Back to Intelligence

BOOBA PROJECT Ransomware Gang: 6 New Leak-Site Listings Targeting Healthcare, Education & Government — Sector Analysis & Detection Rules

SA
Security Arsenal Team
October 2, 2026
13 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-02 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims

BOOBA PROJECT Ransomware Gang: 6 New Leak-Site Listings Targeting Healthcare, Education & Government

Executive Summary

Security Arsenal's dark web monitoring observed BOOBA PROJECT publish six new listings on its .onion leak site across a 48-hour window (2026-10-01 through 2026-10-02). The listings name organizations in the Education, Healthcare, and Government & Defense sectors across the United States, Canada, and Brazil:

  • University of Illinois Chicago (Education, US) — listed 2026-10-02
  • Soni Medical Centre (Healthcare, CA) — listed 2026-10-02
  • EdgeEndo® USA (Healthcare, US) — listed 2026-10-02
  • Raleigh Family Medicine (Healthcare, US) — listed 2026-10-02
  • ASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C (Healthcare, US) — listed 2026-10-01
  • FUNAP - Fundação "Prof. Dr. Manoel Pedro Pimentel" (Government & Defense, BR) — listed 2026-10-01

Every one of these is a claim made by a criminal actor on its own infrastructure. None of these listings constitutes confirmation that any named organization was breached. However, the pattern itself — a concentrated burst of small-to-midsize healthcare entities plus education and government — is actionable intelligence regardless of whether any individual claim is verified. Defenders in these sectors should treat this as a sector-level warning and run the hunts in this briefing.

Sourcing & Verification

  • 0 of 6 listings were independently observed by a second leak-site crawler. All 6 listings are single-source, appearing only via ransomware.live monitoring of the gang's own infrastructure.
  • Inclusion in this briefing reflects the threat actor's claim only and is not confirmation of a breach. No corroboration tier available to us confirms an intrusion — only the organization itself or its regulator can do that.
  • A named organization may dispute the listing. A denial is likewise not proof the claim is false: disclosure obligations vary by jurisdiction, not every incident is reportable, and negotiations or investigations may be ongoing. Neither silence nor denial settles the question.
  • Security Arsenal will publish corrections as warranted and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — BOOBA PROJECT

Analyst note on attribution confidence: BOOBA PROJECT is a low-visibility actor in our tracking. Where public reporting is thin, we state what is observed versus inferred. The profile below blends observed leak-site behavior with TTPs typical of actors operating in this tier; items marked (inferred) should be treated as hypothesis, not established fact.

  • Aliases: None confirmed in our telemetry. The "PROJECT" suffix follows a naming convention seen among short-lived or rebranded RaaS affiliates — monitor for name rotation.
  • Operating model: Behaviorally consistent with a RaaS affiliate or small closed group (inferred). The burst-style posting cadence (6 listings in ~48 hours after a quiet period) suggests affiliate-driven operations where intrusions are batched and published together, often after a negotiation deadline passes.
  • Extortion model: Double extortion — leak-site publication implies data theft claims accompany encryption. The victim profile (clinics, medical groups) is consistent with actors that monetize sensitive PII/PHI as leverage.
  • Ransom demands: Not disclosed on the observed listings. For actors hitting organizations of this size, demands in the low-to-mid six figures (USD) are typical for the tier (inferred).
  • Initial access methods: No confirmed vector for any named victim. Actors in this tier most commonly rely on: (1) purchased access from initial access brokers (IABs), (2) exploitation of edge devices and remote services (VPN gateways, RDP), and (3) phishing with macro-laced or ISO/LNK payloads (inferred, sector-level).
  • Dwell time: Unconfirmed for this actor. Industry-wide, median dwell time for ransomware operations of this profile runs days to a few weeks, with exfiltration typically occurring 24–72 hours before detonation (sector-level baseline).

Current Campaign Analysis

Sector targeting

Healthcare dominates: 4 of 6 listings (Soni Medical Centre, EdgeEndo® USA, Raleigh Family Medicine, ASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C). The remaining two span Education (University of Illinois Chicago) and Government & Defense (FUNAP, BR). This is the classic "soft target, high-leverage data" profile — organizations holding PHI/PII with historically constrained security budgets and 24/7 operational pressure that increases payment likelihood.

Geographic concentration

US-heavy (4 of 6), with one Canadian and one Brazilian listing. The Brazilian government listing (FUNAP — a prison administration foundation) suggests opportunistic rather than region-locked operations, but the center of gravity is North American healthcare.

Victim profile

Mostly small-to-midsize organizations: specialty clinics, a medical device/dental supply firm, a family medicine practice, and a regional gastroenterology group. Revenue ranges for this profile typically fall between $5M–$150M (estimate based on sector and org type). The outlier is a large public university — a pattern consistent with RaaS ecosystems where different affiliates hit whatever access they can buy or brute-force.

Posting frequency / escalation

Only 6 postings in the gang's last 100 are recent — indicating a low-volume actor, with all six arriving in a single 48-hour burst. Burst publishing after silence usually means one of three things: (1) a batch of negotiations timed out simultaneously, (2) the actor is posturing to build reputation, or (3) a new affiliate onboarded with pre-staged access. All three suggest more listings may follow in the coming days.

CVE exposure — hypothesis only

We have no evidence tying any specific CVE to any specific listing above. However, defenders in the targeted sectors should assess exposure to the following actively exploited vulnerabilities (all on CISA KEV with confirmed ransomware use), as these represent the exact edge-access and management-plane weaknesses actors of this tier exploit:

  • CVE-2026-59310 — VMware vCenter path traversal (KEV 2026-08-18). Hypervisor management-plane compromise enables mass encryption — the highest-impact item on this list.
  • CVE-2026-63077 — JetBrains TeamCity deserialization (KEV 2026-08-05). CI/CD compromise enables supply-chain-style lateral spread and credential theft.
  • CVE-2026-20316 — Cisco Secure FMC hard-coded password (KEV 2026-07-29). Firewall management plane = network-wide visibility and policy control.
  • CVE-2026-50751 — Check Point Security Gateway improper authentication in IKEv1 (KEV 2026-06-08). Direct VPN gateway compromise — a top initial access vector.
  • CVE-2026-48027 — Nx Console embedded malicious code (KEV 2026-05-27). Developer-toolchain supply chain exposure.

Treat these as sector-level exposure hypotheses. Patch posture against KEV entries is the single highest-leverage control against opportunistic actors of this profile.

Detection Engineering

Sigma Rules

YAML
---
title: Suspicious RDP or VPN Logon Followed by Remote Service Execution
id: 8f3a2b11-b00b-4a11-9001-0b00ba000001
status: experimental
description: Detects remote logons (RDP/network) closely followed by service creation or remote execution artifacts, consistent with post-exploitation after VPN/RDP initial access as used by opportunistic ransomware affiliates.
author: Security Arsenal Threat Intelligence
date: 2026/10/02
references:
  - https://securityarsenal.com/darkside
logsource:
  product: windows
  category: security
detection:
  selection_logon:
    EventID: 4624
    LogonType:
      - 3
      - 10
  selection_exec:
    EventID:
      - 7045   # Service installed
      - 4697   # Service installed (Security)
  condition: selection_logon or selection_exec
falsepositives:
  - Administrative RDP sessions followed by legitimate software deployment
  - SCCM/Intune service pushes
level: medium
tags:
  - attack.initial_access
  - attack.t1133
  - attack.t1078
  - attack.t1543.003
---
title: PsExec or WMI-Style Lateral Movement Artifact Execution
id: 8f3a2b11-b00b-4a11-9001-0b00ba000002
status: experimental
description: Detects execution of PsExec-style services, WMI process creation, or renamed copies — lateral movement techniques commonly observed in pre-ransomware intrusion chains.
author: Security Arsenal Threat Intelligence
date: 2026/10/02
references:
  - https://securityarsenal.com/darkside
logsource:
  category: process_creation
  product: windows
detection:
  selection_psexec:
    Image|endswith:
      - '\PSEXESVC.exe'
      - '\PsExec.exe'
      - '\psexec64.exe'
  selection_wmi:
    ParentImage|endswith: '\WmiPrvSE.exe'
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\rundll32.exe'
  selection_remcom_paexec:
    Image|endswith:
      - '\RemComSvc.exe'
      - '\paexec.exe'
  condition: 1 of selection_*
falsepositives:
  - Legitimate admin tooling; baseline and allowlist known management hosts
level: high
tags:
  - attack.lateral_movement
  - attack.t1569.002
  - attack.t1047
  - attack.t1021.002
---
title: Pre-Encryption Staging - Shadow Copy Deletion or Mass Archive Creation
id: 8f3a2b11-b00b-4a11-9001-0b00ba000003
status: experimental
description: Detects Volume Shadow Copy deletion/resize and mass archive creation indicative of data staging and anti-recovery steps performed immediately before ransomware detonation.
author: Security Arsenal Threat Intelligence
date: 2026/10/02
references:
  - https://securityarsenal.com/darkside
logsource:
  category: process_creation
  product: windows
detection:
  selection_vss:
    Image|endswith:
      - '\vssadmin.exe'
      - '\wmic.exe'
      - '\bcdedit.exe'
      - '\wbadmin.exe'
      - '\diskshadow.exe'
    CommandLine|contains:
      - 'delete shadows'
      - 'shadowcopy delete'
      - 'resize shadowstorage'
      - 'delete catalog'
      - 'recoveryenabled no'
  selection_archive:
    Image|endswith:
      - '\7z.exe'
      - '\7za.exe'
      - '\rar.exe'
      - '\winrar.exe'
    CommandLine|contains:
      - ' a '
      - '-p'
  condition: selection_vss or selection_archive
falsepositives:
  - Backup software maintenance windows
  - Admin scripts for archive creation — tune by host and account
level: high
tags:
  - attack.impact
  - attack.t1490
  - attack.t1560.001
  - attack.collection

KQL — Microsoft Sentinel Hunt Query

Hunt for the pre-detonation kill chain: remote logon → new service/scheduled task → staging archive → shadow copy tampering, correlated on the same host within a 6-hour window.

KQL — Microsoft Sentinel / Defender
// BOOBA PROJECT / opportunistic-affiliate pre-ransomware staging hunt
// Correlates remote logon, persistence/service creation, archiving, and VSS tampering per host per 6h window
let window = 6h;
let RemoteLogons = SecurityEvent
| where TimeGenerated > ago(7d)
| where EventID == 4624 and LogonType in (3, 10)
| where Account !endswith "$"
| project LogonTime=TimeGenerated, Computer, Account, IpAddress, LogonType;
let ServiceInstalls = union isfuzzy=true
    (SecurityEvent | where EventID in (4697, 7045) | project T=TimeGenerated, Computer, ServiceName, Account),
    (WindowsEvent | where EventID == 7045 | project T=TimeGenerated, Computer, ServiceName=tostring(EventData.ServiceName), Account=tostring(EventData.SubjectUserName));
let SuspiciousProcs = SecurityEvent
| where TimeGenerated > ago(7d)
| where EventID == 4688
| where Process has_any ("vssadmin","wmic","bcdedit","wbadmin","diskshadow","7z.exe","7za.exe","rar.exe","winrar.exe","psexec","psexesvc")
   or CommandLine has_any ("delete shadows","resize shadowstorage","recoveryenabled no","delete catalog")
| project ProcTime=TimeGenerated, Computer, Process, CommandLine, Account;
let HostStages = SuspiciousProcs
| summarize StagingEvents=make_set(Process), FirstStage=min(ProcTime), LastStage=max(ProcTime), StageCount=count() by Computer, bin(ProcTime, window);
RemoteLogons
| summarize FirstLogon=min(LogonTime), LogonAccounts=make_set(Account), SourceIPs=make_set(IpAddress) by Computer, bin(LogonTime, window)
| join kind=inner (ServiceInstalls | summarize Services=make_set(ServiceName) by Computer, bin(T, window))
    on Computer, $left.LogonTime_window == $right.T_window
| join kind=inner HostStages on Computer, $left.LogonTime_window == $right.ProcTime_window
| project Computer, FirstLogon, LogonAccounts, SourceIPs, Services, StagingEvents, StageCount, FirstStage, LastStage
| sort by FirstStage asc;

Tune LogonType, the process list, and the join window for your environment; any host lighting up all three stages warrants immediate isolation.

Rapid Response Script — PowerShell

PowerShell
#Requires -RunAsAdministrator
<#
.SYNOPSIS
  Rapid triage for opportunistic-ransomware pre-staging indicators.
  Checks: exposed RDP, scheduled tasks (7d), new services (7d), VSS state,
  recent shadow copies, suspicious archives in user/temp dirs.
#>
param([int]$LookbackDays = 7)
$since = (Get-Date).AddDays(-$LookbackDays)
$report = [ordered]@{}

Write-Host "`n=== [1] RDP Exposure ===" -ForegroundColor Cyan
$rdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server').fDenyTSConnections -eq 0
$nla = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -ErrorAction SilentlyContinue).UserAuthentication
$report.RDPEnabled = $rdpEnabled; $report.NLAEnabled = ($nla -eq 1)
if ($rdpEnabled -and $nla -ne 1) { Write-Host "[!] RDP ENABLED WITHOUT NLA - high-risk exposure" -ForegroundColor Red }
Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue | Select-Object LocalAddress,LocalPort,State

Write-Host "`n=== [2] Scheduled Tasks created/modified in last $LookbackDays days ===" -ForegroundColor Cyan
Get-ScheduledTask | Where-Object { $_.Date -gt $since } |
  Select-Object TaskName, TaskPath, Date, @{n='Action';s={($_.Actions | ForEach-Object Execute) -join '; '}} | Format-List

Write-Host "`n=== [3] New services in last $LookbackDays days (Event 7045) ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{LogName='System'; Id=7045; StartTime=$since} -ErrorAction SilentlyContinue |
  Select-Object TimeCreated, @{n='Service';s={$_.Properties[0].Value}}, @{n='ImagePath';s={$_.Properties[1].Value}} | Format-List

Write-Host "`n=== [4] Volume Shadow Copy status ===" -ForegroundColor Cyan
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if (-not $shadows) { Write-Host "[!] NO shadow copies present - verify this is expected (anti-recovery indicator)" -ForegroundColor Red }
else { $shadows | Select-Object DeviceObject, InstallDate, VolumeName | Format-Table }

Write-Host "`n=== [5] VSS deletion / bcdedit tampering events (4688, last $LookbackDays days) ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4688; StartTime=$since} -ErrorAction SilentlyContinue |
  Where-Object { $_.Message -match 'vssadmin|bcdedit|wbadmin|diskshadow|delete shadows|resize shadowstorage|recoveryenabled' } |
  Select-Object TimeCreated, Message | Format-List

Write-Host "`n=== [6] Large recent archives (staging indicator) ===" -ForegroundColor Cyan
$paths = @("$env:PUBLIC","$env:TEMP","C:\Users")
foreach ($p in $paths) {
  Get-ChildItem $p -Recurse -Include *.zip,*.7z,*.rar -ErrorAction SilentlyContinue |
    Where-Object { $_.LastWriteTime -gt $since -and $_.Length -gt 50MB } |
    Select-Object FullName, @{n='SizeMB';s={[math]::Round($_.Length/1MB,1)}}, LastWriteTime
}

Write-Host "`n=== Triage complete. Any hits in sections 1,3,4,5 -> isolate host and escalate to IR. ===" -ForegroundColor Yellow

Incident Response Priorities

T-minus detection checklist (before encryption fires)

  1. Unusual archiving activity — 7z/RAR/WinRAR runs on servers, especially with password flags, outside backup windows.
  2. Shadow copy manipulation — vssadmin delete shadows, bcdedit ... recoveryenabled no, wbadmin delete catalog. This is the highest-fidelity "detonation imminent" signal.
  3. New services or scheduled tasks on servers within days of a remote logon from an unrecognized source IP.
  4. WMI/PsExec-style child processes spawning from WmiPrvSE.exe or PSEXESVC across multiple hosts in sequence.
  5. Large outbound transfers to unfamiliar cloud storage, MEGA-style endpoints, or VPS IPs — exfil typically precedes the leak-site post by days.
  6. EDR/AV tampering — disable attempts, exclusions added, or agents going silent.

Critical assets this actor profile typically prioritizes for exfiltration

For healthcare/education/government victims, expect targeting of: EHR/PHI databases and exports, patient billing records, student records (FERPA data), HR/payroll files, legal and insurance documents, email archives of executives, and domain controller NTDS.dit. The FUNAP listing suggests government case/prison administration records are also in scope for data-leverage extortion.

Containment actions, ordered by urgency

  1. Isolate any host showing two or more T-minus indicators — network-level isolation first, not shutdown (preserve memory).
  2. Disable suspected compromised accounts and force reset of any account with remote logons from unknown IPs; revoke sessions/tokens.
  3. Block egress to newly observed cloud storage/VPS destinations at the proxy/firewall.
  4. Protect backups — verify offline/immutable copies are intact and unreachable from production credentials now, not after detonation.
  5. Snapshot volatile evidence (memory, prefetch, USN journal, SRUM) on affected hosts before remediation.
  6. Engage IR retainer / external support if any staging indicator is confirmed — dwell time before detonation is commonly under 72 hours for this actor tier.

Hardening Recommendations

Immediate (24 hours)

  • Patch or mitigate CISA KEV entries matching your stack, prioritized: CVE-2026-59310 (vCenter), CVE-2026-50751 (Check Point VPN), CVE-2026-20316 (Cisco FMC), CVE-2026-63077 (TeamCity), CVE-2026-48027 (Nx Console). If patching is blocked, isolate the management interfaces from the network.
  • Enforce MFA on all remote access (VPN, RDP gateway, OWA, VDI). Unauthenticated or password-only edge access is the most common entry for actors of this tier.
  • Disable or restrict RDP from the internet; require VPN + NLA. Audit 3389 exposure today.
  • Deploy the Sigma rules above and run the KQL hunt across the last 7 days on all servers.
  • Verify backup immutability and alert on any shadow copy deletion event.
  • Block macro execution from internet-sourced Office files (Mark-of-the-Web policy) and restrict 7z/RAR to approved admin accounts.

Short-term (2 weeks)

  • Segment the network — isolate EHR/PHI stores, student record systems, and backup infrastructure into restricted VLANs with ACL'd east-west traffic. Small clinics should not have flat networks.
  • Remove local admin rights broadly; deploy LAPS; tier admin accounts so workstation compromise cannot reach server/DC credentials.
  • Deploy egress filtering and DNS sinkholing for uncommon cloud storage and newly registered domains to break exfil channels.
  • Stand up EDR with tamper protection across servers (not just endpoints), including hypervisor and backup hosts.
  • Centralize logging (Sysmon + Security events) into Sentinel or equivalent with ≥30-day hot retention; test the correlation hunt weekly.
  • Run tabletop exercises on the double-extortion scenario: encryption + PHI leak + regulator notification decision tree (HIPAA, state breach laws, PIPEDA, LGPD as applicable).

All named organizations in this briefing appear solely because a criminal actor listed them on its own leak site. These are unverified claims. Security Arsenal will update this briefing as corroboration or disputes emerge.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.