Booba is a ransomware family with variants for Windows and Linux. It encrypts files and renames them with a family-specific extension. The associated Booba cybercriminal operation conducts ransom negotiations and maintains a data-leak site.
The operation has claimed attacks against companies, academic medical institutions, and local governments, including the University of Illinois Chicago’s College of Medicine and Merrimack County, New Hampshire. The university incident involved confirmed theft of information from college servers and temporary disruption of affected systems, although the university’s main network and patient care delivery remained unaffected. These incidents demonstrate the operation’s involvement in encryption-based extortion and data theft, without establishing that the ransomware executable itself performs exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Booba renames encrypted files with a ".booba" extension and has variants for both Windows and Linux systems.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware with Windows and Linux variants that appends the .booba extension to encrypted files. Its operators claimed the attack on the University of Illinois Chicago's College of Medicine and alleged theft of 344 GB of data. UIC confirmed data theft and temporary system disruption, but the claimed volume was not independently confirmed in the content. A researcher assessed that Booba appears to be a rebrand of Frag, based on leak-site styling and negotiation practices.
Ransomware associated with the Booba gang, which claimed responsibility for the University of Illinois Chicago College of Medicine attack and alleged theft of 344 GB of data. The attack temporarily disrupted systems; patient care was unaffected, and the extent of data theft remains under investigation. The content describes a suspected connection to Frag ransomware, .booba file extensions, and Linux and Windows variants.
Ransomware associated with the Booba gang, which claimed responsibility for the University of Illinois Chicago College of Medicine attack and alleged theft of 344 GB of data. It renames encrypted files with the .booba extension and reportedly has Linux and Windows variants. Researchers suspect it is a rebrand of Frag, based on similarities in leak-site style and negotiation flow; this relationship is not confirmed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.