Boolka is a threat actor known for opportunistic SQL injection attacks to inject malicious JavaScript for data exfiltration.
Analyst brief
Boolka is a threat actor launching opportunistic SQL injection attacks since at least 2022, primarily to infect websites with malicious JavaScript for data exfiltration. They target websites with vulnerable web applications, likely aiming for mass data theft rather than specific victim profiles. Key TTPs and tools include SQL injection for initial access, JavaScript injection for data exfiltration, the BMANAGER trojan for malware distribution, and a delivery platform built on the BeEF framework. Defenders should prioritize patching SQL injection vulnerabilities, monitoring web server code for unauthorized JavaScript modifications, and inspecting network traffic for BeEF-related C2 activity.
Boolka
unknown
Boolka is a threat actor known for infecting websites with malicious JavaScript scripts for data exfiltration. They have been carrying out opportunistic SQL injection attacks since at least 2022. Boolka has developed a malware delivery platform based on the BeEF framework and has been distributing the BMANAGER trojan. Their activities demonstrate a progression from basic website infections to more sophisticated malware operations.