Skip to content

Booba Project

Ransomware Group1 claimLast activity:
Also known as:
  • Booba Team · Alias

Overview

Booba Project is an emerging ransomware and data-extortion operation that also identifies itself as Booba Team. Ransomware.live first recorded a public victim post on July 6, 2026, and continued to monitor the group as active in August. The available evidence supports a financially motivated operation, but it does not identify the operators, establish their jurisdiction or show that Booba Project runs an affiliate program.

Activity and targeting

Ransomware.live recorded 12 Booba Project victim posts first discovered from July 6 through July 31, 2026. Eight named U.S. organizations, two were in Spain, and one each was in Switzerland and Russia. The claimed victims included professional-services, technology, manufacturing, health care, agriculture and food-production organizations. This small, early sample indicates broad commercial targeting more strongly than a stable sector or geographic specialization.

The monitored entries are actor claims, not 12 independently confirmed incidents, and their advertised stolen-data volumes should not be treated as verified. In one independently reported case, Oklahoma Manufacturing Alliance confirmed a contained ransomware event affecting two computers and part of its network. News 9 reported that Booba Project claimed 10 GB of stolen data and threatened publication, while the organization said it found no evidence of information removal or compromised client records. That conflict leaves attribution and exfiltration unconfirmed.

Methods and operational characteristics

The operation maintains separate monitored Tor services for victim publication, negotiation chat and file storage. Its ransom note claims that data was extracted before systems were locked, offers a working decryptor and test before payment, directs victims to a Tor chat portal and warns that independent recovery attempts may damage files. Those statements document the group’s claimed double-extortion and negotiation model; they do not independently validate the malware’s encryption design, exfiltration capability or decryptor.

Public evidence does not establish how Booba Project obtains access, persists, moves laterally, evades defenses or deploys encryption. It also does not identify a malware family, encryption algorithm, loader, command-and-control framework, credential source or verified relationship with an access broker. Techniques observed in the Oklahoma Manufacturing Alliance incident cannot be generalized to the group.

What type of group is it?

Booba Project is best characterized provisionally as a financially motivated ransomware group using encryption and threatened data disclosure for leverage. The Booba Team alias comes from the operation’s own monitored ransom note. The evidence does not establish ransomware-as-a-service operations, an affiliate structure, state sponsorship or an ideological motive. Its infrastructure and claimed victim activity establish a public extortion operation, but incident-level attribution still requires independent corroboration.

Incident claim

Oklahoma Manufacturing Alliance Ransomware Incident

Incident date: Source: ransomware.livePublished: Discovered:

Claim details

Booba Project claimed it breached Oklahoma Manufacturing Alliance, obtained 10 gigabytes of data and would release the material if a ransom was not paid. News 9 attributed the claim to a cybersecurity consultant who observed the group’s post. OMA said it found no evidence that information was removed and that client records were maintained on a separate system not involved in the incident. The claim is recorded as an allegation, not confirmed attribution or confirmed data theft.

Impacted organizations

Impacted location

Sources