Black Basta is a financially motivated ransomware group that emerged in February 2022 and is widely assessed as a successor operation to the Conti ecosystem, with ties to former Conti operators and affiliates. It became one of the most active closed-shop ransomware crews of the 2022-2025 period, conducting double-extortion attacks that combined data theft with file encryption and public leak-site pressure. The group primarily targeted organizations in North America and Europe across multiple sectors, including business services, healthcare, finance, government, and other enterprises of operational or financial value. Black Basta is known for aggressive intrusion tradecraft centered on obtaining initial access through credential abuse, phishing, exploitation of exposed services, and later increasingly through social-engineering-heavy techniques. Reporting links Black Basta-associated actors to spam bombing, Microsoft Teams impersonation of IT support personnel, and abuse of Quick Assist to gain remote access. The group and associated clusters have also been tied to use of loaders, proxy malware, and backdoors such as SystemBC and GhostSocks, as well as post-compromise tooling for reconnaissance, credential theft, lateral movement, persistence, and defense evasion. Observed behaviors include use of legitimate remote management tools, scheduled tasks, registry-based persistence, shadow-copy deletion, event-log clearing, and attempts to disable security controls and multifactor authentication. Black Basta operated as a ransomware enterprise rather than a broad open affiliate program, and later leaks of internal communications provided unusual visibility into its internal organization, negotiations, budgeting, procurement, and attack planning. Those leaks reinforced assessments of continuity with the TrickBot and Conti criminal ecosystem. The group also expanded to Linux encryption capabilities as part of the broader trend of ransomware actors targeting virtualized and server environments in addition to Windows systems. By February 2025, Black Basta was reported to have collapsed after its internal chat logs were leaked publicly. Despite the apparent dissolution of the core brand, former Black Basta affiliates and access brokers continued operating under other banners. Subsequent activity has been linked to successor or related clusters associated with Cactus, 3AM, and especially Payouts King, which reused overlapping initial-access methods, social-engineering playbooks, and post-compromise tradecraft. Black Basta is therefore best understood both as a distinct ransomware gang active from 2022 to 2025 and as part of a broader post-Conti criminal network whose personnel, tooling, and tactics persisted beyond the group’s formal demise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.