveTrack Babuk2 with 741 published victims and 4 known leak locations in a single intelligence view.
Overview
Babuk2 is tracked by Dark Eye as a ransomware group with 741 published victims.
United States is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Leak Status Distribution
No leak-status data available yet.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Web location | Down checked 2h ago | 212.24.99.211. |
| Leak location 4 | Web location | Down checked 2h ago | 5g2e.l.time4vps.cloud |
| Leak location 2 | Onion service | Down checked 2h ago | bxwu33iefqfc3rxigynn3ghvq4gdw3gxgxna5m4aa3o4vscdeeqhiqad.onion |
| Leak location 1 | Onion service | Down checked 2h ago | 7dikawx73goypgfi4zyo5fcajxwb7agemmiwqax3p54aey4dwobcvcyd.onion |
Top Activity Sectors (17)
- Not identified 102
- Services 17
- Public Sector 13
- Communication / Marketing 10
- Healthcare / Pharma 9
- Finance / Legal / Insurance 9
- Retail / E-commerce 6
- Manufacturing / Engineering 5
- IT 5
- Construction / Real Estate 3
- Agriculture / Food 3
- Telecommunications 3
- Education 3
- Energy 2
- Transportation / Travel / Logistics 2
- NGOs / Associations 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (12)
▼MITRE ATT&CK does not currently catalogue Babuk2, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: babuk2 uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: babuk2 modifies Windows Registry Run keys to ensure ransomware execution upon system reboot for persistence.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: babuk2 leverages registry run keys and startup folders to maintain persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: babuk2 disables security tools like antivirus software and monitoring agents to evade detection during infection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: babuk2 manipulates boot sequence via Safe Mode Boot techniques to bypass initial security checks during execution.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: babuk2 encrypts and encodes victim files with custom ransomware keys to ensure irreversible data access denial.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: babuk2 deletes Volume Shadow Copies and backup files via system commands to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: babuk2 discovers remote systems via network scanning to expand foothold across victim networks.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: babuk2 performs network share discovery to identify accessible SMB shares for lateral movement and victim targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: babuk2 uses SMB/Windows Admin Shares for lateral movement between compromised hosts within the network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: babuk2 encrypts victim files using strong symmetric encryption to maximize impact and trigger ransom demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: babuk2 calls system recovery inhibitors like shutdown scripts to prevent victim systems from restoring functionality.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (741)
Search, filter and paginate the victim timeline for Babuk2. Showing 701–741 of 741.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | www.hcisystems.net id16883 View details | United States | Services | — | ||
|
www.hcisystems.net |
||||||
| Ransomware | www.hcisystems.net id33148 View details | United States | Services | — | ||
|
hcisystems.net operates within the IT sector and is situated in the United States. The entity is cataloged within this threat-intelligence index under the designation ransomware victim, specifically linked to the threat actor babuk2. The listing reflects observed intelligence correlating this organization with the ransomware campaign attributed to babuk2, without disclosing confirmed breach details. This entry serves as a structured reference for security professionals monitoring IT infrastructure threats and associated adversary activity. The record emphasizes the neutral association between hcisystems.net and babuk2 within the ransomware victim classification. |
||||||
| Ransomware | www.hcisystems.net id33148 View details | United States | Services | — | ||
|
www.hcisystems.net |
||||||
| Ransomware | www.hcisystems.net id16883 View details | United States | Services | — | ||
|
www.hcisystems.net |
||||||
| Ransomware | www.betteraccountingsolutions.com id16882 View details | United States | Finance / Legal / Insurance | — | ||
|
www.betteraccountingsolutions.com |
||||||
| Ransomware | www.betteraccountingsolutions.com id33149 View details | United States | Finance / Legal / Insurance | — | ||
|
betteraccountingsolutions.com operates within the Finance, Legal, and Insurance sectors based in the United States, providing accounting and compliance-focused solutions for organizations requiring robust financial oversight and regulatory adherence. The entity was officially listed as a ransomware victim associated with the babuk2 threat actor. This classification reflects the cybersecurity threat landscape where ransomware campaigns target critical sectors, disrupting operations and demanding attention from security and compliance professionals. The listing underscores the importance of vigilance and proactive defense within finance, legal, and insurance industries against evolving cyber threats. |
||||||
| Ransomware | www.betteraccountingsolutions.com id33149 View details | United States | Finance / Legal / Insurance | — | ||
|
www.betteraccountingsolutions.com |
||||||
| Ransomware | www.betteraccountingsolutions.com id16882 View details | United States | Finance / Legal / Insurance | — | ||
|
www.betteraccountingsolutions.com |
||||||
| Ransomware | www.aretusamilano.it id16881 View details | Italy | Other | — | ||
|
www.aretusamilano.it |
||||||
| Ransomware | www.aretusamilano.it id33150 View details | Italy | Other | — | ||
|
aretusamilano.it operates within the IT Services sector and serves clients requiring technology and service-oriented solutions based on its domain classification and sector metadata. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim. Its association with the threat actor babuk2 identifies a cybersecurity event linked to this specific malware campaign. No further incident details, such as data stolen, ransom demands, or confirmed breach specifics, are included to maintain factual neutrality and avoid speculation. This entry provides objective context for researchers and defenders monitoring ransomware activity in the Services sector. |
||||||
| Ransomware | www.aretusamilano.it id33150 View details | Italy | Other | — | ||
|
www.aretusamilano.it |
||||||
| Ransomware | www.aretusamilano.it id16881 View details | Italy | Other | — | ||
|
www.aretusamilano.it |
||||||
| Ransomware | www.agenciahost.com id16880 View details | Brazil | Other | — | ||
|
www.agenciahost.com |
||||||
| Ransomware | www.agenciahost.com id33151 View details | Brazil | Other | — | ||
|
agenciahost.com operates within the IT sector and is situated in Brazil. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor and source identified as babuk2. The entry documents the relationship between the organization and the malware campaign without disclosing unverified incident details such as data stolen, records accessed, ransom demands, or confirmed breach specifics. This description maintains an authoritative and neutral perspective for catalog purposes. agenciahost.com was listed as a ransomware victim associated with babuk2. |
||||||
| Ransomware | www.agenciahost.com id33151 View details | Brazil | Other | — | ||
|
www.agenciahost.com |
||||||
| Ransomware | www.agenciahost.com id16880 View details | Brazil | Other | — | ||
|
www.agenciahost.com |
||||||
| Ransomware | www.constelacion.com.sv id16879 View details | El Salvador | Other | — | ||
|
www.constelacion.com.sv |
||||||
| Ransomware | www.constelacion.com.sv id33152 View details | El Salvador | Other | — | ||
|
constelacion.com.sv operates within the Services sector and is headquartered in Slovakia (SV). The entity provides professional services aligned with its sector classification, though specific operational details remain limited to verified threat-intelligence records. It is formally cataloged as a ransomware victim linked to the threat actor babuk2, indicating a cybersecurity incident where this organization was targeted by this specific malware campaign. This listing serves to document the association for threat-intelligence analysis and industry awareness without disclosing unverified incident details. The entry reflects confirmed linkages within the threat-intelligence index rather than speculative claims. |
||||||
| Ransomware | www.constelacion.com.sv id33152 View details | El Salvador | Other | — | ||
|
www.constelacion.com.sv |
||||||
| Ransomware | www.constelacion.com.sv id16879 View details | El Salvador | Other | — | ||
|
www.constelacion.com.sv |
||||||
| Ransomware | www.avantit.no id16878 View details | Norway | Other | — | ||
|
www.avantit.no |
||||||
| Ransomware | www.avantit.no id33153 View details | Norway | Other | — | ||
|
avantit.no operates within the IT sector and is situated in Norway. The entity functions as a technology-focused organization providing digital solutions and services relevant to its sector. It has been documented in threat intelligence resources as a ransomware victim linked to the babuk2 threat actor group. This listing reflects its association with this specific cyber threat within the broader ransomware landscape. The description remains factual and neutral, focusing solely on the entity's categorization and its verified connection to babuk2 without elaborating on unconfirmed incident details. |
||||||
| Ransomware | www.avantit.no id33153 View details | Norway | Other | — | ||
|
www.avantit.no |
||||||
| Ransomware | www.avantit.no id16878 View details | Norway | Other | — | ||
|
www.avantit.no |
||||||
| Ransomware | www.industrialdealimentos.com id16877 View details | Colombia | Manufacturing / Engineering | — | ||
|
www.industrialdealimentos.com |
||||||
| Ransomware | www.industrialdealimentos.com id33154 View details | Colombia | Manufacturing / Engineering | — | ||
|
industrialdealimentos.com operates within the retail and e-commerce sector, with its operational presence linked to Colombia. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, specifically associated with the threat actor babuk2. This designation reflects the cybersecurity event documented within the index, contextualized by the company's sector and geographic location. The description remains factual and neutral, focusing on the verified association without elaborating on unconfirmed technical or operational details of the incident. |
||||||
| Ransomware | www.industrialdealimentos.com id33154 View details | Colombia | Manufacturing / Engineering | — | ||
|
www.industrialdealimentos.com |
||||||
| Ransomware | www.industrialdealimentos.com id16877 View details | Colombia | Manufacturing / Engineering | — | ||
|
www.industrialdealimentos.com |
||||||
| Ransomware | www.lapastina.com id16876 View details | Brazil | Other | — | ||
|
www.lapastina.com |
||||||
| Ransomware | www.lapastina.com id33155 View details | Brazil | Other | — | ||
|
lapastina.com operates within the IT sector and is located in Brazil. The entity is cataloged in this threat-intelligence index as a ransomware victim linked to the threat actor babuk2. This listing type indicates that the organization was impacted by ransomware activity associated with babuk2, without disclosing specific technical details, stolen data categories, record counts, ransom amounts, or confirmed breach specifics. The entry provides neutral context for threat researchers, security teams, and cyber-intelligence consumers seeking to understand the entity's classification within the babuk2-related incident landscape. |
||||||
| Ransomware | www.lapastina.com id33155 View details | Brazil | Other | — | ||
|
www.lapastina.com |
||||||
| Ransomware | www.lapastina.com id16876 View details | Brazil | Other | — | ||
|
www.lapastina.com |
||||||
| Ransomware | www.kovra.com.my id16875 View details | Malaysia | Other | — | ||
|
www.kovra.com.my |
||||||
| Ransomware | www.kovra.com.my id33156 View details | Malaysia | Other | — | ||
|
kovra.com.my operates within the Services sector and is based in Malaysia (MY), providing services aligned with its domain identity. It has been documented within this threat-intelligence index under the classification of ransomware victim. The association links the entity to babuk2, a threat actor known for deploying ransomware campaigns across targeted sectors. This listing reflects verified intelligence linking the domain and organization to the specified threat actor without disclosing unconfirmed incident details. The record serves as a reference point for security teams monitoring ransomware exposure in the Services industry within Southeast Asia. |
||||||
| Ransomware | www.kovra.com.my id33156 View details | Malaysia | Other | — | ||
|
www.kovra.com.my |
||||||
| Ransomware | www.kovra.com.my id16875 View details | Malaysia | Other | — | ||
|
www.kovra.com.my |
||||||
| Ransomware | www.computan.com id16874 View details | Canada | Other | — | ||
|
www.computan.com |
||||||
| Ransomware | www.computan.com id33157 View details | Canada | Other | — | ||
|
computan.com is an IT sector company based in Canada, providing technology services and solutions for clients within the information technology domain. The entity is formally listed within the threat-intelligence index under the designation ransomware victim, with an associated threat actor identified as babuk2. This listing reflects the cybersecurity intelligence assessment connecting computan.com to the babuk2 campaign without disclosing specific technical breach details. The catalog entry serves to document the relationship between the organization, its sector classification, and the attributed threat actor for analytical and defensive purposes. |
||||||
| Ransomware | www.computan.com id33157 View details | Canada | Other | — | ||
|
www.computan.com |
||||||
| Ransomware | www.computan.com id16874 View details | Canada | Other | — | ||
|
www.computan.com |
||||||
| Ransomware | www.scadea.com id16873 View details | United States | Other | — | ||
|
www.scadea.com |
||||||