BABUK RANSOMWARE: A VICTIM OF INDODAX HACK
ID: af4ecea5-a70a-5561-ae32-754a3c69822d
STIX ID: report--af4ecea5-a70a-5561-ae32-754a3c69822d
Feed Name: THE RAVEN FILE
**Executive Summary:** The report documents Babuk ransomware's return (Babuk 2.0), lists specific Bitcoin wallet addresses and transaction amounts showing transfers into Indodax exchange hot wallets, and recounts a September 11, 2024 Indodax compromise that drained roughly $20M — including wallets used by Babuk — causing the group to move subsequent ransom receipts to a different exchange wallet; the piece includes IoCs, transaction timelines, and unconfirmed speculation about DPRK involvement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
