Boolka
- First seen
- 2022-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Last IoC activity
- 2026-07-22 02:03:07
- Profile updated
- 2026-07-07 12:16:21
Targeted industries: technology-and-telecommunications government-and-public-sector retail-and-hospitality
Context
Boolka is a threat actor known for infecting websites with malicious JavaScript scripts for data exfiltration. They have been carrying out opportunistic SQL injection attacks since at least 2022. Boolka has developed a malware delivery platform based on the BeEF framework and has been distributing the BMANAGER trojan. Their activities demonstrate a progression from basic website infections to more sophisticated malware operations.
Reports & references
- group-ib.com — Boolka (report)