logo

Boolka Unveiled: From web attacks to modular malware

ID: a18d2d91-8b66-5bd8-8cf8-eb44518d279e

STIX ID: report--a18d2d91-8b66-5bd8-8cf8-eb44518d279e

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2024-06-21

Date Updated: 2026-04-27

...
...

Group-IB analysts uncovered operations by a cybercriminal actor called Boolka who used opportunistic SQL injection to inject form‑stealing JavaScript into websites and tested a BeEF‑based malware delivery platform (landing pages like updatebrower.com) to distribute a Python‑based trojan ecosystem (BMANAGER, BMREADER, BMLOG, BMHOOK, BMBACKUP) that performs credential/form theft, keylogging, targeted application monitoring, and file exfiltration; the report provides detailed technical analysis, persistence/C2 behaviors, IoCs (domains, IPs, URLs, file hashes), MITRE mappings, and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.