Threat intelligence reporting identifies Bassterlord as a prolific ransomware affiliate and initial access broker who allegedly worked with REvil, RansomEXX, Avaddon, and LockBit while building a reputation on Russian-language underground forums. Researchers say he used exploited Pulse Secure VPN access tied to CVE-2019-11510 to obtain and sell entry into victim networks, including government, university, and corporate environments. A leaked archive containing credentials and operational notes for more than 900 compromised Pulse Secure servers reportedly exposed how such access was cataloged, assessed for usability, and monetized for downstream ransomware attacks.
Separate reporting says Bassterlord later emerged as the apparent leader of the National Hazard Agency team, extending his role beyond access sales into broader ransomware operations and training. He was reportedly linked to attacks or claimed access involving the U.S. Department of Defense-related systems, India’s Department of Revenue, the Uruguayan Navy, and private-sector victims including Maximum Industries. Analysts assess that his public retirement from ransomware was likely deceptive and that he probably remained active behind the scenes, maintaining financial and operational ties to LockBit through the National Hazard Agency.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
KELA analyzed the leaked archive and said it matched several of Bassterlord's offered accesses to entries in the dataset, including a government entity and a university access reportedly sold for USD 12,000 on July 12.
KELA says ZDNet published an exclusive report about a leak containing details from more than 900 compromised Pulse Secure VPN servers. The leak was framed as evidence of how initial access brokers support ransomware operations.
KELA reports that on August 3, 2020, uhodiransomwar released the Pulse Secure leak to expose actors allegedly reselling public compromises as exclusive private access. The publication followed a public dispute with Bassterlord on an underground forum.
On an underground forum, Bassterlord reportedly advertised access to a U.S. state-level government organization for USD 8,000, claiming the initial access came through VPN and was later leveraged into RDP.
Analyst1 says Bassterlord took first place in the 2020 Summer Paper Contest on a Russian hacking forum sponsored by LockBit. The report states this contest entry helped him gain recruitment into LockBit's affiliate program.
KELA reports that Bassterlord said he pivoted from spam-based malware activity to compromising organizations in 2019, after learning techniques for breaching targets via RDP.
According to KELA, Bassterlord said he entered cybercrime in 2016, initially running spam campaigns that delivered trojans and infostealers before later moving into organizational intrusions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.