Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Boolka

Description

Boolka is a threat actor known for infecting websites with malicious JavaScript scripts for data exfiltration. They have been carrying out opportunistic SQL injection attacks since at least 2022. Boolka has developed a malware delivery platform based on the BeEF framework and has been distributing the BMANAGER trojan. Their activities demonstrate a progression from basic website infections to more sophisticated malware operations.

Goals & Targeting

Targeted Sectors

Defense
Financial services
Manufacturing
Retail
Government
Hospitality
Legal services
Aviation

AI Analysis

· 1 week ago

Executive Summary

Boolka is a threat actor leveraging web-based attacks to deploy malicious JavaScript and SQL injection payloads for data exfiltration. Since 2022, they have evolved from opportunistic infections to structured malware operations using the BeEF framework and the BMANAGER trojan. Their activities indicate growing sophistication and potential targeting of web-exposed infrastructure.

Goals & Targeting

Boolka's operations appear to prioritize financial gain through data theft and infrastructure compromise. Their targeting of websites suggests a focus on sectors with vulnerable web applications, such as e-commerce, media, and small-to-medium enterprises with outdated digital infrastructure. The actor's use of SQL injection and custom malware suggests an intent to exploit weak security controls for long-term access and monetization of stolen data. Geographically, their activities align with regions where web security measures are less stringent, though specific countries remain unspecified in available intelligence.

Enhanced Description

Boolka has been identified as an actor specializing in compromising websites through malicious JavaScript injections, with a focus on data exfiltration. Their operations began in 2022 with opportunistic SQL injection attacks, but they have since developed a more advanced malware delivery platform based on the BeEF framework. This evolution suggests a shift toward structured cybercrime operations. The BMANAGER trojan, associated with Boolka, indicates a capacity for persistent access and lateral movement on compromised networks. While initially characterized by basic website infections, their recent activities demonstrate a clear progression toward more complex malware deployment, suggesting resource allocation and technical capability beyond casual attackers.

Key Capabilities

  • Web-based JavaScript injection for data exfiltration
  • SQL injection attacks for initial compromise
  • Malware delivery via the BeEF framework
  • Deployment of the BMANAGER trojan for persistent access
  • Progression from basic infections to multi-staged malware operations

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Exfiltration

ATT&CK Techniques

T1190.001 (Web Shell)
T1567.002 (Web Skimming)
T1040 (Exfiltration over C2)
T1190 (Exploit Public-Facing Application)
T1059.003 (Command-line Interface)

Software / Tooling

BeEF framework
BMANAGER trojan

Campaigns & Victims

Boolka's campaigns focus on exploiting web application vulnerabilities, often through outdated or misconfigured websites. Their operations follow a pattern of initial compromise via SQL or JavaScript injection, followed by malware deployment for sustained access. Campaigns appear to be conducted at a moderate operational tempo, with a focus on stealth and avoiding detection. Notable past operations include the use of BeEF-based platforms to deliver payloads and the deployment of BMANAGER for persistent data collection, though no specific campaigns have been publicly attributed to this actor.

IOC Patterns

  • Malicious JavaScript injection in compromised webpages
  • SQL injection payloads targeting web application vulnerabilities
  • C2 communication patterns using domain generation algorithms
  • Presence of BMANAGER trojan binaries on infected systems
  • BeEF framework exploitation signatures in network traffic

Recommended Actions

  • Implement and enforce web application firewalls to block SQL injection attempts
  • Regularly scan for vulnerable web components and patch outdated software
  • Monitor network traffic for anomalous JavaScript execution and C2 activity
  • Deploy endpoint detection systems to identify BMANAGER trojan behavior
  • Conduct employee training to prevent social engineering related to web-based attacks

Suggested Tags

APT
data-exfiltration
web-based-attack
malware-distribution
sql-injection
bmanager

Confidence Assessment

Confidence in the data is moderate to high, as reported activities are corroborated by observed malware samples and attack patterns. However, gaps exist in linking specific campaigns to Boolka, determining their full geographic targeting scope, and identifying their primary motivation. The absence of publicly attributed attacks limits confirmation of their sophistication level and long-term objectives.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 10 Domain 9 URL 1

References

  1. www.group-ib.com — Cited by web research for: T1583.001
  2. attack.mitre.org — Cited by web research for: Interception
  3. ctid.mitre.org — Cited by web research for: Pyramid
  4. www.ncei.noaa.gov — Cited by web research for: rock
  5. www.group-ib.com — Cited by web research for: Financial Services

Intel Summary

29

Techniques

40

Tools

0

Campaigns

39

IOCs

0

Observed Data

10

Tactics

Tags

Data Exfiltration
APT
data-exfiltration
web-based-attack
malware-distribution
sql-injection
bmanager

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.