Booba is a ransomware and extortion group that has claimed attacks against universities, companies, and local governments in the United States. Its ransomware supports Windows and Linux systems. The operation combines file encryption with data theft and maintains a victim leak site and a ransom-negotiation process. Booba claimed responsibility for an attack on the University of Illinois Chicago’s College of Medicine that temporarily disrupted access to some systems. The university confirmed that information was stolen from college servers, although the volume claimed by Booba was not independently confirmed. The university’s main network and patient care delivery were unaffected. Booba also claimed an attack against Merrimack County, New Hampshire, where a confirmed cyberattack temporarily prevented dispatchers from accessing state criminal information. No country of origin or state sponsorship has been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for the ransomware attack against the University of Illinois Chicago College of Medicine and claimed theft of 344 GB of data. UIC confirmed unauthorized access and data theft, but its investigation remains ongoing. The group reportedly emerged at the end of July and has claimed 49 attacks. SentinelOne suggested it may be a rebrand of Frag; that relationship is not confirmed.
Booba claimed responsibility for a ransomware attack affecting the University of Illinois Chicago's College of Medicine and claimed to have stolen 344 GB of data. The university confirmed temporary system disruption, but the extent of data theft remains under investigation; systems were restored and patient care was unaffected. The group also reportedly targeted Merrimack County, New Hampshire, disrupting access to critical criminal data. The content describes Booba as a suspected rebranding of Frag, not a confirmed attribution.
Booba claimed responsibility for the ransomware attack on the University of Illinois Chicago's College of Medicine and alleged theft of 344 GB of data. UIC confirmed information theft and temporary system disruption, but the content does not independently verify Booba's attribution or claimed theft volume. The group reportedly emerged at the end of July and has claimed 49 attacks, targeting companies and small county governments, including Merrimack County, New Hampshire. A SentinelOne researcher assessed that Booba appears to be a rebrand of Frag ransomware based on similarities in leak-site design and negotiation flow.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.