Actor Profile

🏹 bluebox — Ransomware

Bluebox is a data extortion group that emerged in December 2024, employing double-extortion tactics against victims primarily in France, Sweden, and the French Caribbean, and threatening to notify data protection authorities to add regulatory pressure on victims.

Classification

Ransomware

Leak-site victims

3
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (3)

VictimCountryPublishedDomain
Groupe-fimar FR 2024-12-17T23:44:58.505679+00:00 groupe-fimar.com
PH ARCHITECTURE FR 2024-12-11T12:44:57.550177+00:00 pharchitecture.fr
Westerstrand Urfabrik AB SE 2024-12-11T12:46:01.557279+00:00 westerstrand.se

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

📁 Case Management

+ New case from this

🏹 Add to case

Attach bluebox (Actor / APT) and pull all linked entities:

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php