Bjorka is a threat actor/persona referenced in reporting on the Q1 2025 ransomware landscape. Dragos states that personas linked to FSociety and Bjorka were associated with FunkSec and referenced in connection with Babuk2 ransomware. Dragos also notes associations between FunkSec and personas linked to FSociety and Bjorka, and mentions individuals linked to FSociety and Bjorka as operating Babuk2 ransomware. Based on the provided content, Bjorka is linked by reporting to the ransomware ecosystem around FunkSec and Babuk2, but the available information does not establish a standalone malware family, distinct operational profile, specific victimology, or confirmed nation-state attribution. Known alias in the provided content: Bjorka.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a threat actor linked to Babuk2; Babuk2 reposted previous Bjorka victims and displayed Bjorka branding on its leak site.
Referenced as a linked hacktivist persona associated with individuals operating Babuk 2 and connected to FunkSec’s ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.