Black Basta is a financially motivated, Russian-language ransomware-as-a-service operation that emerged in 2022, reportedly drawing on the post-Conti cybercriminal ecosystem. It conducts double-extortion attacks: operators and affiliates steal data, encrypt victim environments, and threaten public disclosure through a dedicated leak site. Black Basta has targeted organizations across numerous sectors, with heavily affected regions including the United States, Germany, the United Kingdom, Canada, Italy, and Switzerland. Confirmed victim activity includes attacks against U.S. public-health organizations and the UK business-services provider Capita. The group uses diverse initial-access methods, including phishing, Microsoft Teams impersonation, fraudulent IT-support calls, malicious attachments and disk-image delivery, credential stuffing, brute-force activity, stolen credentials, and exploitation of exposed VPN, firewall, remote-access, and enterprise application services. Its phishing operations have used reverse-proxy credential interception and cookie theft to bypass multifactor authentication. Black Basta has also used reconnaissance services and internet scanners to identify targets and exposed services. Post-compromise operations commonly involve QakBot, DarkGate, Pikabot, Lumma Stealer, Cobalt Strike, Rclone, Mimikatz, and remote-management tooling. Operators conduct Active Directory and network discovery, dump credentials, move laterally using remote administration protocols and Windows management mechanisms, establish persistence, evade defenses by disabling or uninstalling security products, and remove shadow copies before encryption. Leaked internal communications indicate structured specialization across infrastructure, social engineering, credential handling, data exfiltration, malware operations, and negotiations. The group appeared to cease publishing victims in early 2025 amid internal conflict; possible rebranding or successor activity has been suggested but is not confirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
67 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 malware families attributed to this actor across reporting.
14 additional families tracked in Mallory.
19 CVEs this actor has used in observed campaigns. 19 of them exploited in the wild.
↑のプロセスを脆弱なNsecSoft NSecKrnlドライバで止める CVE-2025-68947に関連するNsecSoft NSecKrnlドライバでサービス作成を試みて、そのサービスで脆弱性悪用によりカーネルレベルからプロセスキルや検知機能阻害を行う感じ。
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527).
In one intrusion, we observed the Black Basta operator exploiting the PrintNightmare vulnerability and dropping spider.dll as the payload.
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527).
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers.
14 more CVEs tied to this actor tracked in Mallory.
342 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as one of several ransomware families tied to Woodgnat/KongTuke.
Cited in connection with Rclone use in cloud data-theft incidents.
Used or discussed using ChatGPT to improve operational tasks, including phishing, persistence-tool debugging, and validation of stolen email addresses.
A ransomware group potentially connected to Warlock; the report notes an unconfirmed possible offshoot or rebranding relationship based on similarities in tactics, negotiation style, and victimology.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.