Threat reportRansomwareTL-2026-2940
Booba ransomware (reported Frag rebrand) hits University of Illinois Chicago College of Medicine
Booba ransomware (reported Frag rebrand) hits University of (TL-2026-2940), also tracked as Booba Project ransomware, is a high-severity ransomware operation, first published 2026-10-05. It is attributed to Booba with low confidence, affects University of Illinois Chicago College of Medicine IT systems, maps to 4 MITRE ATT&CK techniques (T1078, T1136.001, T1190), and is covered by 9 detection rules and 11 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 4MITRE ATT&CK
- Actors
- 1Booba
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 11Indicators of compromise
Key facts for TL-2026-2940
- Threat ID
- TL-2026-2940
- Also known as
- Booba Project ransomware
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- Booba
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- education, health, government administration, professional services, food and beverage
- Target regions
- North America
- Detection rules
- 9
- Indicators of compromise
- 11
Malware and tooling in Booba ransomware (reported Frag rebrand) hits University of
Malware and tooling: Akira, Booba, fog, frag
How Booba ransomware (reported Frag rebrand) hits University of works
The University of Illinois Chicago said some College of Medicine systems were temporarily unavailable after a ransomware attack; the Booba group claims to have stolen 344 GB. The university says all affected systems have been restored, the main university network was unaffected, and UI Health patient care was not impacted.
On 2026-10-05 The Record reported that the University of Illinois Chicago (UIC) College of Medicine (about 1,300 students, within a university of 35,000+ students across 16 colleges) suffered a ransomware attack that left some College of Medicine systems temporarily unavailable. The Booba ransomware group listed UIC on its leak site and claims to have stolen 344 GB of data; the claim is unverified. UIC states that all affected systems have been restored, the main university network was not affected, and patient care at UI Health was not disrupted. The university is investigating whether any personal, research or academic information was compromised, has reported the incident to law enforcement, coordinated recovery with agencies, and plans to notify affected individuals. The source does not state the initial-access vector, ransom demand, or incident dates.
Booba (tracked by WatchGuard as 'Booba Project') is a crypto-ransomware group operating a double-extortion model (direct extortion, double extortion and free data leaks). Trackers date its first activity to June 2026 (first extortion entry 2026-06-24 against US foodservice cooperative Frosty Acres Brands), while The Record says the group emerged at the end of July 2026 and has claimed 49 attacks. Encrypted files carry the .booba extension and both Windows and Linux variants have been reported. SentinelOne's Brett Williams assessed Booba as a likely rebrand of the Frag ransomware, based on similarities in leak-site style and negotiation flow; this is an analyst assessment, not a confirmed link. Other reported Booba victims include Merrimack County, New Hampshire (listed 2026-09-23, ~3 GB claimed; the county confirmed recovery), Washington County (listed the same day) and various companies and small county governments, with US government and professional services most frequently targeted.
Background on the possible predecessor: Frag appeared in late February 2025 (leak site launched 2025-02-28) and was documented by Sophos as deployed in intrusions tracked as STAC 5881, which also delivered Akira and Fog ransomware. Those intrusions used compromised VPN appliances for access and exploited Veeam Backup & Replication CVE-2024-40711 to create local administrator accounts named 'point' and 'point2'; Frag is run from the command line with a mandatory encryption-percentage parameter and appends .frag to files. Those behaviors are documented for Frag, NOT observed for Booba or the UIC incident, and are included here only as hunting context if the rebrand assessment holds.
MITRE ATT&CK techniques used in TL-2026-2940
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Persistence
T1136.001 Create Account: Local Account
Impact
Affected products and versions in Booba ransomware (reported Frag rebrand) hits University of
- University of Illinois Chicago — College of Medicine IT systems
Remediation for Booba ransomware (reported Frag rebrand) hits University of
Patches
- Apply the Veeam Backup & Replication fix for CVE-2024-40711 (exploited in Frag/STAC 5881 intrusions)
Immediate actions
- Hunt for files with the .booba extension on Windows and Linux hosts
- Review local administrator account creation, especially accounts named 'point' and 'point2' (Frag/STAC 5881 artifact; unconfirmed for Booba)
- Review VPN appliance and backup-server access logs for anomalous logins
Workarounds
- Restrict VPN and backup-console exposure and enforce MFA on remote access
Longer-term hardening
- Maintain offline/immutable backups and test restoration
- Segment medical-school and research networks from the main university network
- Enable ransomware behavioral protection on Windows and Linux endpoints
Timeline of Booba ransomware (reported Frag rebrand) hits University of
- Frag ransomware (suspected predecessor of Booba per SentinelOne's assessment) launches its data-leak site; first victim named in late February 2025 (Cyjax).
- Booba Project's first tracked extortion entry: a US food and beverage victim (WatchGuard tracker); DEXPOSE reports Frosty Acres Brands on 2026-06-25.
- The Record states Booba emerged at the end of July 2026 (date approximate; trackers record activity from June 2026, with 11 attacks in July).
- Merrimack County, NH network security incident begins on the Tuesday before the 2026-08-27 Concord Monitor report; Register of Deeds and dispatch data access disrupted (date derived from 'Tuesday'; no attribution in that article).
- Booba lists Merrimack County, NH (~3 GB claimed) and Washington County on its dark web leak site (SOCRadar).
- UIC discloses ransomware attack on its College of Medicine; Booba claims 344 GB stolen; systems restored, UI Health patient care unaffected; incident reported to law enforcement (The Record).
Sources cited for Booba ransomware (reported Frag rebrand) hits University of
- University of Illinois Chicago affected by ransomware attack on medical school (The Record)
- Booba Project - Ransomware Tracker (WatchGuard)
- Veeam exploit seen used again with a new ransomware, Frag (Sophos)
- Frag explodes onto the scene - New DLS emerges for Frag ransomware (Cyjax)
- Booba Ransomware Strikes Frosty Acres Brands (DEXPOSE)
- Merrimack County cyber breach (Concord Monitor)
- The Merrimack County Data Breach - Booba Project (SOCRadar)
Detection coverage for TL-2026-2940
As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2940 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2940
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.