Booba Project is a financially motivated ransomware syndicate that emerged in July 2026. Utilizing a double-extortion business model, the group targets small-to-midsize industrial entities and employs a sophisticated infrastructure for leak disclosures and cryptocurrency ransom demands.
Key insights
•Leverages stolen credentials from infostealer logs for initial access.
•Exploits unpatched vulnerabilities in RDP services and legacy software.
•Neutralizes security mechanisms before executing ransomware payloads.
•Utilizes hidden onion services for negotiations and data leaks.
•Stages data exfiltration to cloud servers prior to encryption of hosts.
•Demands cryptocurrency payments while threatening public exposure of sensitive data.