Black Basta is a ransomware-as-a-service operation that emerged in 2022 and is associated with the Cardinal cybercrime group, also tracked as Storm-1811 and UNC4393. It conducts double-extortion attacks, exfiltrating victim data before encrypting systems and threatening publication through leak-site operations if payment is not made. The group has targeted hundreds of organizations across numerous sectors, including healthcare, construction, finance, manufacturing, energy, and public services, with heavily affected regions including the United States, Germany, the United Kingdom, Canada, Italy, and Switzerland.
Black Basta ransomware has Windows and VMware ESXi/Linux-targeting variants. Windows variants encrypt files using ChaCha20 or XChaCha20 with asymmetric cryptographic protection of encryption material; a major revised codebase also adopted elliptic-curve cryptography and per-victim file extensions. Its impact and recovery-inhibition behaviors include deleting Volume Shadow Copies, stopping services and processes, and rebooting hosts into Safe Mode for encryption. Some variants alter the desktop wallpaper to display ransom instructions. ESXi-focused variants encrypt virtual-machine storage, creating data-center-scale operational risk.
Black Basta operations commonly obtain access through phishing and spearphishing, credential abuse against exposed remote-access services, exploitation of perimeter-device and Microsoft vulnerabilities, and social engineering. Observed campaigns have used malicious attachments and links, HTML smuggling, weaponized Excel add-ins, QR-code phishing, email bombing followed by Microsoft Teams impersonation, and fraudulent IT-support calls intended to persuade users to install remote-access software. QakBot was extensively used as an initial-access and post-exploitation precursor before its disruption, while later activity has been associated with DarkGate, PikaBot, Lumma, and other malware services.
Post-compromise operations use reconnaissance, credential theft, privilege escalation, lateral movement, persistence, and defense evasion. Black Basta affiliates have used Cobalt Strike, remote execution, Windows administrative services, credential cracking, and exploitation of Windows privilege-escalation vulnerabilities. Leaked internal communications indicate a structured criminal operation with specialized infrastructure, social-engineering, access, malware-development, data-exfiltration, and negotiation functions. Activity reportedly declined following internal conflict and exposure of internal chats in early 2025, though personnel and tradecraft may reappear under other ransomware brands.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
41 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Group members also discussed CVE-2024-23113 and CVE-2024-25600 in internal communications prior to their formal release. This once again indicates a proactive focus on monitoring emerging vulnerabilities and an ability to rapidly transition from awareness to exploitation. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers.
A particularly significant mention is CVE-2024-24919 (CheckPoint VPN authentication bypass), which was evidently purchased by a GG. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
The chat logs include discussions about CVE-2023-36884 (Windows HTML-based RCE), CVE-2022-30190 (Follina), CVE-2021-40444 (MSHTML exploit), and CVE-2017-11882 (Equation Editor RCE), with specific mentions of embedding these exploits into phishing lures. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
The chat logs include discussions about CVE-2023-36884 (Windows HTML-based RCE), CVE-2022-30190 (Follina), CVE-2021-40444 (MSHTML exploit), and CVE-2017-11882 (Equation Editor RCE), with specific mentions of embedding these exploits into phishing lures. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Group members also discussed CVE-2024-23113 and CVE-2024-25600 in internal communications prior to their formal release. This once again indicates a proactive focus on monitoring emerging vulnerabilities and an ability to rapidly transition from awareness to exploitation. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
The chat logs include discussions about CVE-2023-36884 (Windows HTML-based RCE), CVE-2022-30190 (Follina), CVE-2021-40444 (MSHTML exploit), and CVE-2017-11882 (Equation Editor RCE), with specific mentions of embedding these exploits into phishing lures. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Exploits such as CVE-2023-4966 (Citrix NetScaler), CVE-2024-3400 (Palo Alto GlobalProtect RCE), and CVE-2024-23108/CVE-2024-23109 (Fortinet FortiOS) appear in multiple conversations related to mass exploitation efforts. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
CVE-2023-42115, a vulnerability in Exim – a widely used mail transfer agent (MTA) for Unix-based systems – is another notable example. At the time of its disclosure, over 3.5 million Exim servers were exposed to the internet globally. Chat discussions suggest early awareness of this vulnerability within the group. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Exploits such as CVE-2023-4966 (Citrix NetScaler), CVE-2024-3400 (Palo Alto GlobalProtect RCE), and CVE-2024-23108/CVE-2024-23109 (Fortinet FortiOS) appear in multiple conversations related to mass exploitation efforts. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Another key mention is CVE-2023-38831 (WinRAR RCE), used for executing secondary-stage malware. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527). | Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.
In one intrusion, we observed the Black Basta operator exploiting the PrintNightmare vulnerability and dropping spider.dll as the payload. | Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527). | Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.
19 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.
The Cybereason Global SOC (GSOC) team is investigating Qakbot infections observed in customer environments related to a potentially widespread ransomware campaign run by Black Basta.
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.
Proofpoint has associated TA577 campaigns with follow-on ransomware infections including Black Basta.
Black Basta is a ransomware-as-a-service (RaaS) group that emerged in April 2022 and has since attacked over 500 organizations worldwide.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
the threat actor moved laterally on many machines through Windows Management Instrumentation (WMI) ... WMI is leveraged to execute the malicious commands and the ransomware
After infecting the target network the ransomware performs the following actions:- Reconnaissance Collect data Credentials Move laterally Download payloads Execute payloads
YY later inquired if GG's suggestion was to rewrite C# in C#, revealing that Tramp instructed to rewrite the malware from C# to Python using ChatGPT.
These included the use of batch scripts masquerading as software updates.
YY (coder of Black Basta) was instructed to rewrite the tools in Python as some of the gang’s malware got detected by AV/EDR. GG asked YY to use ChatGPT for that... Tramp instructed to rewrite the malware from C# to Python using ChatGPT.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
The exploit takes advantage of this to create a "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WerFault.exe" registry key where it sets the "Debugger" value as its own executable pathname. This allows the exploit to start a shell with administrative privileges.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day. The vulnerability (CVE-2024-26169) occurs in the Windows Error Reporting Service. If exploited on affected systems, it can permit an attacker to elevate their privileges.
BlackBasta ransomware developer appears to be experimenting with stack-based string obfuscation using ADVObfuscator... Many of the malware’s strings have been obfuscated and the filenames have been randomized, which may hinder static-based antivirus detection and behavioral-based EDR detection.
In order to start in safe mode, the ransomware executes the following commands: C:\Windows\SysNative\bcdedit /set safeboot networkChanges C:\Windows\System32\bcdedit /set safeboot networkChanges
BlackBasta 2.0 opens the ransom note in Windows Notepad via the command cmd.exe /c start /MAX notepad.exe .
the script calls the msiexec.exe, trying to uninstall the corresponding package of the EDR/antivirus.
The exploit takes advantage of this to create a "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WerFault.exe" registry key where it sets the "Debugger" value as its own executable pathname. This allows the exploit to start a shell with administrative privileges.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Multiple entries describe enumerating local, logical, or physical drives and disk/volume information, e.g., 'can enumerate local drives,' 'GetLogicalDrives,' 'fsutil fsinfo drives,' 'list drives,' and 'discover logical drive information including the drive type, free space, and volume information.'
251 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation whose leaked chats reportedly show use of ChatGPT for operational tasks, including phishing, persistence-tool debugging, and validation of stolen email addresses.
Ransomware used in the March 2023 attack against Capita; the incident reportedly involved exfiltration of more than six million individuals' records.
A ransomware family mentioned only as another beneficiary of the leaked Conti source code.
Referenced as a ransomware family sharing similarities with Agenda, including payment site/user verification behavior and safe-mode reboot/password-changing functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.