logo

Babuk2 Ransomware: Extortion Attempts Based on False Claims

ID: 2babf70e-2e31-5ee7-8fd2-986a3855820d

STIX ID: report--2babf70e-2e31-5ee7-8fd2-986a3855820d

Feed Name: Halcyon Blog

Threat Score
30/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

...
...

Halcyon RISE analysis indicates that Babuk2’s public extortion claims are likely false and based on recycled data from earlier breaches rather than new ransomware encryptions or fresh network intrusions; the group, active since January 2025 and associated with an operator known as Bjorka, appears to be leveraging the Babuk name for credibility. Organizations are advised to independently verify any extortion claims and check for genuine indicators of compromise before paying ransoms or undertaking costly remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.