Black Basta is a ransomware-as-a-service operation that emerged in 2022 and is associated with the Cardinal cybercrime group, also tracked as Storm-1811 and UNC4393. It is widely assessed as part of the post-Conti ransomware ecosystem and has conducted financially motivated double-extortion attacks: operators exfiltrate victim data, encrypt systems, and threaten publication of stolen material to compel payment. The group has targeted organizations across numerous industries, including healthcare, public health, construction, finance, manufacturing, energy, government-related services, and professional services, with substantial activity affecting organizations in the United States, Europe, and Canada.
Black Basta operators use varied initial-access methods, including spearphishing, Microsoft Teams phishing, email-bombing-assisted vishing, fraudulent IT-support calls, credential stuffing, abuse of leaked credentials, access-brokered accounts, and exploitation of vulnerabilities in internet-facing enterprise software and perimeter devices. QakBot was a prominent access and post-exploitation component in earlier operations; following its 2023 disruption, activity linked to Black Basta increasingly used loaders and stealers including DarkGate, PikaBot, Lumma, and other commercially available or custom tooling. Operators have also used adversary-in-the-middle phishing infrastructure to intercept authentication cookies and bypass MFA.
Post-compromise activity includes reconnaissance of hosts, Active Directory, remote-access services, and network shares; credential theft and cracking; privilege escalation; lateral movement through remote administration mechanisms; persistence; and defense evasion. The group has extensively used Cobalt Strike and related tooling for command execution, payload staging, process injection, and command-and-control concealment. Observed ransomware execution can stop services and processes, remove volume shadow copies, alter boot configuration to encrypt systems in Safe Mode, encrypt files, and present ransom instructions. Black Basta has used ChaCha20 or XChaCha20-based file encryption protected by asymmetric cryptography; some versions introduced elliptic-curve cryptography and per-victim randomized encrypted-file extensions.
Black Basta ransomware targets Windows environments and has dedicated Linux and VMware ESXi encryptors. ESXi-focused deployments can encrypt virtual-machine storage, creating infrastructure-wide disruption. The group has maintained leak-site and negotiation operations to support extortion and has used direct contact with victim executives to increase payment pressure. Internal disputes and public leaks disrupted its visible activity in 2025, but its operators, affiliates, and tradecraft remain relevant to ransomware investigations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
41 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VMware ESXi hypervisors joined to an Active Directory domain grant full administrative access by default to members of a domain group named "ESX Admins." Attackers create that group or add controlled accounts to it to gain administrative access. | Ransomware operators such as BlackByte, Storm-0506, Storm-1175, Octo Tempest, and Manatee Tempest have been actively exploiting CVE-2024-37085 ... where some of these cases have led to Akira and Black Basta ransomware deployments.
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Group members also discussed CVE-2024-23113 and CVE-2024-25600 in internal communications prior to their formal release. This once again indicates a proactive focus on monitoring emerging vulnerabilities and an ability to rapidly transition from awareness to exploitation. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers.
A particularly significant mention is CVE-2024-24919 (CheckPoint VPN authentication bypass), which was evidently purchased by a GG. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
The chat logs include discussions about CVE-2023-36884 (Windows HTML-based RCE), CVE-2022-30190 (Follina), CVE-2021-40444 (MSHTML exploit), and CVE-2017-11882 (Equation Editor RCE), with specific mentions of embedding these exploits into phishing lures. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
The chat logs include discussions about CVE-2023-36884 (Windows HTML-based RCE), CVE-2022-30190 (Follina), CVE-2021-40444 (MSHTML exploit), and CVE-2017-11882 (Equation Editor RCE), with specific mentions of embedding these exploits into phishing lures. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Group members also discussed CVE-2024-23113 and CVE-2024-25600 in internal communications prior to their formal release. This once again indicates a proactive focus on monitoring emerging vulnerabilities and an ability to rapidly transition from awareness to exploitation. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
The chat logs include discussions about CVE-2023-36884 (Windows HTML-based RCE), CVE-2022-30190 (Follina), CVE-2021-40444 (MSHTML exploit), and CVE-2017-11882 (Equation Editor RCE), with specific mentions of embedding these exploits into phishing lures. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Exploits such as CVE-2023-4966 (Citrix NetScaler), CVE-2024-3400 (Palo Alto GlobalProtect RCE), and CVE-2024-23108/CVE-2024-23109 (Fortinet FortiOS) appear in multiple conversations related to mass exploitation efforts. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
CVE-2023-42115, a vulnerability in Exim – a widely used mail transfer agent (MTA) for Unix-based systems – is another notable example. At the time of its disclosure, over 3.5 million Exim servers were exposed to the internet globally. Chat discussions suggest early awareness of this vulnerability within the group. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Exploits such as CVE-2023-4966 (Citrix NetScaler), CVE-2024-3400 (Palo Alto GlobalProtect RCE), and CVE-2024-23108/CVE-2024-23109 (Fortinet FortiOS) appear in multiple conversations related to mass exploitation efforts. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Another key mention is CVE-2023-38831 (WinRAR RCE), used for executing secondary-stage malware. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527). | Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.
In one intrusion, we observed the Black Basta operator exploiting the PrintNightmare vulnerability and dropping spider.dll as the payload. | Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.
20 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Following Conti's 2022 disbandment, members of the Cyrillic-language group rebranded under subgroups including Black Basta.
Ransomware operators such as BlackByte, Storm-0506, Storm-1175, Octo Tempest, and Manatee Tempest have been actively exploiting CVE-2024-37085 ... where some of these cases have led to Akira and Black Basta ransomware deployments.
Ransomware operators such as BlackByte, Storm-0506, Storm-1175, Octo Tempest, and Manatee Tempest have been actively exploiting CVE-2024-37085 ... where some of these cases have led to Akira and Black Basta ransomware deployments.
Ransomware operators such as BlackByte, Storm-0506, Storm-1175, Octo Tempest, and Manatee Tempest have been actively exploiting CVE-2024-37085 ... where some of these cases have led to Akira and Black Basta ransomware deployments.
Ransomware operators such as BlackByte, Storm-0506, Storm-1175, Octo Tempest, and Manatee Tempest have been actively exploiting CVE-2024-37085 ... where some of these cases have led to Akira and Black Basta ransomware deployments.
Ransomware operators such as BlackByte, Storm-0506, Storm-1175, Octo Tempest, and Manatee Tempest have been actively exploiting CVE-2024-37085 ... where some of these cases have led to Akira and Black Basta ransomware deployments.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
the threat actor moved laterally on many machines through Windows Management Instrumentation (WMI) ... WMI is leveraged to execute the malicious commands and the ransomware
After infecting the target network the ransomware performs the following actions:- Reconnaissance Collect data Credentials Move laterally Download payloads Execute payloads
YY later inquired if GG's suggestion was to rewrite C# in C#, revealing that Tramp instructed to rewrite the malware from C# to Python using ChatGPT.
These included the use of batch scripts masquerading as software updates.
YY (coder of Black Basta) was instructed to rewrite the tools in Python as some of the gang’s malware got detected by AV/EDR. GG asked YY to use ChatGPT for that... Tramp instructed to rewrite the malware from C# to Python using ChatGPT.
The exploit takes advantage of this to create a "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WerFault.exe" registry key where it sets the "Debugger" value as its own executable pathname. This allows the exploit to start a shell with administrative privileges.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day. The vulnerability (CVE-2024-26169) occurs in the Windows Error Reporting Service. If exploited on affected systems, it can permit an attacker to elevate their privileges.
BlackBasta ransomware developer appears to be experimenting with stack-based string obfuscation using ADVObfuscator... Many of the malware’s strings have been obfuscated and the filenames have been randomized, which may hinder static-based antivirus detection and behavioral-based EDR detection.
In order to start in safe mode, the ransomware executes the following commands: C:\Windows\SysNative\bcdedit /set safeboot networkChanges C:\Windows\System32\bcdedit /set safeboot networkChanges
BlackBasta 2.0 opens the ransom note in Windows Notepad via the command cmd.exe /c start /MAX notepad.exe .
the script calls the msiexec.exe, trying to uninstall the corresponding package of the EDR/antivirus.
The exploit takes advantage of this to create a "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WerFault.exe" registry key where it sets the "Debugger" value as its own executable pathname. This allows the exploit to start a shell with administrative privileges.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Multiple entries describe enumerating local, logical, or physical drives and disk/volume information, e.g., 'can enumerate local drives,' 'GetLogicalDrives,' 'fsutil fsinfo drives,' 'list drives,' and 'discover logical drive information including the drive type, free space, and volume information.'
Successful exploitation leads to full administrative access to the ESXi hypervisors, allowing threat actors to encrypt the file system of the hypervisor.
251 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group/family identified as a rebrand or successor subgroup formed by former Conti members after Conti disbanded.
Ransomware operation whose leaked chats reportedly show use of ChatGPT for operational tasks, including phishing, persistence-tool debugging, and validation of stolen email addresses.
Ransomware used in the March 2023 attack against Capita; the incident reportedly involved exfiltration of more than six million individuals' records.
A ransomware family mentioned only as another beneficiary of the leaked Conti source code.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.