Threat reportRansomwareTL-2026-2940

Booba ransomware (reported Frag rebrand) hits University of Illinois Chicago College of Medicine

highACTIVE

Booba ransomware (reported Frag rebrand) hits University of (TL-2026-2940), also tracked as Booba Project ransomware, is a high-severity ransomware operation, first published 2026-10-05. It is attributed to Booba with low confidence, affects University of Illinois Chicago College of Medicine IT systems, maps to 4 MITRE ATT&CK techniques (T1078, T1136.001, T1190), and is covered by 9 detection rules and 11 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
4MITRE ATT&CK
Actors
1Booba
Detection rules
9SPL · KQL · Sigma
IOCs
11Indicators of compromise

Key facts for TL-2026-2940

Threat ID
TL-2026-2940
Also known as
Booba Project ransomware
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
Booba
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
education, health, government administration, professional services, food and beverage
Target regions
North America
Detection rules
9
Indicators of compromise
11

Malware and tooling in Booba ransomware (reported Frag rebrand) hits University of

Malware and tooling: Akira, Booba, fog, frag

How Booba ransomware (reported Frag rebrand) hits University of works

The University of Illinois Chicago said some College of Medicine systems were temporarily unavailable after a ransomware attack; the Booba group claims to have stolen 344 GB. The university says all affected systems have been restored, the main university network was unaffected, and UI Health patient care was not impacted.

On 2026-10-05 The Record reported that the University of Illinois Chicago (UIC) College of Medicine (about 1,300 students, within a university of 35,000+ students across 16 colleges) suffered a ransomware attack that left some College of Medicine systems temporarily unavailable. The Booba ransomware group listed UIC on its leak site and claims to have stolen 344 GB of data; the claim is unverified. UIC states that all affected systems have been restored, the main university network was not affected, and patient care at UI Health was not disrupted. The university is investigating whether any personal, research or academic information was compromised, has reported the incident to law enforcement, coordinated recovery with agencies, and plans to notify affected individuals. The source does not state the initial-access vector, ransom demand, or incident dates.

Booba (tracked by WatchGuard as 'Booba Project') is a crypto-ransomware group operating a double-extortion model (direct extortion, double extortion and free data leaks). Trackers date its first activity to June 2026 (first extortion entry 2026-06-24 against US foodservice cooperative Frosty Acres Brands), while The Record says the group emerged at the end of July 2026 and has claimed 49 attacks. Encrypted files carry the .booba extension and both Windows and Linux variants have been reported. SentinelOne's Brett Williams assessed Booba as a likely rebrand of the Frag ransomware, based on similarities in leak-site style and negotiation flow; this is an analyst assessment, not a confirmed link. Other reported Booba victims include Merrimack County, New Hampshire (listed 2026-09-23, ~3 GB claimed; the county confirmed recovery), Washington County (listed the same day) and various companies and small county governments, with US government and professional services most frequently targeted.

Background on the possible predecessor: Frag appeared in late February 2025 (leak site launched 2025-02-28) and was documented by Sophos as deployed in intrusions tracked as STAC 5881, which also delivered Akira and Fog ransomware. Those intrusions used compromised VPN appliances for access and exploited Veeam Backup & Replication CVE-2024-40711 to create local administrator accounts named 'point' and 'point2'; Frag is run from the command line with a mandatory encryption-percentage parameter and appends .frag to files. Those behaviors are documented for Frag, NOT observed for Booba or the UIC incident, and are included here only as hunting context if the rebrand assessment holds.

MITRE ATT&CK techniques used in TL-2026-2940

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Persistence

T1136.001 Create Account: Local Account

Impact

T1657 Financial Theft

Affected products and versions in Booba ransomware (reported Frag rebrand) hits University of

  • University of Illinois Chicago — College of Medicine IT systems

Remediation for Booba ransomware (reported Frag rebrand) hits University of

Patches

  • Apply the Veeam Backup & Replication fix for CVE-2024-40711 (exploited in Frag/STAC 5881 intrusions)

Immediate actions

  • Hunt for files with the .booba extension on Windows and Linux hosts
  • Review local administrator account creation, especially accounts named 'point' and 'point2' (Frag/STAC 5881 artifact; unconfirmed for Booba)
  • Review VPN appliance and backup-server access logs for anomalous logins

Workarounds

  • Restrict VPN and backup-console exposure and enforce MFA on remote access

Longer-term hardening

  • Maintain offline/immutable backups and test restoration
  • Segment medical-school and research networks from the main university network
  • Enable ransomware behavioral protection on Windows and Linux endpoints

Timeline of Booba ransomware (reported Frag rebrand) hits University of

  • Frag ransomware (suspected predecessor of Booba per SentinelOne's assessment) launches its data-leak site; first victim named in late February 2025 (Cyjax).
  • Booba Project's first tracked extortion entry: a US food and beverage victim (WatchGuard tracker); DEXPOSE reports Frosty Acres Brands on 2026-06-25.
  • The Record states Booba emerged at the end of July 2026 (date approximate; trackers record activity from June 2026, with 11 attacks in July).
  • Merrimack County, NH network security incident begins on the Tuesday before the 2026-08-27 Concord Monitor report; Register of Deeds and dispatch data access disrupted (date derived from 'Tuesday'; no attribution in that article).
  • Booba lists Merrimack County, NH (~3 GB claimed) and Washington County on its dark web leak site (SOCRadar).
  • UIC discloses ransomware attack on its College of Medicine; Booba claims 344 GB stolen; systems restored, UI Health patient care unaffected; incident reported to law enforcement (The Record).

Sources cited for Booba ransomware (reported Frag rebrand) hits University of

Detection coverage for TL-2026-2940

As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2940 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
11 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2940

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats