Quick Summary
AllegedExecutive Summary
Oklahoma Manufacturing Alliance, a United States-based manufacturing organization, was targeted by the Booba Project ransomware group. The listing appeared on the Booba Project’s dark web portal on July 28, 2026. SOCRadar’s Dark Web Monitoring service identified this entry, making it one of two U.S. entities named by the group on that date. The manufacturing sector is frequently targeted by ransomware operations due to the potential for significant operational disruption and the value of intellectual property. Booba Project has demonstrated a low-volume, targeted approach, claiming four other victims in the preceding 60 days. Their primary targets have been within the business services, technology, and manufacturing industries, predominantly in the United States, with a single victim identified in Russia. The inclusion of the Oklahoma Manufacturing Alliance aligns with the group’s recent pattern of targeting U.S. domestic entities within the manufacturing sector. Other U.S. entities recently claimed by Booba Project include Incredible Technologies, Pelli Clarke Pelli Architects, Jani-King, and URA Group.
Technical Analysis
A stealer-log check performed on February 2026 using the domain okalliance[.]com yielded a single credential record. This credential was an employee identity associated with the @okalliance[.]com domain, captured in conjunction with a third-party service URL. This finding suggests a potential workstation compromise, as such a pattern indicates a device that may have stored additional credentials beyond what was surfaced in this specific query. The record shows no rotation since its capture. The presence of an infostealer-log credential, especially one linked to a corporate domain and exhibiting a workstation-compromise profile, is a significant indicator of potential initial access for ransomware operations. Threat actors like Booba Project commonly leverage these logs. They source them from initial access brokers, validate the corporate credentials obtained, and then target access points such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While this specific log does not definitively confirm that Booba Project utilized this access method against Oklahoma Manufacturing Alliance, it represents the type of foothold that enables such intrusions. The single credential record and the associated workstation-compromise profile necessitate immediate action. Organizations should rotate the credentials for the affected account and conduct thorough forensic analysis on the compromised endpoint. Continuous monitoring of the dark web and stealer-log feeds is also crucial, as the observed record represents a minimum exposure, not the full extent of potential compromise. Further monitoring for alternate corporate domains and review of Microsoft 365, VPN, and remote-access activity is also recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.