Femwar02 is a reportedly pro-Russian cybercrime threat actor publicly linked to a ransomware attack against Sapienza University of Rome in February 2026. The group appears to have been previously unknown before that incident, and available reporting ties it to deployment of BabLock, also referred to as Rorschach, a ransomware family noted for rapid encryption and code lineage associated with Babuk, LockBit v2.0, and DarkSide components. In the Sapienza intrusion, the actor was associated with disruption of university IT operations and encryption of data, with recovery efforts reportedly relying on unaffected backups. Public reporting also associated the operation with a ransom demand mechanism involving a countdown timer, consistent with extortion-oriented ransomware tradecraft. Based on currently available high-confidence information, Femwar02 should be characterized as an emerging ransomware actor with suspected Russian alignment or origin, but public attribution remains limited and the group’s broader victimology, structure, and operational history are not yet well established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Alleged new cybercrime/ransomware actor linked by Italian media to the ransomware attack that forced Rome’s La Sapienza University to shut down IT infrastructure to contain spread and restore operations.
Reportedly conducted a ransomware attack against La Sapienza University in Rome, causing major IT disruption and encrypting data; the operation is described as pro-Russian and used a ransomware strain similar to Bablock/Rorschach (noted for rapid encryption).
Alleged ransomware attack against La Sapienza University (Rome), with operators reportedly sending a ransom-demand link featuring a 72-hour countdown that starts upon link click.
Allegedly conducted a ransomware attack against Sapienza University of Rome, encrypting data and causing operational disruption; reporting notes malware characteristics/operational patterns similar to Bablock/Rorschach ransomware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.