Quick Summary
AllegedExecutive Summary
Pelli Clarke Pelli Architects, a business services firm based in the United States, has been identified as a victim by the Booba Project ransomware group. The listing was published on their dark web portal on July 22, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. As a company specializing in architecture and design, Pelli Clarke Pelli Architects operates within a digital ecosystem that includes project documentation and associated design software. The Booba Project group is characterized as a low-volume operator, with this incident marking one of a limited number of claims made on their leak site, suggesting their operational profile is still developing. In the 60 days preceding this listing, Booba Project claimed two additional victims, indicating a focused and relatively small operational footprint. Their targeting appears to be concentrated within the business services sector, with recent victims spanning the United States and Russia. Previous entities claimed by Booba Project, such as Jani-King and URA Group, also fall under the business services industry. Consequently, Pelli Clarke Pelli Architects aligns with the group’s apparent primary targeting pattern, rather than representing an outlier.
Technical Analysis
SOCRadar’s analysis of Pelli Clarke Pelli Architects’ domain, specifically pcparch.com, revealed a limited exposure associated with stealer-log telemetry. The query returned a single record, which identified a corporate username on a third-party Software as a Service (SaaS) platform used for design software. This record was classified as indicative of a corporate user on an external service and is more suggestive of a workstation compromise rather than direct access into the firm’s internal network infrastructure. The telemetry did not uncover any high-value credentials related to email, VPN, or other critical endpoints, reinforcing the indication of risk primarily at the workstation level. Furthermore, the log date predates the data’s indexing by several months, and the solitary record does not offer sufficient information to assess credential reuse or persistence. For threat actors like the Booba Project, credentials harvested via infostealers can be a key entry vector. Threat actors or initial access brokers often acquire these logs from underground marketplaces, validate the captured corporate credentials, and subsequently use them to gain access to corporate services. The single third-party credential identified in this incident does not definitively confirm its use by Booba Project. Given that the group’s operational tactics are not yet extensively documented, this finding should be considered a lead for workstation triage rather than a confirmed initial access method. Security teams should investigate the affected endpoint, rotate the exposed account’s credentials, and maintain continuous monitoring of the domain, treating this limited sample as a point of interest rather than definitive proof of compromise or exculpation.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.