Black Basta is a Russian-speaking ransomware-as-a-service operation that emerged in 2022 and is widely regarded as a successor or offshoot of the Conti ecosystem. The group became one of the most active big-game ransomware threats globally, targeting hundreds of organizations across North America, Europe, and other regions, including entities in multiple U.S. critical infrastructure sectors. It has been associated with financially motivated extortion rather than espionage, although reporting has repeatedly linked parts of its ecosystem to broader Russian cybercrime networks and enabling services. Known aliases include BlackBasta and references to Black Basta affiliates and operators. The group has also been discussed in connection with former Conti personnel and, in some reporting, possible historical overlap with REvil-linked actors. Claims identifying specific leadership figures have circulated publicly, but such attributions have not been uniformly corroborated and should be treated cautiously. Black Basta operated a mature affiliate-based model with centralized administration, victim management, negotiation support, and specialist outsourcing. Internal communications exposed a structured organization that tracked victims systematically, assessed revenue, cyber insurance, operational downtime tolerance, and data sensitivity, and tailored ransom demands accordingly. The group combined encryption with data theft and, at times, additional coercive pressure such as harassment and distributed denial-of-service threats, reflecting a multi-extortion model. Its intrusion tradecraft has included exploitation of known vulnerabilities, use of initial access brokers, credential abuse, phishing, brute-force activity against remote access services, and scanning for exposed Remote Desktop Protocol infrastructure. Black Basta has also been linked to social-engineering-heavy intrusion chains involving email bombing, Microsoft Teams impersonation of IT support, and abuse of Quick Assist and other legitimate remote access tools to gain interactive footholds. Reporting after the disruption of QakBot indicated the group adapted toward more manual intrusion methods and alternative loaders. The group has been associated with a broad tooling ecosystem common to modern ransomware operations, including commodity and bespoke malware, proxy and backdoor tooling, credential theft, lateral movement utilities, and abuse of legitimate administration software. Public reporting has linked Black Basta activity or affiliates to malware and infrastructure overlaps involving SystemBC, BackConnect-style tooling, GhostSocks, and brute-force frameworks targeting edge devices and enterprise authentication surfaces. Black Basta relied on criminal support infrastructure, including bulletproof hosting and other abuse-tolerant services. Media Land has been publicly identified as one infrastructure provider used by the operation, alongside broader ecosystem links to services that support ransomware hosting, staging, and operational resilience. The group’s methods and infrastructure patterns have also influenced or overlapped with later clusters and successor activity, including campaigns assessed as evolutions of Black Basta tradecraft and activity involving former affiliates. In 2025, a major leak of internal chat logs and negotiation material exposed extensive details about Black Basta’s operations, victim handling, internal disputes, and targeting practices. The leak is widely assessed to have contributed to the group’s collapse or dissolution in early 2025. Subsequent reporting has suggested that some former members or affiliates may have migrated to other ransomware operations, including Cactus, or to new financially motivated intrusion clusters using similar social-engineering and access techniques. Black Basta remains significant as a case study in the industrialization of ransomware: a highly organized criminal enterprise combining affiliate operations, outsourced services, intelligence-driven victim selection, adaptive intrusion tradecraft, and layered extortion pressure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
59 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
↑のプロセスを脆弱なNsecSoft NSecKrnlドライバで止める CVE-2025-68947に関連するNsecSoft NSecKrnlドライバでサービス作成を試みて、そのサービスで脆弱性悪用によりカーネルレベルからプロセスキルや検知機能阻害を行う感じ。
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527).
In one intrusion, we observed the Black Basta operator exploiting the PrintNightmare vulnerability and dropping spider.dll as the payload.
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527).
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527).
2 more CVEs tied to this actor tracked in Mallory.
84 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in passing as a background association to an infrastructure operator.
Ransomware group cited as using the sanctioned bulletproof hosting service Media Land LLC.
Referenced only as an example of a threat actor known to abuse code-signing certificates.
Mentioned only as background comparison regarding code-signing certificate abuse.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.