#babuk

2025-11-08

📢 Midnight, héritier de Babuk : analyse technique et guide de déchiffrement
📝 Selon un billet de blog technique publié le 8 novembre 2025, l’article explore en profondeur la souche de rançongiciel « Midnight ».
📖 cyberveille : cyberveille.ch/posts/2025-11-0
🌐 source : gendigital.com/blog/insights/r
#Babuk #IOC #Cyberveille

2025-10-14

🚨 Velociraptor DFIR exploited in LockBit ransomware attacks.

Huntress and Cisco Talos link Storm-2603 to a new campaign abusing outdated Velociraptor builds for privilege escalation, lateral movement, and ransomware deployment.

The crew reportedly used SharePoint exploits (ToolShell) and domain admin creation before dropping LockBit, Warlock, and Babuk payloads.

💬 Are open-source DFIR tools the next frontier for living-off-the-land tactics?

Full Details:
technadu.com/qantas-customer-d

Follow TechNadu for more cutting-edge cyber threat intelligence.

#CyberSecurity #DFIR #Velociraptor #Ransomware #LockBit #Warlock #Babuk #ThreatIntel #Storm2603 #Infosec #IncidentResponse #ThreatHunting #TechNadu #CyberAwareness

Qantas Customer Data Was Published After the July Cyber Breach, Impacting 5 Million People
2025-10-11

🚨 Velociraptor DFIR exploited in LockBit ransomware attacks.

Huntress and Cisco Talos link Storm-2603 to a new campaign abusing outdated Velociraptor builds for privilege escalation, lateral movement, and ransomware deployment.

The crew reportedly used SharePoint exploits (ToolShell) and domain admin creation before dropping LockBit, Warlock, and Babuk payloads.

💬 Are open-source DFIR tools the next frontier for living-off-the-land tactics?

Follow @technadu for more cutting-edge cyber threat intelligence.

#CyberSecurity #DFIR #Velociraptor #Ransomware #LockBit #Warlock #Babuk #ThreatIntel #Storm2603 #Infosec #IncidentResponse #ThreatHunting #TechNadu #CyberAwareness

Hackers Turn Velociraptor DFIR Tool Into Weapon in LockBit Ransomware Attacks
2025-10-09

They’re turning the tables—hackers are hijacking Velociraptor (a tool meant to catch them) to launch sneaky ransomware and double-extortion attacks. Just when you thought defenders had it all figured out, the game has changed.

thedefendopsdiaries.com/attack

#velociraptor
#ransomware
#dfir
#cve20256264
#cybersecurity
#threatactors
#doubleextortion
#infosec
#lockbit
#babuk

2025-04-06

HellCat strongly defended the authorship of the attacks, avoiding any ambiguity in credit distribution among its members.
"Am I supposed to prove my attacks? If so, just wait for the deadline to end and download the data—nothing more. We already have a profile."

suspectfile.com/hellcat-rey-an

#HellCat #Rey #Babuk #Orange #Infosec #Data_Breach #Ransomware #Lies

2025-04-04

Auf ihrer Darknet-Website gab die Babuk-Ransomware-Gruppe bekannt, dass sie angeblich rund 750 GB Daten sowie E-Mail-Zugangsdaten von #Rheinmetall Defence gestohlen hat. Insgesamt soll es sich dabei um 1400 Dateien handeln. Zu den gestohlenen Daten zählen laut #Babuk Militärverträge, E-Mails, Geschäftstransaktionen des Unternehmens, Details und Bilder von Produkten sowie viele weitere Informationen.

Weitere Infos und Screenshots gibt es hier:
teufelswerk.net/die-babuk-rans

2025-04-04

Die Babuk Ransomware Gruppe (babuk-bjorka) hat heute auf ihrer Website im Darknet bekanntgegeben, dass sie Rheinmetall Defence (rheinmetall.com) gehackt hat.

#babuk #babukbjorka #ransomware #ransom #rheinmetall #gehackt #hack #hacker #rheinmetalldefence #cybersecurity #itsicherheit #leaksdata #datenschutz #militar

Screenshot von der Darknet Website der Babuk Ransomware Gruppe, auf der unter der Überschrift "Leaks Data" der Eintrag "rheinmetall.com (Rheinmetall Defence)" mit Datum vom 04.04.2025 zu sehen ist.
2025-04-03

New post from #Babuk-Bjorka : Rheinmetall.Com (Rheinmetall Defence)
More at : ransomlook.io/group/Babuk-Bjor #Ransomware

2025-04-03

New post from #Babuk-Bjorka : Secret Plans Of Indian Army
More at : ransomlook.io/group/Babuk-Bjor #Ransomware

2025-04-03

New post from #Babuk-Bjorka : Bangladesh Armed Forces (Bangladesh Army)
More at : ransomlook.io/group/Babuk-Bjor #Ransomware

2025-04-03

New post from #Babuk-Bjorka : Saudi Arabian Military And Government Internal Center
More at : ransomlook.io/group/Babuk-Bjor #Ransomware

2025-04-03

New post from #Babuk-Bjorka : Hellenic Airforce
More at : ransomlook.io/group/Babuk-Bjor #Ransomware

2025-04-03

New post from #Babuk-Bjorka : Turkish Defense Military
More at : ransomlook.io/group/Babuk-Bjor #Ransomware

2025-04-03

New post from #Babuk-Bjorka : Gangotreehomes.Com (Realestate)
More at : ransomlook.io/group/Babuk-Bjor #Ransomware

2025-04-03

New post from #Babuk-Bjorka : Iran Gas Service System
More at : ransomlook.io/group/Babuk-Bjor #Ransomware

2025-04-03

New post from #Babuk-Bjorka : Kfar Hatta Medical Center - Lebanon
More at : ransomlook.io/group/Babuk-Bjor #Ransomware

2025-04-03

New post from #Babuk-Bjorka : Zalora.Sg (Singapore Shopping)
More at : ransomlook.io/group/Babuk-Bjor #Ransomware

2025-04-03

New post from #Babuk-Bjorka : Polizia Italia Mail Access
More at : ransomlook.io/group/Babuk-Bjor #Ransomware

2025-04-03

New post from #Babuk-Bjorka : Ezbuy.Sg (Singapore Shopping)
More at : ransomlook.io/group/Babuk-Bjor #Ransomware

2025-04-02

New post from #Babuk-Bjorka : Dardoc.Com
More at : ransomlook.io/group/Babuk-Bjor #Ransomware

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst