Black Basta is a ransomware family and ransomware-as-a-service operation that emerged in 2022 and rapidly became a major extortion threat to enterprises and critical infrastructure organizations worldwide. It has been associated with large-scale victimization across multiple industries, including sectors with low tolerance for downtime, and has targeted organizations in numerous U.S. critical infrastructure sectors. The operation is widely assessed as part of the post-Conti Russian-speaking ransomware ecosystem, with reporting and leaked internal communications indicating overlap in personnel, tradecraft, and tooling with other major criminal groups.
Black Basta intrusions commonly combine data theft and file encryption as part of a double-extortion model. Operators are known to conduct deliberate victim profiling before deployment, evaluating factors such as revenue, operational dependence, cyber insurance, and the sensitivity of stolen information in order to tailor ransom demands and negotiation strategy. The group has also been linked to pressure tactics beyond encryption and exfiltration, including harassment and operational disruption intended to increase the likelihood of payment.
Initial access associated with Black Basta has included phishing and malware delivery through malicious Office documents, exploitation of vulnerabilities, use of exposed remote access services, and purchases from initial access brokers. More recent activity linked to Black Basta and closely aligned clusters has prominently used social engineering: victims are first overwhelmed with spam or subscription emails, then contacted through Microsoft Teams or by phone by attackers impersonating IT support, who persuade them to launch remote assistance tools such as Quick Assist. Once access is obtained, operators deploy additional tooling, establish persistence, harvest credentials, perform reconnaissance, and move laterally before attempting ransomware execution.
On Windows systems, Black Basta has been observed creating new services for persistence and modifying the Registry, including changes that support execution in Safe Mode and alter the appearance of encrypted files. Reporting also links Black Basta-associated activity to credential theft, keylogging, network scanning, and lateral movement in pre-ransomware phases. The group has used a broad ecosystem of loaders, backdoors, and post-exploitation tooling, and leaked chats indicate reliance on outsourced specialists and rented malware services as part of a mature criminal operating model.
Black Basta has also operated Linux encryptors, reflecting the broader ransomware trend toward targeting virtualized and server environments in addition to Windows endpoints. Public reporting describes the group as a highly organized extortion enterprise with structured internal roles, negotiation processes, and affiliate-style operations. By 2025, leaks of internal chats exposed extensive details about its targeting, negotiations, internal disputes, and possible rebranding or migration of members to other ransomware operations such as Cactus.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
I conducted a retrospective study on the vulnerability CVE-2023-4966, commonly known as Citrix Bleed, which allows attackers to easily bypass authentication in Citrix's Citrix ADC and Citrix Gateway products, over the course of six months. Initially exploited by some attackers as a zero-day in August 2023, a patch was released on October 10, followed by the publication of a PoC in late October, after which various attackers exploited the vulnerability.
CVE-2024–3400 is a high severity vulnerability with a CVSS score of 10.0 in Palo Alto Networks PAN OS that allows arbitrary file creation and command injection. When chat logs from the Black Basta ransomware gang were leaked, messages sharing details about this vulnerability were actively posted in the leaked logs.
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527). | Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527). | Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.
In one intrusion, we observed the Black Basta operator exploiting the PrintNightmare vulnerability and dropping spider.dll as the payload. | Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527). | Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.
Black Basta infections began with Qakbot delivered by email and macro-based MS Office documents, ISO+LNK droppers and .docx documents exploiting the MSDTC remote code execution vulnerability, CVE-2022-30190.
Of the ransomware that was deployed in the incidents – Royal, Black Basta, and Hive... While some of the behaviors in the Black Basta attack... Initial access, in this case, came from a JSP web shell installed on an internet-facing ManageEngine server that had a vulnerability. | In January 2023, at around the same timeframe in which the attacks took place, ManageEngine’s publisher Zoho released a security advisory detailing CVE-2022-47966 an unauthenticated remote code execution vulnerability. In January 2023 there were also reports of attacks against this vulnerability.
A particularly effective technique CVE-2024–37085 allows any member of a specially named AD group to receive full administrative rights on the hypervisor without additional authentication. Ransomware operators simply create the “ESX Admins” group via net group commands and add their controlled account, granting instant ESXi admin access. | This method was observed in high-tempo operations linked to Medusa affiliates (Storm-1175) and has been adopted by multiple groups deploying Akira and Black Basta payloads.
"#StopRansomware: Black Basta" ... "Black Basta, a ransomware variant whose actors have encrypted and stolen data..."
The threat actor gained initial access to the organization via Qakbot infection, followed by the exploitation of a Windows CLFS vulnerability (CVE-2023-28252) to elevate their privileges on affected devices.
CVE-2023-34992: phMontior Service Command Injection
CVE-2024-23108: phMonitor Service Second-Order Command Injection
Technical details and a public exploit have been published for a critical vulnerability affecting Fortinet's Security Information and Event Management (SIEM) solution... The vulnerability is tracked as CVE-2025-25256... may allow an unauthenticated attacker to execute unauthorized code or commands via crafted TCP requests.
“The NSecKrnl driver is a Windows kernel-mode driver with a known critical security vulnerability (CVE-2025-68947), which means that it fails to verify if a user has sufficient permissions before executing commands. This allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes, by issuing crafted Input/Output Control (IOCTL) requests to the driver.”
15 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It is the signature opening move of cyber-criminal crews linked to the notorious Black Basta ransomware operation, alongside a rising tide of copycats executing the same play.
Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.
Conti disbanded later that year, but members of the Cyrillic-language group rebranded under three subgroups: Zeon, Black Basta and Quantum, which quickly rebranded to Royal, before rebranding again to BlackSuit in 2024.
This blog post documents some of the TTPs employed by a threat actor group who were observed deploying Black Basta ransomware during a recent incident response engagement, as well as a breakdown of the executable file which performs the encryption.
For example, DEV-0506 was deploying BlackBasta part-time before the Conti shutdown and is now deploying it regularly.
Devman declined by 70%, from 82 victims to 25. The ransomware’s operator “Tramp”, a former Conti and Black Basta affiliate, was added to Interpol’s wanted list in January 2026.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
YY later inquired if GG's suggestion was to rewrite C# in C#, revealing that Tramp instructed to rewrite the malware from C# to Python using ChatGPT.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions. | APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. Blue Mockingbird has used batch script files to automate execution and deployment of payloads. During HomeLand Justice, threat actors used Windows batch files for persistence and execution.
YY (coder of Black Basta) was instructed to rewrite the tools in Python as some of the gang’s malware got detected by AV/EDR. GG asked YY to use ChatGPT for that... Tramp instructed to rewrite the malware from C# to Python using ChatGPT.
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
After a few days, the actors call the victim, usually via Microsoft Teams, and direct them to initiate a Microsoft Quick Assist remote access session...
Black Basta has been observed spreading via Group Policy Objects (GPO).
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Multiple entries describe enumerating local, logical, or physical drives and disk/volume information, e.g., 'can enumerate local drives,' 'GetLogicalDrives,' 'fsutil fsinfo drives,' 'list drives,' and 'discover logical drive information including the drive type, free space, and volume information.'
The Black Basta group discovered that they had not encrypted the Ascension Healthcare data correctly due to a crypt error and decided to share the decryption key to avoid potential political sanctions and retaliation from US law enforcement against their infrastructure.
Once a Quick Assist session is established, the adversary loads tooling to collect information about the target system and establish persistence... disable endpoint protections... Of note, we also observed the affiliates using HRSword to disable the target’s EDR solution.
file1.bat : a batch file designed to set up the system with autologon as the newly-created administrative user AdminBac, reboot into Safe Mode ... file2.bat : a second batch file, executed in Safe Mode via a registry key, designed to unpack the ransomware binary from the encrypted archive
51 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
186 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example of malware associated with abuse of code-signing certificates.
A ransomware operation mentioned as having used Media Land LLC hosting services.
Ransomware family mentioned in connection with an alleged founder/operator discussed as part of enforcement outcomes for Russian-speaking cybercriminals.
Black Basta is mentioned as a ransomware operation used as a comparison for negotiation tactics in extortion cases.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.