Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors babuk2

Also known as: Satanlock

Description

Babuk Locker 2.0, also known as Bjorka or SkyWave, after failing to make any profit from selling public databases on forums, decided to impersonate Babuk Ransomware group. He launched a blog where he claimed multiple public breaches from BreachForums as ransomware attacks Known victims: 180 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Babuk2, also known as Satanlock, is a medium-sophistication criminal threat actor primarily motivated by financial gain. They are known for leveraging ransomware tactics, albeit often through deceptive means such as impersonating other ransomware groups and creating fake breach announcements to extort money without actual encryption.

Goals & Targeting

Babuk2's strategic objectives revolve around maximizing financial gain through deception and extortion rather than traditional ransomware operations. They appear to target organizations that are more likely to respond to such threats due to the fear of data exposure, with a focus on sectors where the impact of a breach could be significant, such as education or healthcare.

Enhanced Description

Babuk2 operates with a primary focus on financial gain, employing tactics that include impersonation and deception. The group is known for claiming responsibility for data breaches that it has supposedly carried out, using these claims to pressure organizations into paying ransoms despite not necessarily encrypting their data. This approach allows the group to monetize previous data breaches from forums like BreachForums by relabeling them as ransomware attacks. Babuk2's operations are characterized by a focus on creating fear and urgency among victims, leveraging psychological manipulation to induce payment without providing any genuine encryption or damage.

Key Capabilities

  • Social engineering
  • Deceptive phishing
  • Fake ransomware campaigns
  • Leveraging existing breaches for extortion

MITRE ATT&CK Tactics

Initial Access
Execution

Campaigns & Victims

Babuk2 has been active since February 2021, targeting organizations globally with its deceptive ransomware campaigns. The group's operations involve claiming responsibility for data breaches and demanding ransoms without encrypting systems. Notable victims include educational institutions and healthcare organizations, reflecting a pattern of targeting sectors where the impact of a breach could be significant.

IOC Patterns

  • Phishing emails claiming ransomware infections
  • Social media posts or blog claims of breaches linked to targets
  • Threatening communications demanding ransoms

Recommended Actions

  • Implement employee training on phishing and social engineering tactics
  • Monitor for unusual breach claims or extortion attempts
  • Enhance email filtering to detect malicious messages
  • Encourage organizations to avoid paying ransoms and report incidents to law enforcement

Suggested Tags

criminal
ransomware
deception
organizational-gain

Confidence Assessment

Moderate confidence in Babuk2's operational patterns, with limited visibility into their exact methods and infrastructure. Gaps include detailed TTPs beyond deceptive claims, specific targets, and precise attack vectors used.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
criminal
ransomware
deception
organizational-gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Feb 1, 2021
Last Seen
Apr 6, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.