Boolka

First seen
2022-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Last IoC activity
2026-07-22 02:03:07
Profile updated
2026-07-07 12:16:21

Targeted industries: technology-and-telecommunications government-and-public-sector retail-and-hospitality

Context

Boolka is a threat actor known for infecting websites with malicious JavaScript scripts for data exfiltration. They have been carrying out opportunistic SQL injection attacks since at least 2022. Boolka has developed a malware delivery platform based on the BeEF framework and has been distributing the BMANAGER trojan. Their activities demonstrate a progression from basic website infections to more sophisticated malware operations.

Reports & references

  • group-ib.com — Boolka (report)

External references