The Babuk2 ransomware group has been spotted issuing extortion demands based on false claims and recycled data from previous breaches.
See also: Developer of LockBit ransomware extradited to the US

This revelation comes from recent research conducted by the Halcyon RISE team, shedding light on a worrying trend in the cybercrime sector .
The Babuk2 group, also known as Babuk-Bjorka, has caused a stir with public announcements of multiple attacks. However, these claims have not been confirmed by third parties or by the alleged victims, raising doubts about the authenticity of these incidents.
Halcyon analysts found that the group appears to be leveraging data from previous breaches to support its extortion claims. Many of the alleged victims had previously been targeted by other ransomware groups, including RansomHub, FunkSec, LockBit , and even the original Babuk.
What makes this situation particularly worrisome is the absence of evidence to support any new, active encryption or recent network intrusions.
See also: Decrypt Linux/ESXi Akira Ransomware files without paying ransom
Analysis by the Halcyon RISE team indicates that the data used is recycled from previous incidents, despite Babuk2's statements that it has carried out multiple attacks in early 2025.

The Babuk2 ransomware operation appears to be capitalizing on the reputation of the original Babuk ransomware, which was active in 2021. The group is seeking to establish its credibility in the cybercriminal world by using the Babuk name. The administrator, known as Bjorka, was active on various forums and Telegram, with a history of involvement in other data breaches and extortion attempts.
This tactic of issuing false extortion demands poses significant risks to businesses, both financially and in terms of reputation. Even if the claims of an attack are false, the mere threat can pressure organizations into paying ransoms or investing in unnecessary remediation measures.
See also: New SuperBlack ransomware exploits Fortinet vulnerabilities
Protecting against ransomware attacks requires a strategy that combines prevention, detection, and remediation. Some key measures to protect against ransomware include:
- System and software updates
- Antivirus and firewall software
- Regular backups
- User training
- Restriction of access rights
- Blocking executable files from unknown sources
- Networks and remote access
- Isolation and containment of contamination
- Identification of suspicious behavior
By following these measures, you significantly reduce the risk of falling victim to ransomware and other malicious attacks.
Source: cybersecuritynews
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
