Uptime Hamster: 10d 12h 50mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza babuk-bjorka

babuk-bjorka

0 incidentes 0 paises 0 sectores ransomware ID Ultimo: -
Aliases: Babuk2, SkyWave, Bjorka
Ver en IntelTracker → APTTrail →
Babuk-Bjorka, also known as Babuk2, emerged in January 2025 as a distinct ransomware and data extortion group that leverages the brand recognition of the original, largely defunct Babuk ransomware operation. This group, associated with operators like "Bjorka" and "Skywave," is assessed with high confidence to be linked to an Indonesian origin, based on the arrest of an individual claiming to be Bjorka. Its primary motivation is financial gain through double extortion, though it notably achieves this by largely recycling previously leaked victim data from other groups, such as LockBit 3.0, and rebranding other ransomware strains rather than conducting new, legitimate network intrusions. This practice of brand hijacking and re-extortion, often without actual new compromises, is a defining characteristic that sets it apart from traditional ransomware actors, whose claims of victimology are often questionable.

Aliases del actor

Babuk2SkyWaveBjorka

Actores similares

babuk2ransomware · 180Babukactor · 1babukransomware · 1 Babuk-Lockerransomware · 0
Tipo
ransomware
Pais origen
ID
Motivacion
-
Impacto
60
Actualizado
Sat, 20 Ju

Paises objetivo (SOCRadar)

United Arab EmiratesAustraliaBrazilCanadaChinaColombiaGermanySpainFranceUnited Kingdom

Sectores objetivo (SOCRadar)

Construction of BuildingsOther Information ServicesSoftware PublishersReal EstateHospitalsAccommodationAir TransportationManufacturingConstructionElectrical Equipment, Appliance, and Component Manufacturing