Boolka is a threat actor known for infecting websites with malicious JavaScript scripts for data exfiltration. They have been carrying out opportunistic SQL injection attacks since at least 2022. Boolka has developed a malware delivery platform based on the BeEF framework and has been distributing the BMANAGER trojan. Their activities demonstrate a progression from basic website infections to more sophisticated malware operations.
Targeted Sectors
Executive Summary
Boolka is a threat actor leveraging web-based attacks to deploy malicious JavaScript and SQL injection payloads for data exfiltration. Since 2022, they have evolved from opportunistic infections to structured malware operations using the BeEF framework and the BMANAGER trojan. Their activities indicate growing sophistication and potential targeting of web-exposed infrastructure.
Goals & Targeting
Boolka's operations appear to prioritize financial gain through data theft and infrastructure compromise. Their targeting of websites suggests a focus on sectors with vulnerable web applications, such as e-commerce, media, and small-to-medium enterprises with outdated digital infrastructure. The actor's use of SQL injection and custom malware suggests an intent to exploit weak security controls for long-term access and monetization of stolen data. Geographically, their activities align with regions where web security measures are less stringent, though specific countries remain unspecified in available intelligence.
Enhanced Description
Boolka has been identified as an actor specializing in compromising websites through malicious JavaScript injections, with a focus on data exfiltration. Their operations began in 2022 with opportunistic SQL injection attacks, but they have since developed a more advanced malware delivery platform based on the BeEF framework. This evolution suggests a shift toward structured cybercrime operations. The BMANAGER trojan, associated with Boolka, indicates a capacity for persistent access and lateral movement on compromised networks. While initially characterized by basic website infections, their recent activities demonstrate a clear progression toward more complex malware deployment, suggesting resource allocation and technical capability beyond casual attackers.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Boolka's campaigns focus on exploiting web application vulnerabilities, often through outdated or misconfigured websites. Their operations follow a pattern of initial compromise via SQL or JavaScript injection, followed by malware deployment for sustained access. Campaigns appear to be conducted at a moderate operational tempo, with a focus on stealth and avoiding detection. Notable past operations include the use of BeEF-based platforms to deliver payloads and the deployment of BMANAGER for persistent data collection, though no specific campaigns have been publicly attributed to this actor.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the data is moderate to high, as reported activities are corroborated by observed malware samples and attack patterns. However, gaps exist in linking specific campaigns to Boolka, determining their full geographic targeting scope, and identifying their primary motivation. The absence of publicly attributed attacks limits confirmation of their sophistication level and long-term objectives.
No campaigns linked yet.
No observed data linked yet.
29
Techniques
40
Tools
0
Campaigns
39
IOCs
0
Observed Data
10
Tactics