Babuk-Bjorka is a ransomware threat actor tracked as active in 2025 and reported to have ceased or paused operations in April 2025. It was part of the broader ransomware ecosystem that continued to generate rising victim counts despite repeated law-enforcement disruption of prominent groups. Available reporting directly supports only limited attribution and operational detail for this actor. Babuk-Bjorka is identified as a ransomware operation, which implies extortion activity centered on ransomware deployment, but high-confidence specifics about its malware lineage, victimology, geographic focus, affiliate structure, or distinctive tradecraft are not currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Babuk-Bjorka was a ransomware group that became inactive in 2025.
Ransomware/extortion group referenced as having disappeared/paused operations.
Ransomware group reported as having disappeared/paused operations (April).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.