Investigative reporting identified the cybercrime forum user "Babam" as a prolific network access broker who sold stolen corporate remote-access credentials, particularly VPN and Citrix access, to other criminals including ransomware affiliates. The profile drew on leaked forum data, breached-account records, historical WHOIS information, and username and email pivots that tied the actor to the address operns@gmail.com, the alias "bo3dom", and a broader set of related accounts and domains.
The evidence suggests Babam moved from typosquatting and cybercrime-adjacent domain activity into carding by 2015 and later into brokering enterprise access by 2020. Reporting also cited an assessment that one access sale advertised by Babam in April 2021 likely involved Bureau Veritas, which later disclosed a cyber incident and shut down parts of its network, while linguistic clues in the actor's Russian-language posts indicated Russian may be a second language and pointed to a possible origin in Lithuania or another former Soviet state.

TTPs, infrastructure, and targeting history in one profile.
12 events from the most recent confirmed update back to the earliest known activity.
Bureau Veritas later disclosed a cyber incident and network shutdown in November 2021 after the access sale that Flashpoint linked to the company.
Flashpoint assessed that one Babam access sale in April 2021 likely involved Bureau Veritas, linking the broker's offering to a later disclosed victim.
Since the beginning of 2020, Babam created numerous auctions on Exploit, mainly selling stolen VPN credentials from companies.
The reporting assesses that by 2020 Babam had shifted primarily to brokering stolen corporate network access rather than earlier domain and carding activity.
A reverse WHOIS search found that operns@gmail.com was used to register sanjulianhotels.com in 2017, extending the chain of domains tied to Babam-linked identifiers.
In early 2017, Babam told another Verified user in a private message that he was from Lithuania, a detail cited in the attribution analysis.
Babam joined the Russian-language cybercrime forum Verified in February 2016, registering the account with the email address operns@gmail.com according to leaked forum data.
Constella Intelligence found that operns@gmail.com was used in 2016 to register an account at the Lithuanian-language movie streaming service filmai.in, where the associated username was bo3dom.
Babam joined the Russian-language cybercrime forum Exploit in 2015 and later authored more than 270 posts there.
The reporting assesses that by 2015 the actor's activity had moved heavily into carding before later transitioning toward brokering corporate network access.
A Lithuanian company directory report said Palvisa was established in 2011 by Vytautaus Mockus using the phone number 86.7273687 and the email address bo3dom@gmail.com, identifiers linked in the reporting to Babam-related accounts.
A reverse WHOIS search found that operns@gmail.com was used to register bonnjoeder.com in 2011, one of the earliest domain registrations linked in the reporting to the actor later profiled as Babam.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.