Also known as: tracked as, Rorschach, Aug 5, ArechClient2, UAT-10027, fast16, according to the report, sophistication, operational behavior, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, Newscaster, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm, Newscaster Team, Magic Hound, G0059, Phosphorus, TunnelVision, COBALT MIRAGE, Agent Serpens, BOLDBADGER, TG-0110, Sednit, Hammertoss, Patchwork
Femwar02 emerged as a previously unknown adversary in February 2026, quickly attracting attention with a large‑scale ransomware assault on the Sapienza University of Rome. The gang’s hallmark is BabLock (also referenced as Rorschach), an evolution of lockBit 2.0 that incorporates hybrid encryption using curve25519 and hc-128 for speed while enabling partial file encryption to preserve system responsiveness. BabLock also employs direct syscalls to sidestep endpoint detection, DLL sideloading through DarkLoader, and domain‑wide lateral movement via Group Policy on Windows Domain Controllers. The malware’s code shares significant lineage with LockBit 2.0 but fuses modules from Babuk and DarkSide, making its payloads difficult to classify by traditional families alone. In a clear sign of ideological bias, the ransomware avoids encrypting files on systems configured for Russian or other post‑Soviet languages—a pattern that aligns it with pro‑Russian objectives. The attack on Sapienza involved an initial spear‑phishing vector and exploitation of known vulnerabilities in Zimbra services. Femwar02’s operational footprint extends beyond academia, touching government, defense, financial services, media, healthcare, aviation, and critical infrastructure across a broad geographic spectrum that includes the US, CN, GB, IN, JP, RU, IR, FR, DE, and many others. The gang’s approach is one of rapid impact: fast encryption to cripple operations before a ransom can be demanded. Analysts note a high degree of sophistication combined with a pragmatic “smash‑and‑grab” mentality, evidenced by the group’s large‑scale data exfiltration via command‑and‑control channels and evidence of persistence in long‑term espionage profiles tied to other known APTs such as APT28 and APT29. goals_targeting":"Femwar02 seeks to maximize financial gain through swift ransomware deployment while maintaining a political narrative that excludes Russian‑language systems. Their targeting strategy prioritizes high‑profile institutions within critical sectors where disruption is costly and ransom demands are high, yet shows a deliberate avoidance of infrastructures aligned with pro‑Russian usage, indicating both opportunistic profit motives and ideological alignment.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Femwar02 is a pro‑Russian ransomware gang that surfaced in early 2026, launching a high‑impact attack on Italy’s Sapienza University by deploying the BabLock/Rorschach malware. The group focuses on fast hybrid encryption with selective language avoidance, targeting a wide array of sectors worldwide while avoiding systems set to Russian or other post‑Soviet languages. Their tactics combine rapid mass encryption, spear‑phishing, and domain‑wide propagation via Windows Group Policy.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Femwar02’s known campaign record is limited to the Sapienza University incident, yet its pattern mirrors other pro‑Russian actors such as APT28 and APT29: swift initial access via spear‑phishing with a broad dropper bundle, rapid lateral movement using Windows Group Policy, and an emphasis on fast, selective encryption. Post‑attack, the gang appears to exfiltrate data through command‑and‑control channels before encrypting assets. Although only one large attack has been documented, analysts suspect ongoing smaller operations given the actor’s toolset breadth and language‑aware execution strategy.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
4
Techniques
52
Tools
0
Campaigns
16
IOCs
0
Observed Data
3
Tactics