Two New Ransomware Victims Surface as Akira and Booba Project Expand Their Reach + Video

Listen to this Post

Featured Image

A New Warning From the Dark Web

The ransomware landscape rarely stays quiet for long. Even when one major campaign appears to dominate headlines, other criminal groups continue moving through the background, searching for organizations that can be pressured, disrupted, and ultimately exploited for financial gain.

On August 24, 2026, two new organizations appeared in ransomware activity tracked by the ThreatMon Threat Intelligence Team. The listings associate Akira with Bihl and the Booba Project with Chernyy & Associates.

The two entries are significant because they illustrate a familiar pattern in modern ransomware operations: multiple criminal groups can add new victims within the same reporting window, creating a steady stream of organizations exposed to extortion, operational disruption, data theft, and reputational damage.

What Happened on August 24, 2026

According to the supplied ThreatMon intelligence posts, Akira added Bihl to its list of victims at 21:01:38 UTC+3 on August 24, 2026.

A separate entry reported that the Booba Project ransomware group added Chernyy & Associates at 17:50:22 UTC+3 on the same day.

These reports were presented as ransomware activity detected by ThreatMon’s Threat Intelligence Team, with the information surfaced through social media monitoring.

Akira Targets Bihl

The first incident involves the Akira ransomware operation, one of the names that has become closely associated with organized ransomware activity.

ThreatMon reported that Bihl had been added to Akira’s victim list. The available report does not provide additional technical information about the intrusion, such as the initial access vector, affected systems, stolen data, encryption status, or ransom demand.

That absence of detail matters.

A victim-list appearance can be an important early indicator, but it does not automatically reveal how an intrusion occurred or how extensive the compromise may be. Security teams need additional evidence, including endpoint telemetry, identity logs, network activity, and forensic artifacts, to determine what actually happened inside an affected environment.

Booba Project Adds Chernyy & Associates

The second entry concerns the Booba Project, which ThreatMon associated with a new victim, Chernyy & Associates.

The report provides considerably less technical information than a full incident investigation. It identifies the actor, the organization, and the timestamp, but does not explain whether systems were encrypted, whether sensitive information was exfiltrated, or whether the organization has experienced operational disruption.

Still, the appearance is important from a threat-intelligence perspective.

Ransomware groups frequently use public-facing victim listings as part of their pressure strategy. Publishing an organization can increase psychological pressure, attract media attention, and create urgency for negotiations even before the full technical details of an attack become public.

Why Two Victims on the Same Day Matter

The most important lesson is not simply that two organizations appeared on ransomware-related lists.

It is that ransomware remains an ecosystem rather than a single campaign.

Akira and Booba Project represent separate criminal operations, yet both demonstrate the same broader business model: compromise an organization, obtain leverage, and use that leverage to demand payment or threaten exposure.

This means defenders cannot build their security strategy around tracking one ransomware brand.

The name of the group can change. Infrastructure can disappear. Affiliates can move between operations. Malware families can be replaced. Initial access brokers can sell access to completely different attackers.

The underlying defensive problem remains the same.

Ransomware Is Now an Ecosystem

Modern ransomware operations increasingly resemble distributed criminal businesses.

One group may specialize in initial access. Another actor may provide stolen credentials. An affiliate may conduct the intrusion. A separate team may handle data theft, negotiation, or publication.

This division of labor makes ransomware more resilient.

Even if defenders successfully disrupt one malware family, another operation can potentially take advantage of the same exposed remote service, stolen password, vulnerable appliance, or compromised employee account.

That is why organizations should focus less on memorizing ransomware names and more on understanding the attack paths that repeatedly lead to compromise.

The Victim-Listing Strategy

A ransomware victim listing is not merely a technical artifact.

It is also a psychological weapon.

Attackers understand that publicly naming an organization can create pressure on executives, legal teams, customers, insurers, and business partners.

The threat of public disclosure can be particularly damaging when an organization handles confidential contracts, financial information, personal data, intellectual property, or sensitive communications.

For defenders, this means ransomware response cannot stop at malware removal.

Incident response must also consider legal obligations, communications, business continuity, customer notification, evidence preservation, and long-term remediation.

The Information Missing From the Reports

The two supplied entries do not reveal several critical details.

There is no confirmed information about the initial access method.

There is no detailed description of the affected infrastructure.

There is no disclosed malware sample.

There is no technical indicator showing how the attackers entered.

There is no public explanation of whether data was stolen.

There is no confirmed ransom amount in the supplied material.

There is also no detailed timeline describing detection, containment, recovery, or remediation.

Those gaps should not be interpreted as evidence that nothing serious happened. They simply demonstrate why threat-intelligence notifications should be treated as starting points for investigation rather than complete forensic reports.

What Security Teams Should Learn

Organizations should assume that ransomware operators are continuously testing the edges of their security perimeter.

Internet-facing services deserve particular attention.

Remote access infrastructure should be aggressively monitored.

Privileged accounts should receive additional protection.

Multi-factor authentication should be enforced wherever possible.

Backups should remain isolated from production environments.

Endpoint detection should be configured to identify suspicious credential access, lateral movement, and abnormal encryption behavior.

Network segmentation can limit the ability of an attacker to move from one compromised machine to an entire environment.

Most importantly, security teams should investigate unusual activity before it becomes an obvious ransomware incident.

Credentials Remain a Critical Weak Point

Attackers do not always need sophisticated zero-day exploits.

A valid username and password can sometimes provide everything an attacker needs to begin moving through an environment.

Compromised credentials may originate from phishing, infostealers, password reuse, exposed credentials, previous breaches, malicious browser extensions, or third-party compromise.

Organizations should therefore monitor authentication activity for impossible travel patterns, unusual login locations, abnormal device fingerprints, repeated failed authentication attempts, and unexpected privilege escalation.

Identity security has effectively become part of ransomware defense.

Remote Services Need Special Attention

Remote desktop services, VPN infrastructure, cloud identity platforms, remote administration tools, and exposed management interfaces remain attractive targets.

Every externally accessible service increases the

Security teams should maintain a current inventory of internet-facing systems and continuously verify that unnecessary services are disabled.

Patching should also prioritize vulnerabilities that are actively exploited or that expose authentication and remote-code-execution paths.

A vulnerability does not need to be particularly exotic to become dangerous.

It simply needs to be reachable and useful.

Backups Are the Last Line of Defense

When prevention fails, recovery determines how much power an attacker actually has.

A company with reliable, isolated, regularly tested backups is in a fundamentally stronger position than one whose only backup copies remain connected to the production environment.

Ransomware operators understand this.

That is why attackers frequently attempt to locate backup infrastructure, compromise administrative accounts, disable security tools, and interfere with recovery systems before deploying encryption.

A backup that cannot be restored is not a recovery strategy.

The Human Cost Behind the Listing

Behind every ransomware entry is an organization made up of people.

Employees may suddenly lose access to systems they depend on every day.

Customers may experience service interruptions.

Executives may face difficult decisions under intense pressure.

IT teams may work around the clock to rebuild infrastructure.

Legal departments may have to determine whether sensitive information was exposed.

For smaller organizations, the consequences can be even more severe because they may not have large incident-response teams or extensive financial reserves.

That is why ransomware prevention should be viewed as a business-resilience issue, not merely an IT security issue.

What Undercode Say:

Ransomware Reporting Is an Early-Warning System

Threat-intelligence reporting can provide defenders with an early warning before a complete incident picture becomes available.

The appearance of Bihl and Chernyy & Associates in the supplied intelligence highlights how quickly the ransomware ecosystem can generate new victim activity.

Security teams should monitor these signals without waiting for a formal breach announcement.

Actor Names Matter, But Attack Paths Matter More

Akira and Booba Project are useful identifiers for threat hunters.

However, defenders should not build detection programs exclusively around ransomware names.

Attackers change tools.

Affiliates switch malware.

Infrastructure is rebuilt.

The same access techniques can survive those changes.

Victim Listings Can Create Secondary Risk

Once an organization becomes publicly associated with a ransomware operation, it may attract additional attention.

Other criminals can begin looking for exposed infrastructure.

Scammers can impersonate attackers or company representatives.

Customers may become targets of phishing campaigns.

Employees may receive fraudulent recovery or payment requests.

A ransomware incident can therefore create a second wave of security risks.

Detection Speed Changes the Outcome

The difference between detecting an attacker during initial access and discovering the intrusion after widespread encryption can be enormous.

Early detection provides defenders with opportunities to disable compromised accounts, isolate endpoints, terminate malicious sessions, block command-and-control traffic, and preserve forensic evidence.

The earlier the response begins, the fewer options attackers have.

Identity Should Be Treated as Infrastructure

Modern ransomware defense increasingly starts with identity.

A compromised administrator account can be more valuable to an attacker than a vulnerable workstation.

Strong authentication, privileged access management, conditional access, session monitoring, and rapid credential revocation can significantly reduce the attacker’s ability to expand an intrusion.

Network Segmentation Limits Blast Radius

A flat network gives attackers room to move.

Segmentation creates friction.

Critical servers, identity systems, backups, workstations, development environments, and administrative infrastructure should not automatically trust one another.

When segmentation is correctly implemented, compromising one system does not necessarily mean compromising everything.

EDR Alone Is Not Enough

Endpoint detection and response is valuable, but ransomware defense requires multiple layers.

Identity telemetry, network monitoring, cloud logs, DNS visibility, email security, vulnerability management, and backup monitoring should work together.

Attackers exploit gaps between security products.

Defenders should therefore investigate the complete attack chain rather than isolated alerts.

Ransomware Resilience Requires Testing

Organizations often discover weaknesses in their recovery strategy only after an incident.

That is too late.

Backup restoration should be tested before attackers arrive.

Incident-response plans should be rehearsed.

Emergency communication procedures should be documented.

Critical business functions should have recovery priorities.

The goal is not simply to prevent ransomware.

The goal is to remain operational when prevention fails.

Threat Intelligence Should Become Actionable

A list of victim names has limited value if nobody knows what to do with it.

Threat intelligence becomes powerful when it connects directly to defensive action.

A newly observed ransomware actor can trigger searches for related indicators, suspicious authentication events, malware artifacts, domains, IP addresses, and unusual administrative activity.

Intelligence should feed detection.

Detection should feed investigation.

Investigation should feed remediation.

The Two Reports Show a Bigger Pattern

The Bihl and Chernyy & Associates entries are small pieces of a much larger ransomware landscape.

They demonstrate how multiple criminal groups can continue operating simultaneously.

They also show why organizations need continuous monitoring instead of periodic security checks.

Cybersecurity is not a project that ends after a firewall is configured or a vulnerability is patched.

It is a continuous contest between intrusion and defense.

The Most Dangerous Assumption

One of the biggest mistakes an organization can make is believing that it is too small or too unimportant to become a target.

Ransomware operations increasingly depend on scale.

Attackers can automate scanning, credential attacks, vulnerability discovery, and victim selection.

They do not necessarily need to personally identify every organization.

The internet does much of that work for them.

The Real Defensive Advantage

The strongest advantage defenders have is preparation.

An organization that knows its assets, protects its identities, monitors its endpoints, isolates its backups, segments its network, and rehearses incident response is harder to extort.

Attackers want uncertainty.

Defenders should create certainty.

Deep Analysis

Check Internet-Facing Assets

A basic Linux inventory can begin with:

sudo ss -tulpn

This helps administrators identify locally listening services that may require review.

Review Authentication Activity

On Linux systems using systemd, administrators can inspect authentication-related events with:

sudo journalctl --since "24 hours ago" | grep -Ei "failed|authentication|invalid|sudo"

The objective is to identify unusual authentication behavior rather than simply collect logs.

Search for Suspicious Processes

A quick process review can be performed with:

ps aux --sort=-%cpu | head -20

Unexpected processes consuming significant resources deserve investigation, particularly when combined with suspicious network connections or recently modified files.

Examine Network Connections

Administrators can review active network connections with:

sudo ss -antup

Unexpected outbound connections from sensitive servers can provide an important starting point for investigation.

Review Recently Modified Files

A targeted filesystem review can help identify unusual changes:

find /var/www /opt /tmp -type f -mtime -1 2>/dev/null

This should be adapted to the

Search for Scheduled Persistence

Attackers may attempt to establish persistence through scheduled jobs.

Administrators can inspect cron configuration with:

sudo crontab -l
sudo ls -la /etc/cron.

Unexpected scheduled tasks should be investigated rather than automatically deleted, because they may contain valuable forensic evidence.

Check Systemd Services

Suspicious persistence can also appear as a systemd service:

systemctl list-unit-files --state=enabled

Any unfamiliar service should be traced back to its installation source and expected business function.

Monitor Privileged Accounts

Reviewing privileged users remains essential:

getent group sudo

getent group wheel

Organizations should verify that every privileged account is authorized and still required.

Investigate File Encryption Indicators

A sudden increase in file modifications can be an important ransomware warning sign.

Security teams should correlate file-system events with process execution, authentication logs, and network telemetry.

Do not rely on file extensions alone.

Preserve Evidence

When investigating a suspected compromise, defenders should avoid destroying evidence unnecessarily.

Useful information can include process lists, authentication records, network connections, memory captures, endpoint telemetry, and relevant logs.

A rushed cleanup can make forensic reconstruction considerably harder.

Build Detection Around Behavior

Instead of searching only for names such as Akira or Booba Project, defenders should hunt for behaviors including credential dumping, lateral movement, privilege escalation, backup deletion, security-tool tampering, suspicious remote administration, and large-scale file modification.

Behavior survives malware rebranding.

Connect Threat Intelligence to SIEM

Threat-intelligence indicators should be incorporated into the

Security teams can then correlate external intelligence with internal events and determine whether known malicious infrastructure has interacted with corporate systems.

The Final Lesson

The appearance of two new ransomware victims on the same day is a reminder that the threat does not pause.

While defenders investigate one incident, another organization may already be facing initial access.

The strongest response is therefore not panic.

It is preparation.

Organizations that continuously monitor their attack surface, protect identities, segment critical infrastructure, maintain resilient backups, and investigate anomalies early can dramatically reduce the leverage ransomware operators are able to obtain.

✅ Threat Intelligence Attribution

The supplied material explicitly attributes the two ransomware entries to the ThreatMon Threat Intelligence Team and identifies Akira with Bihl and Booba Project with Chernyy & Associates. The article accurately presents those details as reported threat-intelligence activity.

✅ Two Separate Ransomware Entries

The source contains two separate entries dated August 24, 2026, involving different ransomware operations and different organizations. The timestamps and actor-victim pairings have been preserved from the supplied material.

❌ Full Attack Details Are Not Established by the Source

The supplied reports do not establish the initial access method, extent of compromise, stolen data, ransom demand, encryption status, or recovery impact. Those details should not be invented without additional forensic or official information.

Prediction

(+1) Ransomware Victim Listings Will Continue to Increase

As ransomware groups and affiliates continue operating at scale, additional organizations are likely to appear in threat-intelligence monitoring during the coming weeks.

(+1) Threat Intelligence Will Become More Important

Early visibility into emerging victim listings, infrastructure, indicators, and attacker behavior will increasingly help organizations prioritize investigations before incidents become larger crises.

(+1) Identity Security Will Remain a Major Defensive Priority

Attackers will continue targeting credentials because valid access can provide a quieter and more flexible path into enterprise environments than noisy exploitation alone.

(-1) Organizations Relying Only on Perimeter Security Will Face Greater Risk

Traditional perimeter defenses will provide less protection against attackers using valid credentials, trusted remote-access tools, cloud identities, and compromised internal accounts.

Conclusion

The August 24 ransomware activity involving Bihl and Chernyy & Associates is more than another pair of entries in an expanding threat-intelligence feed.

It illustrates the speed, scale, and persistence of the modern ransomware economy.

Akira and Booba Project may use different infrastructure, different tooling, and different affiliates, but the fundamental objective remains familiar: obtain access, create leverage, and turn that leverage into profit.

For defenders, the message is equally clear.

Do not wait for encryption.

Do not wait for a ransom note.

Do not wait for an organization to appear publicly on a victim list.

Find the weak identity, exposed service, abnormal login, suspicious process, and unexplained network connection before an attacker can turn it into a crisis.

In ransomware defense, the most valuable advantage is often the few hours of visibility that exist before the damage becomes impossible to ignore.

▶️ Related Video (82% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.quora.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube