Babuk2 is a ransomware-branded extortion operation first observed in early 2025 that is widely assessed as unaffiliated with the original Babuk group despite adopting its name. The actor is primarily associated with deceptive leak-site activity, including publishing large numbers of unsubstantiated victim claims and reposting or recycling prior leak material to create the appearance of scale and credibility. Multiple assessments characterize Babuk2 as a deception-focused or social-engineering-driven operation rather than a validated, mature ransomware crew with consistently confirmed intrusions. Babuk2 has been linked to encryption-less extortion behavior and deceptive extortion tactics, with victim listings used to generate visibility and perceived momentum. Reporting indicates that some initially dubious victim claims were later followed by confirmed disclosures, but the group’s overall reputation remains centered on inflated or unverifiable claims. In ransomware ecosystem tracking for Q1 2025, Babuk2 was counted among active leak-site operators and was observed claiming dozens of incidents, though those claims were not validated at scale. The operation should be understood as distinct from the historic Babuk ransomware lineage. High-confidence reporting does not establish a confirmed country of origin, operator identity, or stable organizational structure. Its observed behavior aligns more with extortion, reputation-building, and affiliate attraction through spoofed or recycled victim exposure than with clearly demonstrated end-to-end ransomware tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prior ransomware group that initially published unsubstantiated/fake victim lists, then later disclosed confirmed victims as it matured and attracted affiliates.
Apparent deception/masquerade operation claiming many victims; linked to Bjorka and Skywave; observed reposting prior victims from other ransomware groups and using LockBit 3.0 as a purported sample; may be primarily social-engineering/deception rather than conducting real ransomware intrusions.
Actor associated with deceptive extortion and encryption-less extortion; also referenced as operated by individuals linked to Bjorka/FSociety in the FunkSec context.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.