Babuk2 is a ransomware-branded extortion operation first observed in January 2025. It is not affiliated with the original Babuk ransomware group despite adopting a similar name. Babuk2 operated a dedicated leak site and rapidly listed numerous alleged victims, including organizations in the healthcare sector. Its victim claims were widely unsubstantiated and appear in part to have reused or reposted material from prior leak-site posts. The operation is associated with deceptive, encryption-less extortion activity rather than a validated conventional ransomware intrusion capability. Its use of inflated or unverified victim claims appears intended to generate visibility and credibility within the ransomware ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with healthcare-sector dedicated leak-site postings.
Referenced as a prior ransomware group that initially published unsubstantiated/fake victim lists, then later disclosed confirmed victims as it matured and attracted affiliates.
Apparent deception/masquerade operation claiming many victims; linked to Bjorka and Skywave; observed reposting prior victims from other ransomware groups and using LockBit 3.0 as a purported sample; may be primarily social-engineering/deception rather than conducting real ransomware intrusions.
Actor associated with deceptive extortion and encryption-less extortion; also referenced as operated by individuals linked to Bjorka/FSociety in the FunkSec context.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.