Babuk2 Ransomware

Under attack by ransomware or suffering a cyber breach?

Speed is critical when facing a live cyber attack. If you believe you’ve been compromised, by the Babuk2 ransomware group or another threat actor - contact us immediately.

About Babuk2 ransomware group

Babuk2 ransomware is a recently emerged threat, first detected in early 2024. While this group claims links to the original Babuk ransomware group (known for a series of high-profile ransomware attacks and leaking their source code on the dark web), researchers and the original operators have denied any true connection.

Instead, Babuk2 appears to be a loosely organised or opportunistic threat group that exploits the Babuk name to intimidate and pressure organisations. The behaviour of Babuk2 actors is often chaotic and inconsistent, and many of the group’s claims about successful data breaches lack technical validation. Analysts suggest Babuk2 may operate more as a scam or “copycat” outfit than a truly sophisticated ransomware operation. Many of their campaigns involve unsophisticated threat actors repurposing old, recycled data and making false claims on data leak sites.

What we can help with:

Request a call back

If your organisation has been infected with ransomware contact us immediately.

How Babuk2 operators work

Babuk2 relies on a classic double extortion model:

  • Initial access is gained through phishing, exploiting unpatched vulnerabilities, or compromised credentials, leading to fresh network intrusions across multiple sectors.

  • The group first exfiltrates sensitive data to external servers for data theft.

  • They then use robust encryption methods (often elliptic-curve cryptography) to lock encrypted files, appending the .babuke2 extension.

  • Victims receive a ransom note with instructions to negotiate on a dark web site.

  • If payment is refused, the ransomware group threatens to publish or leak breached data, sample data, or previously leaked data on their data leak site.

The threat actors behind Babuk2 have conducted multiple attacks and often pressure organisations by posting victim posts and alleged intrusion details online. They regularly make false claims about the volume and sensitivity of the stolen data to create panic and coerce payment.

We are equipped to deal with an attack from any ransomware group.

Don’t hesitate to contact us if you are under attack from a ransomware group not listed above. 

Recognising a Babuk2 attack

Babuk2 first appeared in early 2024 and quickly became active across Europe and North America, targeting corporate networks, government agencies, and industrial suppliers. The group has claimed around 180 attacks to date.

Babuk2 is known for using a double extortion model, demanding payment both to decrypt data and to prevent stolen information from being leaked publicly. Victims often face added pressure from the group’s aggressive tactics, including posting data on leak sites and recycling previously breached or leaked files to appear more threatening.

Common signs of a Babuk2 attack include sudden file encryption, ransom notes referencing Babuk2, and threats of data exposure. The group may also reuse elements from earlier Babuk campaigns to boost credibility. Any organisation handling sensitive data and lacking strong cyber defences should treat these indicators seriously, as Babuk2 remains an active and persistent threat.

Why you must not interfere with your ransomware environment

If you discover a physical break-in at your offices, your first instinct would be to call the police; touch nothing and let them search for clues. Then, your focus would shift to restoring business operations.

A cyber-attack requires the same approach. Your digital environment is a CRIME SCENE. It is crucial to leave the environment untouched to allow for a forensic investigation.

This is not a task for your IT team or MSP. Digital Forensic specialists are available 24/7 to assist you, just like in a physical crime.

description Sector Date Discovered Attack Date Country Screenshot
tecnologias.mspz2.gob.ec Public Sector 23/04/2025 07:48 PM 06/04/2025 08:59 PM EC View
turkish defense military Public Sector 04/04/2025 06:52 AM 04/04/2025 01:00 AM TR View
rheinmetall.com (Rheinmetall Defence) Manufacturing 04/04/2025 06:51 AM 04/04/2025 01:15 AM DE View
gangotreehomes.com (RealEstate) Not Found 03/04/2025 11:28 PM 03/04/2025 09:43 PM IN -
Secret plans of Indian army Not Found 03/04/2025 11:28 PM 03/04/2025 11:27 PM -
Bangladesh Armed Forces (BangLadesh Army) Public Sector 03/04/2025 11:27 PM 03/04/2025 11:26 PM BD -
Saudi Arabian military and government internal center Public Sector 03/04/2025 11:26 PM 03/04/2025 11:26 PM SA -
Hellenic Airforce Public Sector 03/04/2025 11:26 PM 03/04/2025 11:25 PM GR -
ezbuy.sg (Singapore Shopping) Consumer Services 03/04/2025 09:53 PM 03/04/2025 06:05 AM SG View
Iran gas service system, Energy 03/04/2025 09:52 PM 03/04/2025 10:48 AM IR View
kfar hatta medical center - Lebanon Healthcare 03/04/2025 09:51 PM 03/04/2025 10:52 AM LB View
Polizia italia mail access Public Sector 03/04/2025 03:20 AM 03/04/2025 03:19 AM IT View
zalora.sg (Singapore Shopping) Consumer Services 03/04/2025 03:19 AM 03/04/2025 03:18 AM SG View
ascires.com Healthcare 02/04/2025 08:18 PM 11/10/2024 10:37 PM ES View
aosense.com - AO Sense INC. Technology 02/04/2025 08:16 PM 02/04/2025 08:15 PM US View
dardoc.com Not Found 02/04/2025 08:15 PM 25/11/2024 03:45 AM DK View
navy-mil-bd Public Sector 02/04/2025 06:47 PM 02/04/2025 06:46 PM BD View
drdo.gov.in Public Sector 02/04/2025 01:49 AM 02/04/2025 01:47 AM IN View
uniproof.com.br Not Found 01/04/2025 09:17 PM 01/04/2025 09:16 PM BR View
(UPDATE) - whitecapcanada.com Technology 01/04/2025 04:52 PM 01/04/2025 04:51 PM CA View
pln.co.id - PLN INDONESIA Energy 31/03/2025 05:24 PM 31/03/2025 05:23 PM ID View
moh.gov.rw Public Sector 31/03/2025 05:23 PM 31/03/2025 05:22 PM RW View
iDRAC (Integrated Dell Remote Access Controller) management interface for Dell servers Technology 29/03/2025 04:24 PM 29/03/2025 04:23 PM US View
elsoms.com Agriculture and Food Production 29/03/2025 02:50 AM 07/09/2024 03:31 PM GB View
brune.com.br - Group MC (conglomerate) Not Found 29/03/2025 02:49 AM 29/03/2025 02:48 AM BR View
towellengineering.net Manufacturing 29/03/2025 02:48 AM 15/08/2024 12:00 AM OM View
icvc.co - Instituto Cardiovascular del Cesar Healthcare 29/03/2025 02:46 AM 29/03/2025 02:45 AM CO View
modiin-ezrachi.co.il Not Found 29/03/2025 01:23 AM 12/10/2024 07:03 PM IL View
La Futura Not Found 29/03/2025 01:22 AM 29/03/2025 01:20 AM View
Atlantic Coast Consulting Inc Not Found 29/03/2025 01:20 AM 29/03/2025 01:19 AM US View
theeyeclinicsurgicenter.com - The Eye Clinic Surgicenter company Healthcare 29/03/2025 01:19 AM 29/03/2025 01:18 AM View
leadzen.ai Technology 28/03/2025 05:54 PM 28/03/2025 05:53 PM IN View
healthcasts.com Healthcare 28/03/2025 05:53 PM 28/03/2025 05:52 PM US View
pureincubation.com Technology 28/03/2025 05:51 PM 28/03/2025 05:50 PM US View
unired.uz Not Found 28/03/2025 02:50 PM 28/03/2025 02:49 PM UZ View
nadra.gov.pk - NADRA official Of Pakistan Army & (Andhra Pradesh) Public Sector 27/03/2025 07:51 AM 27/03/2025 07:50 AM PK View
heras.co.uk Manufacturing 26/03/2025 10:58 PM 29/05/2024 07:04 PM GB View
alliedwoundcare.com Healthcare 26/03/2025 10:57 PM 12/01/2024 04:16 AM US View
crimsgroup.com Not Found 26/03/2025 10:55 PM 26/03/2025 10:25 PM US View
aman-iraq.com Not Found 26/03/2025 10:54 PM 26/03/2025 10:53 PM IQ View
mot.gov.iq - Iraqi Ministry of Commerce (Of Trade) Public Sector 26/03/2025 01:14 PM 26/03/2025 01:13 PM IQ View
israel Infrastructure & Secret Documents intelligence information Not Found 26/03/2025 01:13 PM 26/03/2025 01:12 PM IL View
kalesavunma.com - KALE SAVUNMA. Manufacturing 25/03/2025 10:54 PM 25/03/2025 10:53 PM TR View
airexplore.aero Transportation/Logistics 24/03/2025 09:24 PM 24/03/2025 09:23 PM SK View
iberdrola.com (Spain energy) Energy 24/03/2025 07:55 PM 24/03/2025 07:54 PM ES View
Synesis Surveillance System Technology 22/03/2025 02:54 PM 22/03/2025 02:53 PM RU View
inmarsat.com Telecommunication 22/03/2025 11:54 AM 22/03/2025 11:53 AM GB View
jp-property.com Not Found 22/03/2025 11:52 AM 22/03/2025 11:51 AM JP View
armetal.com Manufacturing 21/03/2025 07:49 PM 21/03/2025 07:48 PM SA View
The Ticktin Law Group By Babuk Locker 2.0 Business Services 21/03/2025 07:23 AM 21/03/2025 07:22 AM US View
Mpaj.gov.my Public Sector 21/03/2025 07:22 AM 21/03/2025 07:21 AM MY View
exostar.com TOP Defense AS Technology 21/03/2025 02:53 AM 21/03/2025 02:52 AM View
Standard Capital Securities (Pvt) Backoffice - Pakistan Stock Market Data Vault Financial Services 21/03/2025 01:22 AM 21/03/2025 01:21 AM PK View
mohrss.gov.cn ( Ministry of Human Resources and Social Security ) Public Sector 20/03/2025 11:53 PM 20/03/2025 11:52 PM CN View
amazon.com Technology 20/03/2025 11:52 PM 20/03/2025 11:51 PM US View
fr.sodexo.com Hospitality and Tourism 20/03/2025 01:57 PM 20/03/2025 01:56 PM FR View
Corporate access, up to Shipping Apps in QATAR Transportation/Logistics 20/03/2025 01:55 PM 20/03/2025 01:54 PM QA View
woqod.com Energy 20/03/2025 01:54 PM 20/03/2025 01:53 PM QA View
mof.go.th - Ministry of Finance (Thailand) Public Sector 20/03/2025 01:53 PM 20/03/2025 01:52 PM TH View
smic.mi.th (Thailand Intelligence Agency) Public Sector 20/03/2025 09:23 AM 20/03/2025 09:21 AM TH View
http://www.gob.ve Public Sector 19/03/2025 07:58 PM 19/03/2025 07:57 PM VE View
Access Panel Financial Technology Company (Thailand) Technology 19/03/2025 07:57 PM 19/03/2025 07:56 PM TH View
United States County Palm Beach Goverment Public Sector 19/03/2025 07:56 PM 19/03/2025 07:55 PM US View
Municipal taxation Secretariat Access - Brazil Goverment Public Sector 19/03/2025 07:55 PM 19/03/2025 07:54 PM BR View
Intelligence Bureau of the Joint Staff Department of the Central Military Commission China Public Sector 19/03/2025 06:28 PM 19/03/2025 06:27 PM CN View
rac.gov.my Public Sector 19/03/2025 06:26 PM 19/03/2025 06:25 PM MY View
nimapinfotech.com Technology 19/03/2025 06:25 PM 19/03/2025 06:24 PM IN View
esaote.com Healthcare 18/03/2025 06:27 PM 18/03/2025 06:26 PM IT View
nstda.or.th Technology 18/03/2025 06:26 PM 18/03/2025 06:25 PM TH View
kominfo.go.id Public Sector 18/03/2025 06:24 PM 01/07/2024 07:10 PM ID View
pajak.go.id Public Sector 18/03/2025 06:23 PM 18/03/2025 06:22 PM ID View
dukcapil.kemendagri.go.id (SIAK DUKCAPIL MINISTRY OF HOME AFFAIRS OF INDONESIA) Public Sector 18/03/2025 06:22 PM 18/03/2025 06:20 PM ID View
whitecapcanada.com Technology 18/03/2025 03:24 PM 18/03/2025 03:23 PM CA View
hcahealthcare.com INC. Healthcare 18/03/2025 01:47 PM 18/03/2025 01:46 PM US View
sp.tnitelecom.com Telecommunication 18/03/2025 12:23 PM 18/03/2025 12:22 PM US View
Otelier.io Technology 18/03/2025 12:21 PM 18/03/2025 12:20 PM US View
highwirepress.com Technology 18/03/2025 07:45 AM 18/03/2025 07:44 AM US View
taobao.com Technology 17/03/2025 02:51 AM 17/03/2025 02:50 AM CN View
Takedown notice of 18 Mars 2025 - Request #1025 Technology 17/03/2025 02:50 AM 17/03/2025 02:49 AM CN -
icmr.gov.in Public Sector 17/03/2025 01:20 AM 17/03/2025 01:19 AM IN View
Ministry Of Defense of the Republic Of Korea Public Sector 16/03/2025 11:46 PM 16/03/2025 11:45 PM KR View
JD.com Inc (Chinese) Technology 16/03/2025 11:45 PM 16/03/2025 11:43 PM CN View
Florida Department of Transportation (FDOT) Public Sector 16/03/2025 02:50 PM 16/03/2025 01:19 PM US View
Orange.com Telecommunication 16/03/2025 02:49 PM 16/03/2025 01:36 PM FR View
Belarus E-commerce & Energy Data Technology 15/03/2025 10:23 AM 15/03/2025 10:22 AM BY View
knesset.gov.il Public Sector 15/03/2025 10:22 AM 25/10/2024 08:53 AM IL View
nrru.ac.th - University Education 15/03/2025 10:21 AM 15/03/2025 10:20 AM TH View
iaai.com - Washington DC DMV Business Services 14/03/2025 12:45 PM 14/03/2025 12:44 PM US View
The Ministry of National Defense - mod.gov.vn (NavyVietnam) Public Sector 14/03/2025 10:14 AM 14/03/2025 10:13 AM VN View
movistar.com.pe Telecommunication 14/03/2025 10:13 AM 14/03/2025 10:11 AM PE View
Taiwan - Mackay Hospital Healthcare 14/03/2025 08:02 AM 13/03/2025 02:23 PM TW View
cch.org.tw - Changhua Christian Hospital Healthcare 14/03/2025 08:01 AM 13/03/2025 02:19 PM TW View
nuclep.gov.br. Nuclep Brazil Public Sector 14/03/2025 08:00 AM 13/03/2025 02:50 PM BR View
parliament.iq By Babuk Locker 2.0 Public Sector 14/03/2025 07:59 AM 14/03/2025 04:34 AM IQ View
web.asia.edu.tw - Taiwan (Asia University) Education 14/03/2025 07:57 AM 14/03/2025 05:21 AM TW View
Intelligence Bureau of the Joint Staff Department of the Central Military Commission China Public Sector 14/03/2025 07:56 AM 14/03/2025 07:55 AM CN View
Indian military and government defense 20TB Public Sector 14/03/2025 07:55 AM 14/03/2025 07:40 AM View
Iraqi Ministry of Finance Public Sector 13/03/2025 12:57 AM 13/03/2025 12:15 AM IQ View
Iraqi Council of Ministers Public Sector 13/03/2025 12:55 AM 13/03/2025 12:39 AM IQ View
marinabaysands.com -  Singapore Hotel (Internal Server) Hospitality and Tourism 12/03/2025 05:25 PM 12/03/2025 05:24 PM SG View
hitekgroup.in india Finance Financial Services 12/03/2025 02:23 PM 12/03/2025 02:21 PM IN View
India's telecommunication network Telecommunication 12/03/2025 12:51 PM 12/03/2025 12:50 PM IN View
Baykar Turkish defense company C4I and artificial intelligence By Babuk Locker 2.0 Manufacturing 12/03/2025 12:55 AM 12/03/2025 12:53 AM TR View
airexplore.aero Company Transportation/Logistics 11/03/2025 02:23 PM 11/03/2025 02:22 PM SK View
fnde.gov.br brazilian government Public Sector 11/03/2025 02:54 AM 11/03/2025 02:53 AM BR View
wapda.gov.pk By Babuk Locker 2.0 Public Sector 11/03/2025 02:53 AM 11/03/2025 02:52 AM PK View
lexmark.com Company Technology 11/03/2025 02:52 AM 11/03/2025 02:51 AM US View
forvismazars.com.fr ( mazars.fr ) By Babuk Locker 2.0 Not Found 11/03/2025 01:24 AM 11/03/2025 01:22 AM FR View
petstop.com Company Consumer Services 10/03/2025 11:52 PM 10/03/2025 11:51 PM -
misaludhealth.com By Babuk Locker 2.0 Technology 10/03/2025 11:51 PM 10/03/2025 11:50 PM -
bank.pingan.com Financial Services 10/03/2025 10:22 PM 10/03/2025 10:03 PM CN View
Access to Indian Ministry of Defence and Military Secret (DRDO) documents By Babuk Locker 2.0 Public Sector 10/03/2025 10:21 PM 10/03/2025 10:19 PM IN View
Mandarin.com.br Not Found 10/03/2025 07:23 PM 10/03/2025 07:22 PM BR View
mazars.fr company Financial Services 10/03/2025 11:28 AM 10/03/2025 08:00 AM FR View
INDONESIA TAXPAYER IDENTIFICATION NUMBER (NPWP) Public Sector 28/01/2025 06:12 PM 28/01/2025 06:11 PM ID View
MYINDIHOME TELKOM INDONESIA Telecommunication 28/01/2025 04:03 PM 28/01/2025 04:02 PM ID View
MYINDIHOME TELKOM INDONESIA Telecommunication 28/01/2025 03:13 PM 28/01/2025 03:12 PM ID View
MYPERTAMINA INDONESIA Energy 28/01/2025 05:56 AM 28/01/2025 05:55 AM ID View
Greetings! copral.com.br Today we are posting here the new company, "Copral Comercio e Navegacao LTDA". Manufacturing 27/01/2025 11:39 AM 27/01/2025 11:37 AM BR View
HUMAN, founded in 1972, is a Germany based privately owned company which develops, manufactures and distributes a wide range of IVD Diagnostics and laboratory equipment. Technology 27/01/2025 08:30 AM 01/02/2021 08:29 AM DE View
As America's premier elevator and escalator consulting company, BOCA Group is the partner of choice for the biggest and best-known building owners and developer Not Found 27/01/2025 08:27 AM 01/02/2021 08:26 AM US View
This is a public request for Alentec & Orion AB, you don't have much time left to get in touch with us and help you resolve your security problems, we also continue to be in your networks and monitor you Manufacturing 27/01/2025 08:25 AM 27/01/2025 08:24 AM SE View
Lassen Sie sich kostenlos von unseren Experten aus Stuttgart beraten. Digitalisierung geht schnell und einfach - Wir haben Lösungen für den Mittelstand! Not Found 27/01/2025 08:23 AM 27/01/2025 08:22 AM DE View
viacaojacarei.com.br Transportation/Logistics 27/01/2025 08:21 AM 27/01/2025 08:20 AM BR View
gelco-s-a.com.br Manufacturing 27/01/2025 08:19 AM 27/01/2025 08:17 AM BR View
Kurosu & Co.SA - kurosu.com.py LEAKED Agriculture and Food Production 27/01/2025 08:17 AM 27/01/2025 08:16 AM PY View
zapopan.gob Public Sector 27/01/2025 08:16 AM 27/01/2025 08:15 AM MX View
carc.gov Public Sector 27/01/2025 08:14 AM 27/01/2025 08:13 AM JO View
nhbg Not Found 27/01/2025 08:13 AM 27/01/2025 08:12 AM CO View
APMS ( Advanced Physician Management Service LLC Healthcare 27/01/2025 08:12 AM 27/01/2025 08:10 AM US View
a top-tier law firm in Workers Compensation Defense! Business Services 27/01/2025 08:10 AM 27/01/2025 08:09 AM View
precisediagnosticspacs.com Healthcare 27/01/2025 08:09 AM 27/01/2025 08:08 AM US View
zetech.ac.ke Education 27/01/2025 08:08 AM 27/01/2025 08:07 AM KE View
maxprofit.mcode.me Not Found 27/01/2025 08:07 AM 27/01/2025 08:06 AM View
skopje.gov.mk Public Sector 27/01/2025 08:06 AM 27/01/2025 08:05 AM MK View
rtdc.gov.mn access Public Sector 27/01/2025 08:05 AM 27/01/2025 08:04 AM MN View
pbos.gov.pk Public Sector 27/01/2025 08:04 AM 27/01/2025 08:02 AM PK View
abd-ong.org Not Found 27/01/2025 08:02 AM 27/01/2025 08:01 AM ES View
mtgazeta.uz Not Found 27/01/2025 08:01 AM 27/01/2025 08:00 AM UZ View
sincorpe.org.br Not Found 27/01/2025 08:00 AM 27/01/2025 07:59 AM BR View
pti.agency Not Found 27/01/2025 07:58 AM 27/01/2025 07:57 AM DE View
singularanalysts.com Technology 27/01/2025 07:57 AM 27/01/2025 07:56 AM US View
gervetusa.com Healthcare 27/01/2025 07:56 AM 27/01/2025 07:55 AM US View
workers.com.zm Not Found 27/01/2025 07:55 AM 27/01/2025 07:54 AM ZM View
wacer.com.au Manufacturing 27/01/2025 07:54 AM 27/01/2025 07:53 AM AU View
thebetareview.com Technology 27/01/2025 07:51 AM 27/01/2025 07:50 AM US View
senseis.xmp.net Not Found 27/01/2025 07:50 AM 27/01/2025 07:49 AM View
fpsc-anz.com Not Found 27/01/2025 07:48 AM 27/01/2025 07:47 AM AU View
mandiricoal.net Energy 27/01/2025 07:47 AM 27/01/2025 07:46 AM IN View
dealplexus.com Financial Services 27/01/2025 07:46 AM 27/01/2025 07:45 AM IN View
bee-insurance.com Financial Services 27/01/2025 07:45 AM 27/01/2025 07:44 AM US View
lamundialdeseguros.com Financial Services 27/01/2025 07:44 AM 27/01/2025 07:42 AM CO View
indianaerospaceandengineering.com Manufacturing 27/01/2025 07:42 AM 27/01/2025 07:41 AM US View
gstpam.org Not Found 27/01/2025 07:41 AM 27/01/2025 07:40 AM View
http://www.shootinghouse.com.br Not Found 27/01/2025 07:40 AM 27/01/2025 07:39 AM BR View
headwaterco.com Technology 27/01/2025 07:38 AM 27/01/2025 07:36 AM US View
http://www.al-shefafarm.ro Agriculture and Food Production 27/01/2025 07:36 AM 27/01/2025 07:35 AM RO View
http://www.ykp.com.br Technology 27/01/2025 07:35 AM 27/01/2025 07:34 AM BR View
http://www.go4kora.tv Not Found 27/01/2025 07:34 AM 27/01/2025 07:33 AM View
http://www.rekamy.com Technology 27/01/2025 07:33 AM 27/01/2025 07:32 AM MY View
http://www.dvttechnologyltd.com Technology 27/01/2025 07:32 AM 27/01/2025 07:31 AM US View
http://www.siea.sk Energy 27/01/2025 07:31 AM 27/01/2025 07:30 AM SK View
http://www.spmundi.com.br Manufacturing 27/01/2025 07:30 AM 27/01/2025 07:28 AM BR View
http://www.merchant.id Financial Services 27/01/2025 07:28 AM 27/01/2025 07:27 AM ID View
http://www.cyncsolutions.com Technology 27/01/2025 07:27 AM 27/01/2025 07:26 AM US View
Baca County Feedyard, Inc Agriculture and Food Production 27/01/2025 07:26 AM 27/01/2025 07:25 AM US View
http://www.skywaycoach.ca Transportation/Logistics 27/01/2025 07:25 AM 27/01/2025 07:24 AM CA View
http://www.farmaciaflorio.com Healthcare 27/01/2025 07:24 AM 27/01/2025 07:23 AM IT View
http://www.nrshealthcare.com Healthcare 27/01/2025 07:23 AM 27/01/2025 07:22 AM GB View
http://www.hcisystems.net Technology 27/01/2025 07:22 AM 27/01/2025 07:20 AM US View
http://www.betteraccountingsolutions.com Financial Services 27/01/2025 07:20 AM 27/01/2025 07:19 AM US View
http://www.aretusamilano.it Not Found 27/01/2025 07:19 AM 27/01/2025 07:18 AM IT View
http://www.agenciahost.com Hospitality and Tourism 27/01/2025 07:18 AM 27/01/2025 07:17 AM BR View
http://www.constelacion.com.sv Technology 27/01/2025 07:17 AM 27/01/2025 07:16 AM SV View
http://www.avantit.no Technology 27/01/2025 07:16 AM 27/01/2025 07:15 AM NO View
http://www.industrialdealimentos.com Agriculture and Food Production 27/01/2025 07:14 AM 27/01/2025 07:13 AM CO View
http://www.lapastina.com Agriculture and Food Production 27/01/2025 07:13 AM 27/01/2025 07:12 AM BR View
http://www.kovra.com.my Not Found 27/01/2025 07:12 AM 27/01/2025 07:11 AM MY View
http://www.computan.com Technology 27/01/2025 07:11 AM 27/01/2025 07:09 AM CA View
http://www.scadea.com Technology 27/01/2025 07:09 AM 27/01/2025 07:08 AM US View

Post breach actions

  • Call a NCSC Cyber Incident Response approved supplier Some NCSC providers will fund up to 48 hours of investigation into your incident.
  • Report the incident to Report Fraud
  • Locate your business continuity plan Work out what you can do without access to your systems and data.
  • Identify your business insurance contact details
Business woman contacting a Zensec ransomware recovery service

Who are we and what experience do we have in responding to cyber incidents?

We are accredited to ISO 27001 and recognised by the UK’s National Cyber Security Centre (NCSC).

We provide comprehensive cyber risk management services, with a core focus on Digital Forensics and Incident Response (DFIR). Our capabilities are driven by a 24/7 Security Operations Centre and a dedicated in-house intelligence team that delivers timely, actionable threat reporting.

With decades of collective cyber security experience, we have the expertise to assume operational ownership of your entire IT security architecture – simplifying and strengthening cyber security across your business.

As an Assured Service Provider for Cyber Incident Response (CIR) at the Standard Level. This accreditation demonstrates our ability to deliver high-assurance, effective support in response to a wide range of cyber threats.

Your NCSC-approved supplier is a specialist crime scene investigator who will:

  1. Isolate and preserve your environment for forensic investigation.
  2.  Identify where the data has been duplicated and issue a legal takedown order.
  3. Identify your data, application and systems restore points. These might be at different points in time and will need to be carefully restored and reconstructed in a pristine environment.
  4.  Liaise with your business insurance company and if needed, with the Police.
  5. Advise you on notifying your customers of your situation.
  6. Rebuild your systems, restore your data and get you back to full operation. Note: This process can take between 2 weeks – 2 months.

 

Working with us

Our response process

Our team are ransomware recovery specialists with a proven, streamlined approach to resolving incidents quickly and effectively.

Step 1: Triage

We deploy our incident response team the same day. From the first call, we begin onboarding, introduce key stakeholders, set communication schedules, and start gathering critical information to guide the response.

Step 2: Investigation

DFIR (Digital Forensic Incident Response) teams investigate breaches to identify vulnerabilities, attack vectors, and system impacts from ransomware such as Data Loss (PII). We deliver clear forensic insights to guide mitigation.

Step 3: Contain

Our onsite and remote teams act fast to stop the attack in its tracks. That includes isolating affected systems, removing malicious code, and putting protections in place to prevent further spread or damage.

Step 4: Remediate & Eradicate

Once contained, we work to fully eliminate the threat. This includes fixing exploited vulnerabilities, restoring systems to a secure state, and ensuring no traces of the attack remain.

Step 5: Recover

Our incident response teams help get your business back to normal. We restore access to systems, recover data, and ensure services are safe, stable, and functioning, with minimal downtime.

Step 6: Post Incident

We conduct a full review of the incident response and recovery efforts. Together we assess what happened, what worked, and what can be improved, helping you build stronger defences for the future.

Forensic analysis to drive recovery

Our process includes a thorough digital forensic analysis from step two where the output becomes a central component of business recovery. This is because understanding the attack is of critical importance:

  • Informing an initial infection date

  • The extent and spread of infection

  • Data exfiltration having an impact on regulatory positions

  • Ensuring that the attacker and any tooling or artefacts they leave behind are eradicated

It is critical that the analysis of digital evidence is carried out to an agreed plan.

Maximising early root cause discovery and legal leverage

The process is purpose-built to uncover the root cause as early as possible, which is essential to inform remediation / eradication and recovery as well as supporting a legal take-down case if this is applicable. A legal take-down means we can assist in the legal enforcement that stops the criminals from publishing the data, thus undermining the ransom notice.

Our Digital Forensic and Incident Response (DFIR) teams maintain consistent communication throughout. Dedicated Incident Managers and technical engineering leads provide updates during the Cyber Incident Response journey, utilising risk registers and working within change management processes, all from triage through to post-incident, delivering successful business recovery.

Key take aways

  • You will not be able to access your systems or data.
  • It is advised to disconnect from the internet and shut down your systems, including PCs, to prevent further infections.
  • Your Office 365 system might also be compromised, allowing the attackers to monitor your responses. Avoid communicating with individuals through your primary email or team systems.
  • Threat actors typically infiltrate your system at least 2-4 weeks before you become aware of the attack. Your data will have already been exfiltrated. If your system is encrypted, this was not an overnight event.
  • Ransom demands in the UK typically range from £500,000 to £3 million, with some sectors, like education, facing demands that exceed £5 million
  • Paying the ransom may violate financial sanctions, which is a criminal offence and could result in a custodial sentence or further financial penalties.
  • If your data is sold or published online, it puts your customers and staff at risk, potentially implicating you in a Data Protection breach.
  • You will need to submit a data takedown request to the initial location where the data was transferred.
  • Do not overwrite the encrypted data. It is crucial to determine when the infection began and where the data was sent.
  • Avoid rebuilding from the latest backup, as it is likely to be infected.

Why should I trust Zensec to do this work rather than my IT team?

A forensic analysis needs to be meticulous and a clean restore and recovery requires a wealth of experience not normally available in an in-house team who must provide a broader range of IT support skills:

Internal IT teams don’t have the necessary skill set to resolve security encryption issues themselves. 

IT teams may recover to the same position with indicators of compromise ready to do it again… which can lead to another breach.

Internal teams are pressured to restore business operations and may recover before forensic analysis even begins, potentially destroying the crime scene before completion.

We can help

Frequently asked questions

Key information when you’re under pressure.

Babuk2 appears to be a different threat group from the original Babuk, though they use the Babuk name and some of the same ransomware strains and tactics. Many of their group’s claims are exaggerated or based on recycled data, and there is little evidence of direct ties between Babuk2 and the original Babuk operators.

Babuk2 and other ransomware groups gain initial access through phishing, unpatched vulnerabilities, and weak passwords. They often use previously leaked data to identify new targets. Prevent future attacks by:

  • Applying all software patches and updates promptly.

  • Enforcing strong, unique passwords and multi-factor authentication.

  • Training staff to spot phishing attempts.

  • Regularly reviewing access controls and removing unnecessary accounts.

  • Engaging with a threat intelligence partner like Zensec for ongoing monitoring.

Payment to Babuk2 or other ransomware groups is never guaranteed to solve the problem. Babuk2 actors are known for false claims and publishing previously leaked data regardless of payment. In the UK, paying ransoms may violate financial sanctions, see the latest sanctions list. Instead, rely on a professional incident response for recovery.

The NCSC is the UK National Cyber Security Centre. They provide cyber security guidance and support, helping to make the UK the safest place to live and work online. They have defined a Cyber Incident Response procedure and they have approved and accredited suppliers to provide this service.

https://www.ncsc.gov.uk/

As a recognised Assured Service Provider by the National Cyber Security Centre (NCSC), Zensec provide comprehensive cyber risk management services that are designed to Protect, Detect & Mitigate cyber security threats across the UK.

Report Fraud is the UK's national reporting centre for fraud and cybercrime. Whether you have been scammed, defrauded, or experienced cybercrime in England, Wales, or Northern Ireland, Report Fraud offers a central point of contact for information on fraud and financially motivated cybercrime.

https://www.reportfraud.police.uk/https://www.actionfraud.police.uk/

Yes. If sensitive data or personal data is stolen, you may need to inform customers, regulators, and law enforcement agencies, including Action Fraud. Zensec will advise you through all mandatory and recommended notifications.

Ransomware attacks by Babuk2 and other ransomware groups cause operational downtime, data loss, reputational harm, and legal risk. The effect on your business depends on the speed and quality of your response, the nature of the breached data, and how well you communicate with stakeholders. Zensec helps you recover securely and strengthens your defences for the future.

Dealing with a ransomware attack?
Our ransomware recovery service can help

Our expert team works quickly to contain the breach, recover your data, and restore your systems to full operation. We’ll guide you through every step of the recovery process and help strengthen your defences to prevent future attacks. Regain control with Zensec - trusted support when it matters most.