Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

Booba Project Ransomware Group

Ransomware group profile

15Victims
RussiaSource country
48Impact score

Description

Booba Project is a financially motivated ransomware syndicate that emerged in July 2026. Utilizing a double-extortion business model, the group targets small-to-midsize industrial entities and employs a sophisticated infrastructure for leak disclosures and cryptocurrency ransom demands.

Key insights

  • Leverages stolen credentials from infostealer logs for initial access.
  • Exploits unpatched vulnerabilities in RDP services and legacy software.
  • Neutralizes security mechanisms before executing ransomware payloads.
  • Utilizes hidden onion services for negotiations and data leaks.
  • Stages data exfiltration to cloud servers prior to encryption of hosts.
  • Demands cryptocurrency payments while threatening public exposure of sensitive data.

Threat Level & Status Breakdown

For Booba Project · Based on incidents in selected period

3.9threat level
Aggressiveness10/ 10
Lethality0/ 10
Criticality1.4/ 10

Status Breakdown

Claimed100.0%15
First seenJun 2026
Last seenJul 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedAug 27, 2026

Recent activity

Monthly attack count for Booba Project in the selected period

15Total attacks
11peak in Jul
7.5avg / month
↑ 7 vs first month
JunJul036912

No intelligence data for this group.

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for Booba Project

Defense Evasion

T1562

Impair Defenses

Execution

T1047

Windows Management Instrumentation

Impact

T1486

Data Encrypted for Impact

T1490

Inhibit System Recovery

Lateral Movement

T1080

Taint Shared Content

T1021

Remote Services

T1021.001

Remote Desktop Protocol

Other

T1041

T1041

T1561

T1561

Persistence

T1078

Valid Accounts

Victims(23)

Otherupstaging.com
Claimed
2 days ago
Energy & Utilitiesuragroup.com
Claimed
2 days ago
United StatesOtherjaniking.com
Claimed
2 days ago
United StatesTechnologypcparch.com
Claimed
2 days ago
Government & Defensetelewave.com
Claimed
2 days ago
Healthcarezynex.com
Claimed
2 days ago
Otherfrostyacres.com
Claimed
2 days ago
RussiaProfessional Serviceschernyy-law.com
Claimed
4 days ago
United KingdomTechnologydavroc.co.uk
Claimed
4 days ago
United StatesFinancial Servicescwico.com
Claimed
4 days ago
MexicoProfessional Servicesfederisabogados.com
Claimed
4 days ago
United StatesManufacturingbetzindustries.com
Claimed
28 days ago
United StatesManufacturingokalliance.com
Claimed
about 1 month ago
United StatesTechnologyitsgames.com
Claimed
about 1 month ago
SwitzerlandHealthcarezynex.ch
Claimed
about 1 month ago
Claimed
about 2 months ago
Claimed
about 2 months ago
Claimed
about 2 months ago
Claimed
about 2 months ago
United StatesProfessional Servicesupstaging.com
Claimed
about 2 months ago

Page 1 of 2

Affected countries(6)

Countries where this group has been reported to target or leak victims.