Black Basta is a Russian-linked ransomware-as-a-service operation that emerged in 2022 and is widely assessed as a successor to the Conti ecosystem. The group became one of the most active ransomware threats globally, targeting hundreds of organizations, including entities across U.S. critical infrastructure sectors. Internal leaks exposed a structured criminal enterprise with operators, affiliates, negotiators, social-engineering personnel, and outsourced support functions, as well as evidence of intelligence-driven victim selection and detailed pre-attack profiling. Reporting has also described confirmed links between Black Basta and Russian intelligence services, although specific command relationships are not publicly established at high confidence. Black Basta has conducted financially motivated intrusions centered on data theft and ransomware deployment, and has used multi-pressure extortion tactics including encryption, exfiltration, leak-site pressure, deadline manipulation, and in some reporting harassment and DDoS as additional coercive layers. The group has relied on both direct intrusion activity and affiliate-driven access, including initial access brokers, exposed remote services, and brute-force operations. Leaked communications indicate systematic tracking of victims, use of numerous known vulnerabilities, and prioritization of organizations judged likely to pay quickly, especially those with low tolerance for downtime. Observed tradecraft includes phishing and social engineering, especially email flooding followed by Microsoft Teams impersonation of IT support staff to induce victims to launch remote-support tools such as Quick Assist. Black Basta activity has also been associated with abuse of remote access software, exploitation of edge devices and public-facing applications, scanning for exposed RDP, brute-force frameworks targeting enterprise perimeter technologies, and post-compromise use of legitimate administration tools. Across reporting, the group and its affiliates have been linked to persistence mechanisms, credential abuse, lateral movement via RDP, data exfiltration, and defense evasion through continual changes to tooling and deployment methods. Malware and tooling associated with Black Basta operations or affiliates have included SystemBC and social-engineering-led backdoor delivery chains, and some former affiliates have been tied to later clusters using similar Teams and Quick Assist intrusion patterns. Black Basta maintained a public leak site and operated as a classic RaaS ecosystem with affiliates. Multiple reports indicate the operation effectively collapsed or dissolved in early 2025 after internal chat logs were leaked, though former members or affiliates are believed to have migrated to other ransomware operations and continued using closely related tactics. Known aliases and related references include BlackBasta, Black Basta affiliates, and historically reported ties to the broader Conti lineage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
↑のプロセスを脆弱なNsecSoft NSecKrnlドライバで止める CVE-2025-68947に関連するNsecSoft NSecKrnlドライバでサービス作成を試みて、そのサービスで脆弱性悪用によりカーネルレベルからプロセスキルや検知機能阻害を行う感じ。
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527).
In one intrusion, we observed the Black Basta operator exploiting the PrintNightmare vulnerability and dropping spider.dll as the payload.
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527).
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527).
2 more CVEs tied to this actor tracked in Mallory.
84 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a prior example of Teams-based social engineering by ransomware affiliates, not as part of the main STAC4749 campaign.
Groupe cybercriminel dont des liens avec les services de renseignement russes sont mentionnés, illustrant la dissimulation étatique par procuration.
Mentioned only in passing as a background association to an infrastructure operator.
Ransomware group cited as using the sanctioned bulletproof hosting service Media Land LLC.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.