Booba Project — Ransomware Profile
Booba Project (also tracked as "Booba" and, on RansomLook, "Booba Team") is a data-extortion operation that surfaced in June 2026, operating a Tor leak site and negotiating with victims via a ProtonMail address (boobaproject@proton.me). Reporting to date describes a steal-and-leak model, exfiltrating victim data and threatening publication unless a ransom is negotiated, with no public confirmation of file encryption, no named tooling or exploited CVEs, and no vendor cluster attribution. Its first five publicly listed victims span the United States and Spain across food production, telecommunications, IT services, construction and business/entertainment services. There is no evidence that Booba Project is a rebrand of an established ransomware family; it remains an early-stage operation under observation.Also tracked as
Booba, Booba Team
IntelFusions coverage (2)
- New ransomware crew Crpx O debuts by hitting US dental practices 2026-07-10 · Ransomware
- New ransomware crew Booba Project debuts by naming five victims 2026-07-07 · Ransomware
Recent claimed victims
- Betz Industries 2026-07-31
- Oklahoma Manufacturing Alliance 2026-07-28
- Incredible Technologies 2026-07-28
- Zynex 2026-07-24
- Pelli Clarke Pelli Architects 2026-07-22
- Jani-King 2026-07-15
- URA Group 2026-07-07
- Frosty Acres Brands 2026-07-06
- Upstaging 2026-07-06
- Nfinite 9000 S.L. 2026-07-06
- Fonsan 2026-07-06
- Telewave, Inc. 2026-07-06