Ransomware Group intelligence
Booba Project
ActiveTrack Booba Project with 34 published victims and 3 known leak locations in a single intelligence view.
Overview
Booba Project is tracked by Breach House as a ransomware group with 34 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Up checked 7d ago | d77tnb4bkmj3e366msrzllnwsi2t5e54e4yqh7zm7y5hlfwugnwzswad.onion |
| Leak location 1 | Onion service | Up checked 7d ago | 7t3zi3e7ki6iseun77ofqtr6wmbpgnpc2ada6gstcxp54lw6q2zb7jad.onion |
| Leak location 2 | Onion service | Down checked 7d ago | eazk7las3xsvsyxgww3jgzammqjevso2ydnmlopdhl3u2muyrmmilrqd.onion |
Top Activity Sectors (10)
Typical Attacks (13)
▼MITRE ATT&CK does not currently catalogue Booba Project, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: Booba Project executes malicious payloads through PowerShell scripts injected into legitimate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1569.002 Service Execution Execution
What they do: Booba Project executes ransomware binaries through Windows Service installation to ensure persistence.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: Booba Project adds malicious entries to Registry Run Keys to maintain persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Booba Project disables antivirus tools by terminating security processes and modifying Windows Defender settings.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: Booba Project deletes Volume Shadow Copy and backup directories via vssadmin commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: Booba Project uses file and directory discovery via PowerShell to enumerate critical data paths before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1614.001 System Language Discovery Discovery
What they do: Booba Project performs system language discovery to tailor encryption patterns for regional data formats.
What that means: Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Booba Project moves laterally via SMB/Windows Admin Shares to encrypt networked assets across manufacturing systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1560.001 Archive via Utility Collection
What they do: Booba Project archives stolen data using built-in utility commands before exfiltration via C2 channels.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1041 Exfiltration Over C2 Channel Exfiltration
What they do: Booba Project exfiltrates victim data through encrypted C2 channels before deploying ransomware payloads.
What that means: Adversaries may steal data by exfiltrating it over an existing command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: Booba Project encrypts victim files using custom symmetric encryption routines targeting business documents and backups.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Booba Project stops critical Windows services like backup and monitoring utilities using net stop commands.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Booba Project inhibits system recovery by corrupting restore points and disabling backup services.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (34)
Search, filter and paginate the victim timeline for Booba Project. Showing 1–34 of 34.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Davroc id32073 View details | United Kingdom | IT | — | |
|
www.davroc.co.uk operates within the IT sector based in the United Kingdom. The entity is cataloged in this threat-intelligence index as a ransomware victim linked to the Booba Project threat actor. This listing type indicates that the organization was targeted by ransomware activity associated with this specific adversary group. The entry serves to inform security analysts and stakeholders about potential exposure within the IT sector in the UK, contributing to broader threat awareness without disclosing unconfirmed incident details. The association with Booba Project underscores the need for vigilance among organizations in similar sectors. |
|||||
| Ransomware | Davroc id32073 View details | United Kingdom | IT | — | |
|
Furniture and Home Furnishings Manufacturing Stolen data: 15 GB. |
|||||
| Ransomware | Chernyy & Associates id32074 View details | Russian Federation | Finance / Legal / Insurance | — | |
|
www.chernyy-law.com operates within the Russian Finance, Legal, and Insurance sectors, providing specialized legal and professional services aligned with these industries. As cataloged in the threat-intelligence index, this entity is classified as a ransomware victim linked to the Booba Project threat actor. The Booba Project is recognized for targeting organizations across critical infrastructure sectors including finance, legal services, and insurance. This listing reflects the entity's documented association with this specific cyber threat campaign without disclosing unverified incident details. The entry serves to inform stakeholders of the exposure profile and sector concentration relevant to ongoing threat monitoring and risk assessment. |
|||||
| Ransomware | Chernyy & Associates id32074 View details | Russian Federation | Finance / Legal / Insurance | — | |
|
Law Practice Stolen data: 67 GB. |
|||||
| Ransomware | Country-Wide Insurance id32070 View details | United States | IT | — | |
|
www.cwico.com operates within the IT sector and is headquartered in the United States, providing technology-focused services and solutions. The entity is cataloged in this threat-intelligence index specifically as a ransomware victim linked to the Booba Project threat actor. This classification reflects the cybersecurity context in which the organization was identified within the Booba Project's operational footprint. The listing type underscores the nature of the relationship between the entity and the associated threat actor without disclosing unverified incident details. This entry serves threat analysts and security professionals monitoring ransomware activity across IT sectors. |
|||||
| Ransomware | Country-Wide Insurance id32070 View details | United States | IT | — | |
|
Insurance Stolen data: 92 GB. |
|||||
| Ransomware | Federis Abogados id32071 View details | Mexico | Finance / Legal / Insurance | — | |
|
www.federisabogados.com operates within the Finance, Legal, and Insurance sectors and is located in Mexico. The entity provides legal and professional advisory services aligned with regulated financial and legal service delivery. In the threat-intelligence index, it is cataloged as a ransomware victim associated with the Booba Project threat actor. This listing reflects its inclusion in the index under the ransomware victim classification, contextualized by its geographic and sectoral profile. No specific incident details, such as data stolen, ransom demands, or breach confirmation, are asserted in this description. |
|||||
| Ransomware | Federis Abogados id32071 View details | Mexico | Finance / Legal / Insurance | — | |
|
Law Practice Stolen data: 61 GB. |
|||||
| Ransomware | Betz Industries id31077 View details | United States | Manufacturing / Engineering | — | |
|
Betz Industries is a US-based company operating in the manufacturing and engineering sector, providing various products and services. The company is involved in the design, development, and production of industrial equipment and components. Betz Industries was listed as a ransomware victim associated with Booba Project. |
|||||
| Ransomware | Betz Industries id31077 View details | United States | Manufacturing / Engineering | — | |
|
Industrial Machinery Manufacturing Stolen data: 7 GB. |
|||||
| Ransomware | Oklahoma Manufacturing Alliance id31013 View details | United States | IT | — | |
|
Okalliance.com is an IT company based in the US, providing various IT services. The company operates in the IT sector, offering services to clients in the United States. Okalliance.com was listed as a ransomware victim associated with Booba Project |
|||||
| Ransomware | Oklahoma Manufacturing Alliance id31013 View details | United States | IT | — | |
|
Business Consulting and Services Stolen data: 10 GB. |
|||||
| Ransomware | Incredible Technologies id31008 View details | United States | IT | — | |
|
ItsGames operates in the IT sector in the United States, providing various services. The company's specific offerings are not well-documented. ItsGames is generally involved in the IT industry. It was listed as a ransomware victim associated with Booba Project |
|||||
| Ransomware | Incredible Technologies id31008 View details | United States | IT | — | |
|
Entertainment Providers Stolen data: 25 GB |
|||||
| Ransomware | Zynex id30827 View details | Switzerland | Healthcare / Pharma | ||
|
Zynex CH is a Swiss company operating in the healthcare and medicine sector. The company is based in Switzerland and provides various medical services and products. Zynex CH was listed as a ransomware victim associated with Booba Project |
|||||
| Ransomware | Zynex id30827 View details | Switzerland | Healthcare / Pharma | ||
|
IT Services and IT Consulting Stolen data: 1.4 GB |
|||||
| Ransomware | Zynex id30828 View details | Switzerland | Healthcare / Pharma | ||
|
Zynex is a Swiss company operating in the healthcare and pharmaceutical sector, providing various services and offerings. The company is based in Switzerland and serves the local market with its healthcare products. Zynex was listed as a ransomware victim associated with Booba Project |
|||||
| Ransomware | Zynex id30828 View details | Switzerland | Healthcare / Pharma | ||
|
IT Services and IT Consulting Stolen data: 1.4 GB |
|||||
| Ransomware | Pelli Clarke Pelli Architects id30746 View details | United States | Construction / Real Estate | — | |
|
PCP Architects is a US-based company operating in the construction and real estate sector, providing architectural services. The company is involved in various projects, contributing to the development of the US construction industry. PCP Architects was listed as a ransomware victim associated with Booba Project. |
|||||
| Ransomware | Pelli Clarke Pelli Architects id30746 View details | United States | Construction / Real Estate | — | |
|
Architecture and Planning Stolen data: 45 GB. |
|||||
| Ransomware | Jani-King id30581 View details | United States | Services | — | |
|
Janiking is a US-based company operating in the services sector, providing various offerings to its customers. As a services company, Janiking likely provides support and maintenance services to its clients. Janiking was listed as a ransomware victim associated with Booba Project |
|||||
| Ransomware | Jani-King id30581 View details | United States | Services | — | |
|
Facilities Services Stolen data: 12 GB. |
|||||
| Ransomware | URA Group id30318 View details | Russian Federation | Manufacturing / Engineering | — | |
|
Uragroup.com is a company based in Russia, operating in the manufacturing and engineering sector. The company likely provides various products and services related to its sector. Uragroup.com was listed as a ransomware victim associated with Booba Project |
|||||
| Ransomware | URA Group id30318 View details | Russian Federation | Manufacturing / Engineering | — | |
|
Stolen data: 5 GB |
|||||
| Ransomware | Upstaging id30287 View details | United States | Transportation / Travel / Logistics | — | |
|
Upstaging.com is a company operating in the transportation, travel, and logistics sector in the United States. The company provides various services to support the logistics and transportation needs of its clients. Upstaging.com was listed as a ransomware victim associated with Booba Project |
|||||
| Ransomware | Upstaging id30287 View details | United States | Transportation / Travel / Logistics | — | |
|
Entertainment Providers Stolen data: 10 GB |
|||||
| Ransomware | Frosty Acres Brands id30276 View details | United States | Agriculture / Food | — | |
|
Frostyacres.com is an online presence for a US-based company operating in the agriculture and food sector. The company likely provides products or services related to farming, food production, or distribution. As a ransomware victim, frostyacres.com was listed in association with the Booba Project threat actor. |
|||||
| Ransomware | Frosty Acres Brands id30276 View details | United States | Agriculture / Food | — | |
|
Food & Beverages Stolen data: 8 GB |
|||||
| Ransomware | Telewave, Inc. id30277 View details | United States | Telecommunications | — | |
|
Telewave is a US-based company operating in the telecommunications sector, providing various products and services. The company offers solutions for wireless network operators, public safety agencies, and other organizations. Telewave was listed as a ransomware victim associated with Booba Project |
|||||
| Ransomware | Telewave, Inc. id30277 View details | United States | Telecommunications | — | |
|
Telecommunications Stolen data: 37 GB Telewave.io will exhibit at Booth #1146 at APCO 2026 – Association of Public Safety Communications Officials in San Antonio, Texas! They will have what to tell about. |
|||||
| Ransomware | Fonsan id30278 View details | Spain | Other | — | |
|
Fonsan is a company based in Spain, operating in the other sector. The company likely provides various services, although specific details about its offerings are not well-documented. Fonsan was listed as a ransomware victim associated with Booba Project |
|||||
| Ransomware | Fonsan id30278 View details | Spain | Other | — | |
|
Construction Stolen data: 23.4 GB |
|||||
| Ransomware | Nfinite 9000 S.L. id30279 View details | Spain | IT | — | |
|
nfinite9000.com is a company operating in the IT sector, based in Spain. The company likely provides various IT services, given its sector classification. nfinite9000.com was listed as a ransomware victim associated with Booba Project |
|||||
| Ransomware | Nfinite 9000 S.L. id30279 View details | Spain | IT | — | |
|
IT Services and IT Consulting Stolen data: 3 GB |
|||||