Ransomware Group intelligence

Babuk2

Inactive

Track Babuk2 with 193 published victims and 4 known leak locations in a single intelligence view.

Victims 193 Known published victims in this dataset
First discovered 2025-01-27 Earliest victim discovery date
Last discovered 2025-04-23 Latest victim discovery date
Inactive since 367 days Days since the latest known victim
Top country United States 33 victims
Known locations 4 Leak or negotiation infrastructure tracked

Overview

Babuk2 is tracked by Breach House as a ransomware group with 193 published victims.

United States is currently the most targeted country in this dataset.

4 known leak locations are currently associated with this group.

Top Countries

Interactive distribution based on the currently visible victims list.

Top Countries
Distribution

    Known Leak Locations (4)

    Label Type Availability Links
    Leak location 1 Onion service Unknown 7dikawx73goypgfi4zyo5fcajxwb7agemmiwqax3p54aey4dwobcvcyd.onion
    Leak location 2 Onion service Unknown bxwu33iefqfc3rxigynn3ghvq4gdw3gxgxna5m4aa3o4vscdeeqhiqad.onion
    Leak location 3 Web location Unknown 212.24.99.211.
    Leak location 4 Web location Unknown 5g2e.l.time4vps.cloud

    Top Activity Sectors

    No sector intelligence available.

    Research Sources

    No external research sources linked yet.

    Victims (193)

    Search, filter and paginate the victim timeline for Babuk2.

    Type Target Discovered Country Business Category Intel Link
    Ransomware tecnologias.mspz2.gob.ec id19320 View details Ecuador Other
    Ransomware turkish defense military id18945 View details Türkiye Other
    Ransomware rheinmetall.com (Rheinmetall Defence) id18944 View details Germany Manufacturing / Engineering
    Ransomware gangotreehomes.com (RealEstate) id18941 View details India NGOs / Associations
    Ransomware Secret plans of Indian army id18940 View details Other
    Ransomware Bangladesh Armed Forces (BangLadesh Army) id18939 View details Bangladesh Other
    Ransomware Saudi Arabian military and government internal center id18938 View details Saudi Arabia Public Sector
    Ransomware Hellenic Airforce id18937 View details Greece Other
    Ransomware ezbuy.sg (Singapore Shopping) id18934 View details Singapore Retail / E-commerce
    Ransomware Iran gas service system id18933 View details Iran, Islamic Republic of Energy
    Ransomware kfar hatta medical center - Lebanon id18932 View details Lebanon Healthcare / Pharma
    Ransomware Polizia italia mail access id18930 View details Italy Other
    Ransomware zalora.sg (Singapore Shopping) id18929 View details Singapore Retail / E-commerce
    Ransomware ascires.com id18920 View details Spain Other
    Ransomware aosense.com - AO Sense INC. id18919 View details United States Services
    Ransomware dardoc.com id18918 View details Denmark Other
    Ransomware navy-mil-bd id18916 View details Bangladesh Other
    Ransomware drdo.gov.in id18901 View details India Other
    Ransomware uniproof.com.br id18900 View details Brazil Communication / Marketing
    Ransomware (UPDATE) - whitecapcanada.com id18897 View details Canada Other
    Ransomware pln.co.id - PLN INDONESIA id18861 View details Indonesia Other
    Ransomware moh.gov.rw id18860 View details Rwanda Other
    Ransomware iDRAC (Integrated Dell Remote Access Controller) management interface for Dell servers id18795 View details United States Services
    Ransomware elsoms.com id18782 View details United Kingdom Other
    Ransomware brune.com.br - Group MC (conglomerate) id18781 View details Brazil Services
    Ransomware towellengineering.net id18780 View details Oman Manufacturing / Engineering
    Ransomware icvc.co - Instituto Cardiovascular del Cesar id18779 View details Colombia Other
    Ransomware modiin-ezrachi.co.il id18778 View details Israel Other
    Ransomware La Futura id18777 View details Other
    Ransomware Atlantic Coast Consulting Inc id18776 View details United States Services
    Ransomware theeyeclinicsurgicenter.com - The Eye Clinic Surgicenter company id18775 View details Healthcare / Pharma
    Ransomware 🚀 Launch Your Own Ransomware(RAAS) Business with Our Exclusive Ransomware Panel Source Cod... id18773 View details Services
    Ransomware leadzen.ai id18764 View details India Other
    Ransomware healthcasts.com id18763 View details United States Healthcare / Pharma
    Ransomware pureincubation.com id18762 View details United States Services
    Ransomware unired.uz id18759 View details Uzbekistan Other
    Ransomware nadra.gov.pk - NADRA official Of Pakistan Army & (Andhra Pradesh) id18739 View details Pakistan Communication / Marketing
    Ransomware nadra.gov.pk - NADRA official Of Pakistan Army id18738 View details Pakistan Other
    Ransomware heras.co.uk id18736 View details United Kingdom Other
    Ransomware alliedwoundcare.com id18735 View details United States Other
    Ransomware crimsgroup.com id18734 View details United States Services
    Ransomware aman-iraq.com id18733 View details Iraq Other
    Ransomware mot.gov.iq - Iraqi Ministry of Commerce (Of Trade) id18723 View details Iraq Retail / E-commerce
    Ransomware israel Infrastructure & Secret Documents intelligence information id18722 View details Israel Construction / Real Estate
    Ransomware kalesavunma.com - KALE SAVUNMA. id18708 View details Türkiye Other
    Ransomware airexplore.aero id18667 View details Slovakia Other
    Ransomware iberdrola.com (Spain energy) id18662 View details Spain Energy
    Ransomware Synesis Surveillance System id18604 View details Russian Federation Other
    Ransomware inmarsat.com id18603 View details United Kingdom Other
    Ransomware jp-property.com id18602 View details Japan Construction / Real Estate
    Ransomware armetal.com id18598 View details Saudi Arabia Manufacturing / Engineering
    Ransomware 🚀 DB Market – Buy & Sell Databases Safely! id18571 View details United States Retail / E-commerce
    Ransomware The Ticktin Law Group id18570 View details United States Finance / Legal / Insurance
    Ransomware Mpaj.gov.my id18569 View details Malaysia Other
    Ransomware exostar.com TOP Defense AS id18568 View details Other
    Ransomware Our Official telegram channel babuk Locker 2.0 id18567 View details United Kingdom Other
    Ransomware Standard Capital Securities (Pvt) Backoffice - Pakistan Stock Market Data Vault id18566 View details Pakistan Retail / E-commerce
    Ransomware mohrss.gov.cn ( Ministry of Human Resources and Social Security ) id18564 View details China Public Sector
    Ransomware amazon.com id18563 View details United States Other
    Ransomware fr.sodexo.com id18542 View details France Other
    Ransomware Corporate access, up to Shipping Apps in QATAR id18541 View details Qatar Transportation / Travel / Logistics
    Ransomware woqod.com id18540 View details Qatar Other
    Ransomware mof.go.th - Ministry of Finance (Thailand) id18539 View details Thailand Finance / Legal / Insurance
    Ransomware smic.mi.th (Thailand Intelligence Agency) id18534 View details Thailand Communication / Marketing
    Ransomware www.gob.ve id18532 View details Venezuela, Bolivarian Republic of Other
    Ransomware Access Panel Financial Technology Company (Thailand) id18531 View details Thailand IT
    Ransomware United States County Palm Beach Goverment id18530 View details United States Public Sector
    Ransomware Municipal taxation Secretariat Access - Brazil Goverment id18529 View details Brazil Public Sector
    Ransomware Intelligence Bureau of the Joint Staff Department of the Central Military Commission... id18528 View details China Public Sector
    Ransomware rac.gov.my id18527 View details Malaysia Other
    Ransomware nimapinfotech.com id18526 View details India IT
    Ransomware esaote.com id18503 View details Italy Other
    Ransomware nstda.or.th id18502 View details Thailand Other
    Ransomware kominfo.go.id id18501 View details Indonesia Other
    Ransomware pajak.go.id id18500 View details Indonesia Other
    Ransomware dukcapil.kemendagri.go.id (SIAK DUKCAPIL MINISTRY OF HOME AFFAIRS OF INDONESIA) id18499 View details Indonesia Agriculture / Food
    Ransomware whitecapcanada.com id18496 View details Canada Other
    Ransomware A Buyer Fake Actor BF id18495 View details Burkina Faso Other
    Ransomware hcahealthcare.com INC. id18491 View details United States Healthcare / Pharma
    Ransomware sp.tnitelecom.com id18488 View details United States Telecommunications
    Ransomware Otelier.io id18487 View details United States Other
    Ransomware highwirepress.com id18484 View details United States Communication / Marketing
    Ransomware taobao.com id18460 View details China Other
    Ransomware pinduoduo.com id18459 View details China Other
    Ransomware This entry has been removed following a request from the company id18492 View details China Services
    Ransomware icmr.gov.in id18457 View details India Other
    Ransomware Ministry Of Defense of the Republic Of Korea id18456 View details Korea, Republic of Public Sector
    Ransomware JD.com Inc (Chinese) id18455 View details China Services
    Ransomware Florida Department of Transportation (FDOT) id18439 View details United States Transportation / Travel / Logistics
    Ransomware Orange.com id18438 View details France Other
    Ransomware Belarus E-commerce & Energy Data id18429 View details Belarus Retail / E-commerce
    Ransomware knesset.gov.il id18428 View details Israel Other
    Ransomware nrru.ac.th - University id18427 View details Thailand Education
    Ransomware iaai.com - Washington DC DMV id18418 View details United States Other
    Ransomware access and various companies By babuk Locker 2.0 id18417 View details United Kingdom Other
    Ransomware The Ministry of National Defense - mod.gov.vn (NavyVietnam) id18413 View details Viet Nam Public Sector
    Ransomware movistar.com.pe id18412 View details Peru Other
    Ransomware Taiwan - Mackay Hospital id18399 View details Taiwan, Province of China Healthcare / Pharma
    Ransomware cch.org.tw - Changhua Christian Hospital id18398 View details Taiwan, Province of China Healthcare / Pharma
    Ransomware nuclep.gov.br. Nuclep Brazil id18397 View details Brazil Other
    Ransomware parliament.iq id18396 View details Iraq Other
    Ransomware web.asia.edu.tw - Taiwan (Asia University) id21591 View details Taiwan, Province of China Education
    Ransomware Intelligence Bureau of the Joint Staff Department of the Central Military Commission China id18394 View details China Public Sector
    Ransomware Indian military and government defense 20TB id18393 View details Public Sector
    Ransomware Iraqi Ministry of Finance id18384 View details Iraq Finance / Legal / Insurance
    Ransomware Iraqi Council of Ministers id18383 View details Iraq Public Sector
    Ransomware marinabaysands.com -  Singapore Hotel (Internal Server) id18373 View details Singapore Hospitality / Food & Beverage / Tourism
    Ransomware hitekgroup.in india Finance id18368 View details India Finance / Legal / Insurance
    Ransomware India's telecommunication network id18362 View details India Telecommunications
    Ransomware Babuk Locker 2.0 affiliate program 2025 id18358 View details United Kingdom Communication / Marketing
    Ransomware Baykar Turkish defense company C4I and artificial intelligence id18349 View details Türkiye Services
    Ransomware wapda.gov.pk By Babuk Locker 2.0 id18316 View details Pakistan Other
    Ransomware airexplore.aero Company id18325 View details Slovakia Services
    Ransomware fnde.gov.br brazilian government id18317 View details Brazil Public Sector
    Ransomware wapda.gov.pk id18321 View details Pakistan Other
    Ransomware lexmark.com Company id18315 View details United States Services
    Ransomware forvismazars.com.fr ( mazars.fr ) By Babuk Locker 2.0 id18313 View details France Other
    Ransomware forvismazars.com.fr ( mazars.fr ) id18348 View details France Other
    Ransomware petstop.com Company id18311 View details Services
    Ransomware misaludhealth.com By Babuk Locker 2.0 id18310 View details United Kingdom Healthcare / Pharma
    Ransomware misaludhealth.com id18347 View details Healthcare / Pharma
    Ransomware bank.pingan.com (CN) By Babuk Locker 2.0 id18309 View details China Finance / Legal / Insurance
    Ransomware bank.pingan.com (CN) id18346 View details China Finance / Legal / Insurance
    Ransomware Access to Indian Ministry of Defence and Military Secret (DRDO) documents By Babuk Locker ... id18308 View details India Public Sector
    Ransomware Mandarin.com.br By Babuk Locker 2.0 id18305 View details Brazil Other
    Ransomware Mandarin.com.br id18345 View details Brazil Other
    Ransomware mazars.fr id18296 View details France Other
    Ransomware INDONESIA TAXPAYER IDENTIFICATION NUMBER (NPWP) id16958 View details Indonesia Other
    Ransomware MYINDIHOME TELKOM INDONESIA by ( Babuk Locker ) id16956 View details Indonesia Other
    Ransomware MYINDIHOME TELKOM INDONESIA id16951 View details Indonesia Other
    Ransomware MYPERTAMINA INDONESIA id16947 View details Indonesia Other
    Ransomware copral.com.br id16936 View details Brazil Communication / Marketing
    Ransomware human.de id16933 View details Germany Communication / Marketing
    Ransomware bocagroup.com id16932 View details United States Construction / Real Estate
    Ransomware alentec.com id16931 View details Sweden Telecommunications
    Ransomware Württemberger Medien id16930 View details Germany IT
    Ransomware viacaojacarei.com.br id16929 View details Brazil Other
    Ransomware gelco-s-a.com.br id16928 View details Brazil Other
    Ransomware Kurosu & Co.SA - kurosu.com.py id16927 View details Paraguay Other
    Ransomware zapopan.gob.mx id16926 View details Mexico Other
    Ransomware carc.gov.jo id16925 View details Jordan Other
    Ransomware nhbg.com.co id16924 View details Colombia Other
    Ransomware APMS ( Advanced Physician Management Service LLC id16923 View details United States Services
    Ransomware a top-tier law firm in Workers Compensation Defense! id16922 View details Finance / Legal / Insurance
    Ransomware precisediagnosticspacs.com id16921 View details United States Communication / Marketing
    Ransomware zetech.ac.ke id16920 View details Kenya IT
    Ransomware maxprofit.mcode.me id16919 View details Communication / Marketing
    Ransomware skopje.gov.mk id16918 View details North Macedonia Other
    Ransomware rtdc.gov.mn id16917 View details Mongolia Other
    Ransomware pbos.gov.pk id16916 View details Pakistan Other
    Ransomware abd-ong.org id16915 View details Spain Other
    Ransomware mtgazeta.uz id16914 View details Uzbekistan Other
    Ransomware sincorpe.org.br id16913 View details Brazil Services
    Ransomware pti.agency id16912 View details Germany Communication / Marketing
    Ransomware singularanalysts.com id16911 View details United States Other
    Ransomware gervetusa.com id16910 View details United States Other
    Ransomware workers.com.zm id16909 View details Zambia Other
    Ransomware wacer.com.au id16908 View details Australia Other
    Ransomware thebetareview.com id16907 View details United States Other
    Ransomware senseis.xmp.net id16906 View details Other
    Ransomware fpsc-anz.com id16905 View details Australia Other
    Ransomware mandiricoal.net id16904 View details India Other
    Ransomware dealplexus.com id16903 View details India Other
    Ransomware bee-insurance.com id16902 View details United States Finance / Legal / Insurance
    Ransomware lamundialdeseguros.com id16901 View details Colombia Other
    Ransomware indianaerospaceandengineering.com id16900 View details United States Manufacturing / Engineering
    Ransomware gstpam.org id16899 View details Other
    Ransomware www.shootinghouse.com.br id16898 View details Brazil Other
    Ransomware headwaterco.com id16897 View details United States Other
    Ransomware www.al-shefafarm.ro id16896 View details Romania Agriculture / Food
    Ransomware www.ykp.com.br id16895 View details Brazil Other
    Ransomware www.go4kora.tv id16894 View details Other
    Ransomware www.rekamy.com id16893 View details Malaysia Other
    Ransomware www.dvttechnologyltd.com id16892 View details United States IT
    Ransomware www.siea.sk id16891 View details Slovakia Other
    Ransomware www.spmundi.com.br id16890 View details Brazil Other
    Ransomware www.merchant.id id16889 View details Indonesia Other
    Ransomware www.cyncsolutions.com id16888 View details United States Services
    Ransomware Baca County Feedyard, Inc id16887 View details United States Public Sector
    Ransomware www.skywaycoach.ca id16886 View details Canada Other
    Ransomware www.farmaciaflorio.com id16885 View details Italy Agriculture / Food
    Ransomware www.nrshealthcare.com id16884 View details United Kingdom Healthcare / Pharma
    Ransomware www.hcisystems.net id16883 View details United States Services
    Ransomware www.betteraccountingsolutions.com id16882 View details United States Finance / Legal / Insurance
    Ransomware www.aretusamilano.it id16881 View details Italy Other
    Ransomware www.agenciahost.com id16880 View details Brazil Other
    Ransomware www.constelacion.com.sv id16879 View details El Salvador Other
    Ransomware www.avantit.no id16878 View details Norway Other
    Ransomware www.industrialdealimentos.com id16877 View details Colombia Manufacturing / Engineering
    Ransomware www.lapastina.com id16876 View details Brazil Other
    Ransomware www.kovra.com.my id16875 View details Malaysia Other
    Ransomware www.computan.com id16874 View details Canada Other
    Ransomware www.scadea.com id16873 View details United States Other