🏹 bluebox — Ransomware
Bluebox is a data extortion group that emerged in December 2024, employing double-extortion tactics against victims primarily in France, Sweden, and the French Caribbean, and threatening to notify data protection authorities to add regulatory pressure on victims.
Classification
Ransomware
Leak-site victims
3
Ransomware.live
Associated IoCs
0
local intel
MITRE techniques
—
ATT&CK
Tracked
Yes
Ransomware.live
🔥 Leak-Site Victims (3)
| Victim | Country | Published | Domain |
|---|---|---|---|
| Groupe-fimar | FR | 2024-12-17T23:44:58.505679+00:00 | groupe-fimar.com |
| PH ARCHITECTURE | FR | 2024-12-11T12:44:57.550177+00:00 | pharchitecture.fr |
| Westerstrand Urfabrik AB | SE | 2024-12-11T12:46:01.557279+00:00 | westerstrand.se |
Source: Ransomware.live leak-site monitoring (cached, offline-safe).
📁 Case Management
🏹 Campaigns & malware
🏹 Add to case
🧩 Advanced Capabilities
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron