08 Boolka

Boolka

Region
Asia-Pacific, 
Europe, 
North America
Industries
Financial Services, 
Government, 
Software & IT
First seen
January 2024
Cybercrime
Vast exploitation of vulnerabilities on high traffic websites, potentially affecting thousands of users and businesses
Heritage
Represent a new wave of cybercriminals
Categorizations
Modular malware
About

Boolka’s evolving stealth tactics have made it a notable player within the Masked Actors community. This group’s ability to adapt and deploy modular website malware mean it’s a significant threat. Not only can this expose victims to financial crime, but reputational damage too.

Learn more about Boolka from Group-IB’s research
Victims

Exact numbers are unclear, but the group’s skills in exploiting vulnerabilities on websites are vast — potentially affecting thousands of users and businesses worldwide. Particularly those with poorly secured websites which lack defences against SQL injection and cross-site scripting hacks. This includes data-sensitive sectors like e-commerce and finance.

What we know about Boolka members

We believe the actor behind Boolka is likely to be an individual or small group with advanced knowledge of website vulnerabilities and malware delivery platforms.

Motivations
Financial gain through data theft and exploitation of website weaknesses.
Top 10 Masked Actors for 2025
RansomHub
#1
GoldFactory
#2
Lazarus
#3
DragonForce
#4
Oilrig
#5
MuddyWater
#6
Brain Cipher
#7
Boolka
#8
Ajina
#9
Team TNT
#10