Skip to main content
Mallory
3 malware familiesExploits CVEs in the wild

Black Basta

Also known asblack_basta

Black Basta is a Russia-linked ransomware-as-a-service group active from early 2022 until its internal chat logs were leaked in February 2025. It is described as a ransomware gang that emerged rapidly in April 2022, compromising at least a dozen companies within weeks, targeting organizations worldwide, and using double extortion: stealing corporate data before encrypting systems and threatening publication on its Tor leak site, referred to as the "Black Basta Blog" or "Basta News," with negotiations conducted through a separate "Chat Black Basta" portal. Reported victims and impacts in the provided content include Capita, where the group compromised Microsoft Office 365 and accessed personal data of staff and clients. Observed Black Basta tradecraft in the provided content includes targeted email bombing followed by phone- or Microsoft Teams-based help desk impersonation, often persuading victims to install remote access tools such as AnyDesk or use Quick Assist. Multiple reports state this social-engineering pattern became strongly associated with former Black Basta affiliates and continued after the group’s internal conflict and collapse in early 2025. The content also links former Black Basta affiliates or derived crews to rapid Teams-vishing intrusions, sometimes progressing from contact to malicious execution in as little as 12–20 minutes. Technical behaviors attributed to Black Basta ransomware in the content include requiring administrative privileges, deleting Volume Shadow Copies via vssadmin, hijacking an existing Windows service, rebooting systems into Safe Mode with Networking before encryption, dropping readme.txt ransom notes, changing the desktop wallpaper, appending the .basta extension to encrypted files, and using ChaCha20 for file encryption with RSA-4096 to protect encryption keys. The content also notes Black Basta among ransomware families observed targeting VMware ESXi environments. The provided content repeatedly connects Black Basta to the broader Conti ecosystem. It states that after Conti disbanded, members rebranded into subgroups including Zeon, Black Basta, and Quantum, with Quantum later becoming Royal and then BlackSuit. Some reporting cited in the content speculated Black Basta may have been a Conti rebrand based on similarities in negotiation style and leak-site behavior, but that linkage is presented as unconfirmed. The content further states that Black Basta’s leaked internal chats in early 2025 exposed operational structure, internal conflicts, and figures such as Tramp, after which affiliates dispersed to other groups including Chaos, INC, Lynx, Cactus, and Nokoyawa. Related successor or affiliate-linked activity in the content includes BlackSuit and crews tracked as former Black Basta affiliates.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

15 of 15 tactics74 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1589
Gather Victim Identity Information
T1598×2
Phishing for Information
T1598.004
Spearphishing Voice
TA0042
Resource Development
1 technique
T1588
Obtain Capabilities
TA0001
Initial Access
3 techniques
T1078×3
Valid Accounts
T1078.004
Cloud Accounts
T1190×2
Exploit Public-Facing Application
T1566×5
Phishing
T1566.001
Spearphishing Attachment
T1566.003×4
Spearphishing via Service
T1566.004
Spearphishing Voice
TA0002
Execution
6 techniques
T1047
Windows Management Instrumentation
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1059×5
Command and Scripting Interpreter
T1059.001×2
PowerShell
T1059.003
Windows Command Shell
T1203
Exploitation for Client Execution
T1204×2
User Execution
T1569
System Services
T1569.002
Service Execution
TA0003
Persistence
7 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1078×3
Valid Accounts
T1078.004
Cloud Accounts
T1098
Account Manipulation
T1112×4
Modify Registry
T1136
Create Account
T1505
Server Software Component
T1505.003
Web Shell
T1543
Create or Modify System Process
T1543.003
Windows Service
TA0004
Privilege Escalation
5 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1078×3
Valid Accounts
T1078.004
Cloud Accounts
T1098
Account Manipulation
T1484
Domain or Tenant Policy Modification
T1484.001×2
Group Policy Modification
T1543
Create or Modify System Process
T1543.003
Windows Service
TA0005
Stealth
4 techniques
T1036
Masquerading
T1070
Indicator Removal
T1070.004
File Deletion
T1078×3
Valid Accounts
T1078.004
Cloud Accounts
T1218
System Binary Proxy Execution
T1218.010
Regsvr32
TA0112
Defense Impairment
2 techniques
T1112×4
Modify Registry
T1484
Domain or Tenant Policy Modification
T1484.001×2
Group Policy Modification
TA0006
Credential Access
1 technique
T1003
OS Credential Dumping
TA0007
Discovery
4 techniques
T1016
System Network Configuration Discovery
T1046
Network Service Discovery
T1082
System Information Discovery
T1083
File and Directory Discovery
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.001×2
Remote Desktop Protocol
T1021.002×2
SMB/Windows Admin Shares
TA0009
Collection
1 technique
T1074
Data Staged
TA0011
Command and Control
4 techniques
T1071×2
Application Layer Protocol
T1090
Proxy
T1090.003
Multi-hop Proxy
T1105×4
Ingress Tool Transfer
T1219×8
Remote Access Tools
TA0010
Exfiltration
3 techniques
T1041
Exfiltration Over C2 Channel
T1537
Transfer Data to Cloud Account
T1567×2
Exfiltration Over Web Service
TA0040
Impact
5 techniques
T1485
Data Destruction
T1486×7
Data Encrypted for Impact
T1490×4
Inhibit System Recovery
T1491
Defacement
T1491.001
Internal Defacement
T1529
System Shutdown/Reboot
WEAPONIZED

Associated vulnerabilities

6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.

1 more CVE tied to this actor tracked in Mallory.

IOCS

Observables

13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping53

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs6

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables13

Domains, IPs, and hashes tied to this actor, refreshed continuously.