Black Basta is a ransomware-as-a-service cybercrime group first identified in April 2022. CISA stated in a November 2024 advisory update that the group had targeted at least 500 organizations worldwide, including organizations in 12 of the 16 U.S. critical infrastructure sectors. Reporting in the provided content describes Black Basta as a financially motivated criminal operation rather than a state-sponsored actor. The group is associated with high-impact ransomware and extortion operations and has been described as using a systematic, intelligence-driven victim selection process. Leaked internal Telegram chats spanning September 2023 to September 2024 indicated that Black Basta maintained victim-tracking data, referenced dozens of software vulnerabilities, scanned for exposed RDP services, used initial access brokers, and prioritized victims with low tolerance for downtime and a high likelihood of paying. The same leaks exposed internal disagreements over responsibilities, pay, and healthcare targeting, and S-RM assessed that the leaks most likely signaled the group’s dissolution. The content also states Black Basta had not listed a victim on its public leak site since January 11, 2025, and separately describes the group as having shut down in 2025. Black Basta tradecraft in the provided content includes phishing, malware deployment, social engineering, exploitation of vulnerabilities, brute-force activity against edge devices, and use of panic-triggering intimidation during extortion. The content states Black Basta used QakBot in November 2022 by hijacking legitimate email threads and sending phishing emails for initial access. After the August 2023 QakBot disruption, leaked chats indicated the group relied more on phishing, social engineering, brute-force attacks, and alternative loaders. The content also links Black Basta to a custom framework called BRUTED used to target Fortinet, Palo Alto, and Cisco devices, and says the group may have actively exploited CVE-2023-4966 (Citrix Bleed). Leaked chats also contained discussion of CVE-2024-3400 affecting Palo Alto PAN-OS. Multiple items in the content associate Black Basta-linked activity with social-engineering intrusion chains involving email bombing, Microsoft Teams IT-support impersonation, and abuse of legitimate remote-support tools such as Quick Assist. BlueVoyant assessed one such campaign as aligning with Blitz Brigantine, also tracked as Storm-1811 and STAC5777, and said it mirrored Black Basta-linked social-engineering tradecraft. Other reporting in the content also associates Storm-1811 with Black Basta ransomware deployment and notes TTP similarities with Cactus. The content describes Black Basta as operating in a mature ransomware ecosystem with structured teams, outsourced specialist services, scheduled social-engineering operations, and performance-based compensation. One report cited in the content states that before shutting down in 2025, Black Basta attacked 520 victims across 39 industries, used about two dozen ransomware variants, and collected at least $107 million in bitcoin payments. Aliases and associated tracking names directly mentioned in the content include Black Basta, Blitz Brigantine, Storm-1811, and STAC5777. The content also notes possible movement of some members to Cactus after Black Basta’s apparent decline or dissolution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
↑のプロセスを脆弱なNsecSoft NSecKrnlドライバで止める CVE-2025-68947に関連するNsecSoft NSecKrnlドライバでサービス作成を試みて、そのサービスで脆弱性悪用によりカーネルレベルからプロセスキルや検知機能阻害を行う感じ。
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527).
In one intrusion, we observed the Black Basta operator exploiting the PrintNightmare vulnerability and dropping spider.dll as the payload.
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527).
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527).
1 more CVE tied to this actor tracked in Mallory.
78 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as using a custom BRUTED framework to target Fortinet, Palo Alto, and Cisco as part of credential access operations tied to ransomware activity.
Referenced for comparable ransom negotiation behavior, including prolonged bargaining and reduced final settlements.
Referenced for similar extortion negotiation patterns reconstructed from leaked internal chats.
Uses email bombing followed by Microsoft Teams vishing/social engineering to trick victims into granting remote access via Quick Assist or remote-support tools, leading to credential theft, backdoor deployment, persistence, and eventual ransomware deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.