Bjorka is a cybercriminal persona linked in reporting to ransomware ecosystem activity around Babuk2 and to associations with FSociety and Skywave. Available reporting does not establish Bjorka as a clearly defined standalone intrusion set with independently validated operations, infrastructure, or victimology. Instead, the name appears in connection with personas tied to deceptive or low-confidence ransomware branding activity, particularly Babuk2, which has been assessed as a likely deception or reposting operation rather than a validated ransomware actor. High-confidence reporting links Bjorka by association to ransomware-related extortion branding, but does not provide sufficient corroborated evidence to attribute a distinct malware family, stable organizational structure, country of origin, or consistent targeting profile directly to Bjorka. Based on the available facts, Bjorka is best characterized as an alias associated with cybercriminal and ransomware-adjacent activity rather than a fully attributed threat actor cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a threat actor linked to Babuk2; Babuk2 reposted previous Bjorka victims and displayed Bjorka branding on its leak site.
Referenced as a linked hacktivist persona associated with individuals operating Babuk 2 and connected to FunkSec’s ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.