logo

BABUK RANSOMWARE: A VICTIM OF INDODAX HACK

ID: af4ecea5-a70a-5561-ae32-754a3c69822d

STIX ID: report--af4ecea5-a70a-5561-ae32-754a3c69822d

Feed Name: THE RAVEN FILE

Threat Score
75/100

Date Published: 2025-02-06

Date Updated: 2026-04-19

Author: RakeshKrish

...
...

**Executive Summary:** The report documents Babuk ransomware's return (Babuk 2.0), lists specific Bitcoin wallet addresses and transaction amounts showing transfers into Indodax exchange hot wallets, and recounts a September 11, 2024 Indodax compromise that drained roughly $20M — including wallets used by Babuk — causing the group to move subsequent ransom receipts to a different exchange wallet; the piece includes IoCs, transaction timelines, and unconfirmed speculation about DPRK involvement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.