Back to Intelligence

BOOBA PROJECT Ransomware Group: 6 New Leak-Site Listings Across Government, Healthcare & Education — Sector Analysis & Detection Rules

SA
Security Arsenal Team
September 23, 2026
14 min read

Classification: TLP:CLEAR | Publication Date: 2026-09-24 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims

BOOBA PROJECT Ransomware Group: 6 New Leak-Site Listings Across Government, Healthcare & Education

Executive Summary

Security Arsenal's dark web monitoring has observed six new listings published to the BOOBA PROJECT ransomware group's .onion leak site between 2026-09-22 and 2026-09-23. The group claims to have compromised organizations spanning government & defense, healthcare, education, and other sectors across the United States, Italy, and Moldova. Every one of these listings is currently single-source only — no second independent crawler has corroborated that the postings exist, and no listing on a criminal leak site constitutes confirmation of an actual breach.

Security teams in the affected sectors — particularly U.S. county-level government, regional healthcare providers, and K-12/higher education — should treat this campaign as a pre-positioning warning: the sector and geography pattern aligns with known initial-access exposure in VMware vCenter, JetBrains TeamCity, and perimeter VPN/firewall appliances currently listed in CISA's Known Exploited Vulnerabilities catalog. Detection content is provided below to hunt for pre-encryption staging behavior consistent with double-extortion tradecraft.

Sourcing & Verification

  • 0 of 6 listings were independently observed by a second leak-site crawler; 6 of 6 appear on a single source only (ransomware.live aggregation). Single-source status means we cannot yet rule out scraping error, gang misattribution, or a fabricated listing.
  • Inclusion in this briefing reflects the threat actor's claim only. It is not confirmation that any named organization suffered a breach, and nothing in this data tier can establish that.
  • A named organization may dispute the listing, and a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction and sector, and not every incident is legally reportable — so neither public silence nor an outright denial settles the question either way. Only the organization or its regulator can confirm or refute an incident.
  • Security Arsenal will publish corrections to this briefing if any listing is withdrawn, disputed, or corroborated. We welcome contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — BOOBA PROJECT

Attribution caveat: BOOBA PROJECT is a low-signature operation in open-source reporting. The following profile reflects observable leak-site behavior and tradecraft patterns common to comparable operations; where reliable group-specific intelligence does not exist, we say so rather than guess.

  • Aliases / rebranding: No confirmed aliases are associated with this name in public reporting. The "PROJECT" naming convention and the sudden burst of multi-sector postings are consistent with either a new entrant or a rebrand of a fragmented operation post-takedown — a common pattern after major RaaS disruptions. Treat attribution as provisional.
  • Operating model: Unconfirmed. The compressed publishing cadence (6 listings in ~48 hours) and the mixed-sector, mixed-geography victimology are characteristic of a Ransomware-as-a-Service (RaaS) affiliate model, where multiple operators with different access sources post victims to a shared leak site. A closed-group model cannot be ruled out at this stage.
  • Ransom demands: No verified demand figures exist for this group. Comparable mid-tier operations targeting county government and regional healthcare typically open demands in the low-to-mid six figures (USD), scaling against perceived ability to pay and cyber-insurance coverage.
  • Initial access methods (sector-level hypothesis): No forensic evidence ties BOOBA PROJECT to a specific vector for any named listing. However, the gang's victim profile overlaps heavily with organizations known to be exposed via: (1) unpatched perimeter appliances (VPN concentrators, firewall management planes), (2) virtualization management layers (vCenter), (3) CI/CD infrastructure (TeamCity), and (4) phishing-led credential theft against under-resourced IT teams in municipal government and school districts.
  • Double extortion: The existence of a dedicated leak site with named listings is itself evidence of a name-and-shame / double-extortion model — data theft threatened before or alongside encryption. Defenders should assume exfiltration precedes detonation by days to weeks.
  • Dwell time: Unconfirmed for this group. Industry median for comparable operations is 5–11 days from initial access to encryption; exfiltration typically begins within the first 72 hours. This is the detection window the content below is designed to catch.

Current Campaign Analysis

Listings observed (as claimed by the threat actor)

Organization (as spelled on leak site)Sector (per leak site)CountryPublishedCorroboration
Washington CountyGovernment & DefenseUS2026-09-23Single-source
Smart Eye CareHealthcare? (unstated)2026-09-23Single-source
The Merrimack CountyGovernment & DefenseUS2026-09-23Single-source
COSEF - Consorzio di Sviluppo Economico del FriuliOtherIT2026-09-23Single-source
GOTTHELFNot FoundMD2026-09-22Single-source
Tulare Western High SchoolEducationUS2026-09-22Single-source

Sector targeting

Government & Defense accounts for 2 of 6 listings (both U.S. county-level entities), with Healthcare and Education each contributing one U.S. listing. This is a classic soft-target triad: municipal government, regional healthcare, and school districts share under-resourced security teams, aging perimeter infrastructure, high availability pressure, and — critically for extortion economics — sensitive regulated data (PII, PHI, student records) that raises the pressure to pay. The Italian economic development consortium and the Moldovan listing suggest opportunistic affiliate-driven targeting rather than a deliberate geopolitical focus.

Geographic concentration

4 of 6 listings with a stated country are U.S.-based. Italy and Moldova each appear once. The U.S. weighting matches the broader ransomware economy's focus on American public-sector and healthcare victims.

Victim profile

The claimed organizations skew toward small-to-mid-size entities: county governments, a specialty eye-care provider, a single high school, a regional development consortium. Estimated revenue/budget ranges are likely $10M–$250M — the segment most likely to lack 24/7 SOC coverage and most likely to be running exposed or end-of-life remote access infrastructure.

Posting frequency / escalation

Six listings in approximately 48 hours is an aggressive opening cadence for a low-profile name. Two interpretations: (1) a stockpile of previously obtained access dumped at once to establish leak-site credibility, or (2) an active affiliate pipeline. Either way, defenders should assume additional listings are likely in the coming weeks.

CVE linkage — hypothesis only

We have no evidence connecting any specific CVE to any specific named listing. However, the following CISA KEV entries represent exactly the exposure classes this victim profile typically carries, and all have confirmed ransomware use in the wild:

  • CVE-2026-59310 — VMware vCenter path traversal: virtualization-layer compromise enables mass encryption of entire clusters, the hallmark of modern ransomware detonation.
  • CVE-2026-63077 — JetBrains TeamCity deserialization: unauthenticated RCE against build servers; an increasingly common pivot into source code, signing keys, and downstream supply-chain access.
  • CVE-2026-20316 — Cisco Secure FMC hard-coded password: management-plane takeover of perimeter firewalls.
  • CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1): direct perimeter VPN compromise — the single most common ransomware initial access vector.
  • CVE-2026-48027 — Nx Console embedded malicious code: supply-chain poisoning of developer workstations.

Patch posture against these five KEV entries should be validated this week by any organization in the targeted sectors.

Detection Engineering

The following content targets the pre-encryption behaviors typical of double-extortion operations: perimeter access exploitation, living-off-the-land lateral movement, and data staging/exfiltration before detonation.

YAML
---
title: BOOBA PROJECT — Suspicious RDP/VPN Brute Force Followed by Successful Authentication
tatus: experimental
description: Detects burst of failed logons from a single source followed by a successful interactive/remote logon — consistent with perimeter brute force or password spraying against VPN/RDP gateways as initial access.
author: Security Arsenal Threat Intelligence
logsource:
  category: authentication
  product: windows
detection:
  selection_failed:
    EventID: 4625
  selection_success:
    EventID: 4624
    LogonType:
      - 3
      - 10
  condition: selection_failed | count() by SourceAddress > 20
  timeframe: 10m
level: high
tags:
  - attack.initial_access
  - attack.t1078
  - attack.t1110
  - attack.t1133
---
title: BOOBA PROJECT — PsExec or WMI Remote Service Creation (Lateral Movement)
status: experimental
description: Detects remote service installation and execution via PsExec-style named pipes or WMI process creation — standard lateral movement tooling observed across double-extortion ransomware operations.
author: Security Arsenal Threat Intelligence
logsource:
  category: process_creation
  product: windows
detection:
  selection_psexec:
    Image|endswith:
      - '\PSEXESVC.exe'
      - '\psexec.exe'
      - '\paexec.exe'
      - '\csexec.exe'
  selection_wmi:
    ParentImage|endswith: '\WmiPrvSE.exe'
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\rundll32.exe'
  condition: 1 of selection_*
level: high
tags:
  - attack.lateral_movement
  - attack.t1569.002
  - attack.t1047
  - attack.t1021.002
---
title: BOOBA PROJECT — Pre-Encryption Staging — Archive Creation and Shadow Copy Deletion
status: experimental
description: Detects mass-archive creation with common exfil tools and/or Volume Shadow Copy deletion — the highest-fidelity pre-detonation indicators in ransomware playbooks. Alerting on this pair provides a final containment window before encryption.
author: Security Arsenal Threat Intelligence
logsource:
  category: process_creation
  product: windows
detection:
  selection_staging:
    Image|endswith:
      - '\rar.exe'
      - '\7z.exe'
      - '\winrar.exe'
      - '\rclone.exe'
      - '\megacmd.exe'
  selection_vss:
    Image|endswith:
      - '\vssadmin.exe'
      - '\wmic.exe'
      - '\bcdedit.exe'
      - '\wbadmin.exe'
    CommandLine|contains:
      - 'delete shadows'
      - 'shadowcopy delete'
      - 'resize shadowstorage'
      - 'recoveryenabled no'
      - 'delete catalog'
  condition: 1 of selection_*
level: critical
tags:
  - attack.collection
  - attack.t1560.001
  - attack.exfiltration
  - attack.t1567
  - attack.impact
  - attack.t1490

The following Microsoft Sentinel query hunts for the lateral-movement-then-staging sequence across a 14-day window, correlating remote service creation with subsequent large outbound transfers or archive utility execution on the same host:

KQL — Microsoft Sentinel / Defender
let Lookback = 14d;
let LateralHosts =
    SecurityEvent
    | where TimeGenerated > ago(Lookback)
    | where EventID == 7045  // service installed
    | where ServiceFileName has_any ("PSEXESVC", "\\ADMIN$", "\\C$")
       or ServiceName has_any ("PSEXESVC")
    | summarize FirstLateral = min(TimeGenerated) by Computer, Account
    | project Computer, FirstLateral, Account;
let Staging =
    DeviceProcessEvents
    | where TimeGenerated > ago(Lookback)
    | where FileName in~ ("rar.exe", "7z.exe", "winrar.exe", "rclone.exe", "megacmd.exe", "vssadmin.exe", "bcdedit.exe")
    | extend Indicator = iff(FileName in~ ("vssadmin.exe", "bcdedit.exe"), "ShadowCopyTamper", "ArchiveOrExfilTool")
    | summarize StagingEvents = make_set(ProcessCommandLine, 20),
                IndicatorTypes = make_set(Indicator),
                FirstStaging = min(TimeGenerated)
      by DeviceName;
LateralHosts
| join kind=inner (Staging) on $left.Computer == $right.DeviceName
| where FirstStaging >= FirstLateral
| extend HoursBetween = datetime_diff("hour", FirstStaging, FirstLateral)
| project Computer, Account, FirstLateral, FirstStaging, HoursBetween, IndicatorTypes, StagingEvents
| order by FirstLateral asc

A result with a short HoursBetween value and both indicator types present on a server-class host is a page-the-on-call event.

For rapid first-response triage on any host suspected of involvement — including hosts belonging to organizations in the listed sectors conducting proactive sweeps — run the following PowerShell script (elevated). It checks for exposed RDP, scheduled tasks created in the last 7 days (a common persistence mechanism), recent suspicious service installations, and shadow copy state:

PowerShell
# Security Arsenal — Rapid Ransomware Pre-Detonation Triage
# Run elevated. Outputs consolidated findings to C:\Triage_$env:COMPUTERNAME.txt

$Out = "C:\Triage_$($env:COMPUTERNAME).txt"
"=== TRIAGE $env:COMPUTERNAME — $(Get-Date) ===" | Out-File $Out

# 1. RDP exposure
"`n--- RDP Status ---" | Out-File $Out -Append
$rdp = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue
"RDP Enabled: $(if ($rdp.fDenyTSConnections -eq 0) {'YES — INVESTIGATE EXPOSURE'} else {'No'})" | Out-File $Out -Append
Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue | Format-Table | Out-File $Out -Append

# 2. Scheduled tasks created in last 7 days (persistence)
"`n--- Scheduled Tasks (created/modified last 7 days) ---" | Out-File $Out -Append
Get-ScheduledTask | ForEach-Object {
    $info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
    [PSCustomObject]@{ TaskName = $_.TaskName; Path = $_.TaskPath; LastRun = $info.LastRunTime }
} | Where-Object { $_.LastRun -gt (Get-Date).AddDays(-7) } | Format-Table | Out-File $Out -Append

# 3. New services (Event 7045) last 7 days — PsExec-style lateral movement
"`n--- Service Installs (7045) last 7 days ---" | Out-File $Out -Append
Get-WinEvent -FilterHashtable @{LogName='System'; Id=7045; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue |
    Select-Object TimeCreated, Message | Format-List | Out-File $Out -Append

# 4. Volume Shadow Copies — presence check (ransomware deletes these pre-detonation)
"`n--- Shadow Copies ---" | Out-File $Out -Append
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
"Shadow copy count: $($shadows.Count) — $(if ($shadows.Count -eq 0) {'ZERO: investigate vssadmin/bcdedit deletion'} else {'present'})" | Out-File $Out -Append

# 5. Recent failed logon burst by source (brute force / spraying)
"`n--- Failed Logons (4625) top sources, last 24h ---" | Out-File $Out -Append
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddDays(-1)} -ErrorAction SilentlyContinue |
    Group-Object { $_.Properties[19].Value } | Sort-Object Count -Descending | Select-Object -First 10 Count, Name | Format-Table | Out-File $Out -Append

Write-Host "Triage complete: $Out"

Incident Response Priorities

T-minus detection checklist (before encryption fires)

  1. Shadow copy tamperingvssadmin delete shadows, bcdedit recoveryenabled no, wbadmin delete catalog on any server. This is the closest-to-detonation high-fidelity signal; treat as imminent.
  2. Archive utility execution at scalerar.exe/7z.exe on servers where no backup or packaging workflow exists, especially targeting file shares, HR/finance directories, or patient/student record systems.
  3. Exfil toolingrclone, MEGAcmd, or sustained large outbound transfers (multi-GB to uncommon external IPs or cloud storage) from a small number of hosts.
  4. New service installations (7045) and remote ADMIN$/C$ share access fanning out from one workstation — the lateral movement signature of hands-on-keyboard operators.
  5. EDR/AV tampering attempts — disabling Defender via PowerShell (Set-MpPreference -DisableRealtimeMonitoring), uninstalling agents, or adding broad exclusions.

Assets historically prioritized for exfiltration (double-extortion economics)

  • Regulated data stores: patient records (healthcare), student records (education), constituent PII and law-enforcement-adjacent records (county government).
  • HR and payroll exports, financial statements, insurance documentation (used to calibrate demand size).
  • Legal and contract repositories; email archives of executive accounts.
  • Domain controller ntds.dit and credential stores — both for extortion leverage and persistence.

Containment actions, ordered by urgency

  1. Isolate, don't power off any host showing shadow-copy deletion or mass archiving — preserve memory for forensics while severing network paths (EDR network isolation or switch-level quarantine).
  2. Disable the suspected initial-access account(s) and force enterprise-wide credential resets for any account observed in lateral movement events — assume DCSync if a DC was touched.
  3. Block egress for exfil tooling destinations at the perimeter; capture netflow for the past 14 days to size any data theft.
  4. Verify backup integrity immediately — confirm offline/immutable copies predate the earliest suspicious authentication; do not wait for encryption to discover backups were reachable.
  5. Engage IR retainer and counsel before any communication decisions; notification obligations (state AG, HHS OCR for PHI, etc.) are driven by the organization's own investigation, not by the criminal's claim.

Hardening Recommendations

Immediate (24 hours)

  • Patch or isolate the five KEV exposures listed above: vCenter (CVE-2026-59310), TeamCity (CVE-2026-63077), Cisco Secure FMC (CVE-2026-20316), Check Point gateways (CVE-2026-50751), and audit developer workstations for the malicious Nx Console build (CVE-2026-48027). If patching cannot complete today, remove the management interfaces from any network reachable by general users or the internet.
  • Deploy the Sigma detections above and run the KQL hunt across the last 14 days — the median dwell time means access may already exist.
  • Enforce phishing-resistant MFA on all VPN, RDP-gateway, and remote management access; audit for legacy IKEv1 remote access profiles on Check Point and equivalent legacy VPN paths.
  • Run the triage PowerShell script on domain controllers, backup servers, and hypervisor management hosts; confirm shadow copies and backups exist and are immutable.
  • Block execution of rar.exe, 7z.exe (non-managed installs), rclone.exe, and vssadmin.exe/bcdedit.exe for non-administrative users via AppLocker or WDAC.

Short-term (2 weeks)

  • Segment backup and virtualization management planes onto dedicated networks unreachable from general user VLANs; require jump-host access with session recording.
  • Deploy decoy file shares / canary credentials on file servers and workstations — encryption staging touches these early.
  • Implement egress data-loss thresholds: alert on any single host transferring more than a defined volume to external destinations within 24 hours.
  • Stand up 24/7 monitoring or MDR coverage — the victim profile in this campaign is defined by organizations without it. County governments, school districts, and regional healthcare providers should evaluate managed detection specifically for after-hours coverage, when most detonations occur.
  • Exercise the ransomware playbook: tabletop the exfiltration-plus-encryption scenario with leadership and counsel, including the decision tree for criminal leak-site claims that cannot yet be verified.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.