Babuk2 is a ransomware-branded operation first observed in January 2025. Available reporting indicates it is not affiliated with the original Babuk group and is widely assessed as a deceptive or reposting operation rather than a validated, fully evidenced ransomware actor. Optiv reported that Babuk2 listed at least 85 victims in Q1 2025 without validation and appeared to repost prior leak posts as a deception-based social engineering strategy. Dragos similarly described Babuk Locker/Babuk 2 as using deceptive extortion tactics involving unsubstantiated breach claims and recycled or falsified leaks, and advised careful validation of intelligence related to its claims. Dragos recorded Babuk 2 among ransomware groups claiming industrial-sector victims in Q1 2025, with 29 incidents attributed in its reporting. The content also notes references linking Babuk2 to personas associated with FSociety and Bjorka. High-confidence behavior described in the sources centers on extortion and leak-site claim inflation through recycled or falsified victim data, rather than confirmed malware deployment, encryption behavior, or specific technical infection vectors. No specific indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Another new ransomware operation... was Babuk2. Babuk2 was first observed in January 2025."
"Another new ransomware operation... was Babuk2. Babuk2 was first observed in January 2025."
"Another new ransomware operation... was Babuk2. Babuk2 was first observed in January 2025."
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operation using the Babuk name without affiliation to the original Babuk; content suggests it may be largely deception/reposting of other groups’ leak posts rather than conducting validated intrusions, and a circulated sample was reportedly LockBit 3.0.
Ransomware associated in the report with deceptive/extortion-focused activity and unverified breach claims complicating victim verification.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.