babuk-bjorka
0 incidentes
0 paises
0 sectores
ransomware ID Ultimo: -
Aliases: Babuk2, SkyWave, Bjorka
Babuk-Bjorka, also known as Babuk2, emerged in January 2025 as a distinct ransomware and data extortion group that leverages the brand recognition of the original, largely defunct Babuk ransomware operation. This group, associated with operators like "Bjorka" and "Skywave," is assessed with high confidence to be linked to an Indonesian origin, based on the arrest of an individual claiming to be Bjorka. Its primary motivation is financial gain through double extortion, though it notably achieves this by largely recycling previously leaked victim data from other groups, such as LockBit 3.0, and rebranding other ransomware strains rather than conducting new, legitimate network intrusions. This practice of brand hijacking and re-extortion, often without actual new compromises, is a defining characteristic that sets it apart from traditional ransomware actors, whose claims of victimology are often questionable.
Paises objetivo (SOCRadar)
United Arab Emirates
Australia
Brazil
Canada
China
Colombia
Germany
Spain
France
United Kingdom
Sectores objetivo (SOCRadar)
Construction of BuildingsOther Information ServicesSoftware PublishersReal EstateHospitalsAccommodationAir TransportationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing