# Booba ransomware (reported Frag rebrand) hits University of Illinois Chicago College of Medicine

> The University of Illinois Chicago said some College of Medicine systems were temporarily unavailable after a ransomware attack; the Booba group claims to have stolen 344 GB. The university says all affected systems have been restored, the main university network was unaffected, and UI Health patient care was not impacted.

- **Published:** 2026-10-05T00:00:00Z
- **Last reviewed:** 2026-10-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2940
- **ID:** TL-2026-2940
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** Booba
- **Detections:** 9 · **IOCs:** 11 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-10-05 The Record reported that the University of Illinois Chicago (UIC) College of Medicine (about 1,300 students, within a university of 35,000+ students across 16 colleges) suffered a ransomware attack that left some College of Medicine systems temporarily unavailable. The Booba ransomware group listed UIC on its leak site and claims to have stolen 344 GB of data; the claim is unverified. UIC states that all affected systems have been restored, the main university network was not affected, and patient care at UI Health was not disrupted. The university is investigating whether any personal, research or academic information was compromised, has reported the incident to law enforcement, coordinated recovery with agencies, and plans to notify affected individuals. The source does not state the initial-access vector, ransom demand, or incident dates.

Booba (tracked by WatchGuard as 'Booba Project') is a crypto-ransomware group operating a double-extortion model (direct extortion, double extortion and free data leaks). Trackers date its first activity to June 2026 (first extortion entry 2026-06-24 against US foodservice cooperative Frosty Acres Brands), while The Record says the group emerged at the end of July 2026 and has claimed 49 attacks. Encrypted files carry the .booba extension and both Windows and Linux variants have been reported. SentinelOne's Brett Williams assessed Booba as a likely rebrand of the Frag ransomware, based on similarities in leak-site style and negotiation flow; this is an analyst assessment, not a confirmed link. Other reported Booba victims include Merrimack County, New Hampshire (listed 2026-09-23, ~3 GB claimed; the county confirmed recovery), Washington County (listed the same day) and various companies and small county governments, with US government and professional services most frequently targeted.

Background on the possible predecessor: Frag appeared in late February 2025 (leak site launched 2025-02-28) and was documented by Sophos as deployed in intrusions tracked as STAC 5881, which also delivered Akira and Fog ransomware. Those intrusions used compromised VPN appliances for access and exploited Veeam Backup & Replication CVE-2024-40711 to create local administrator accounts named 'point' and 'point2'; Frag is run from the command line with a mandatory encryption-percentage parameter and appends .frag to files. Those behaviors are documented for Frag, NOT observed for Booba or the UIC incident, and are included here only as hunting context if the rebrand assessment holds.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1136.001 Create Account: Local Account
- T1657 Financial Theft

## Sources

- [University of Illinois Chicago affected by ransomware attack on medical school (The Record)](https://therecord.media/ransomware-university-illinois-chicago)
- [Booba Project - Ransomware Tracker (WatchGuard)](https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/booba-project)
- [Veeam exploit seen used again with a new ransomware, Frag (Sophos)](https://www.sophos.com/en-us/blog/veeam-exploit-seen-used-again-with-a-new-ransomware-frag)
- [Frag explodes onto the scene - New DLS emerges for Frag ransomware (Cyjax)](https://www.cyjax.com/resources/blog/frag-explodes-onto-the-scene-new-dls-emerges-for-frag-ransomware)
- [Booba Ransomware Strikes Frosty Acres Brands (DEXPOSE)](https://www.dexpose.io/?p=36511)
- [Merrimack County cyber breach (Concord Monitor)](https://www.concordmonitor.com/2026/08/27/merrimack-county-cyber-breach-nh/)
- [The Merrimack County Data Breach - Booba Project (SOCRadar)](https://socradar.io/data-breach/the-merrimack-county-booba-project-ransomware-2026/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2940
