Boolka Unveiled: From web attacks to modular malware
ID: a18d2d91-8b66-5bd8-8cf8-eb44518d279e
STIX ID: report--a18d2d91-8b66-5bd8-8cf8-eb44518d279e
Feed Name: Group-IB Blog
Group-IB analysts uncovered operations by a cybercriminal actor called Boolka who used opportunistic SQL injection to inject form‑stealing JavaScript into websites and tested a BeEF‑based malware delivery platform (landing pages like updatebrower.com) to distribute a Python‑based trojan ecosystem (BMANAGER, BMREADER, BMLOG, BMHOOK, BMBACKUP) that performs credential/form theft, keylogging, targeted application monitoring, and file exfiltration; the report provides detailed technical analysis, persistence/C2 behaviors, IoCs (domains, IPs, URLs, file hashes), MITRE mappings, and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
