Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationenforcement-actionunderground-data-leakcryptocurrency-platform-risk

German Authorities Add Alleged Black Basta Ringleader to EU Most-Wanted List

Updated 3mo agoFirst seen Jan 16, 202612 sources

German law enforcement added Oleg Evgenievich Nefedov/Nefekov, a 35-year-old Russian national, to the EU’s most-wanted list in connection with the Black Basta ransomware operation. German prosecutors and the Federal Criminal Police Office (BKA) allege he founded and led the group, acting as a “managing director” who selected targets, recruited and tasked members, participated in ransom negotiations, and managed extortion proceeds used to pay affiliates.

Authorities attribute to Black Basta a large global victim set since at least early 2022; reporting cites BKA estimates of roughly 700 organizations attacked worldwide and external researcher estimates of $100M+ in extortion payments by the end of 2023. The manhunt follows broader disruption and scrutiny of the group after an internal leak reportedly contributed to Black Basta ceasing activity, and the EU listing includes multiple alleged aliases (e.g., tramp, tr, gg, AA, kurva, Washingt0n, S.Jimmi) tied to the suspect’s role in developing and operating the ransomware and related malware used for intrusion, data theft, and encryption-based extortion paid in cryptocurrency.

Share:
German Authorities Add Alleged Black Basta Ringleader to EU Most-Wanted List
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Jan 16, 20265mo ago

Nefedov added to EU Most Wanted and Interpol wanted lists

German authorities placed Oleg Nefedov on the EU Most Wanted list and said Interpol issued a Red Notice for him, seeking public tips on his whereabouts, travel, contacts, and online accounts. Authorities believe he is likely in Russia, though his exact location is unknown.

Germany names Oleg Nefedov as alleged Black Basta leader

Germany's BKA and Frankfurt prosecutors publicly identified Russian national Oleg Evgenievich Nefedov as the suspected founder and leader of Black Basta. They accused him of developing the ransomware, selecting targets, recruiting members, participating in ransom negotiations, and managing cryptocurrency proceeds.

Two Ukrainian suspects identified as Black Basta 'hash crackers'

Investigators identified two Ukrainian suspects accused of supporting Black Basta by extracting passwords from stolen data, stealing credentials, and escalating privileges to prepare ransomware attacks. Authorities said their work enabled intrusions, data theft, and malware deployment against victims.

Germany and Ukraine raid suspects linked to Black Basta

Ukrainian and German law enforcement conducted coordinated searches in the Ivano-Frankivsk and Lviv regions targeting alleged Black Basta members. Authorities seized digital devices, notes, and cryptocurrency assets for forensic analysis as part of the investigation.

Feb 28, 20251y ago

Black Basta activity declines after leak exposure

Following the 2025 internal leak, Black Basta reportedly became inactive, removed its leak site, and ceased activity in a collapse compared by some reporting to Conti’s post-leak downfall. Some affiliates were reported to have shifted to other operations such as CACTUS.

Black Basta extorts organizations in Germany and worldwide

Between March 2022 and February 2025, German authorities say Black Basta extorted more than 100 companies and institutions in Germany and roughly 600 to 700 organizations worldwide. Reported losses in Germany exceeded €20 million, with hospitals and public institutions among the victims.

Feb 1, 20251y ago

Black Basta internal chats are leaked

Internal Black Basta chat logs and related data were leaked in early 2025, exposing operational details, member aliases, and technical information used by researchers and investigators. The leak was later cited as key evidence linking Oleg Nefedov to the group’s leadership.

Apr 1, 20224y ago

Black Basta ransomware operation emerges

Black Basta began operating as a ransomware-as-a-service group in 2022, with multiple reports placing its emergence in early 2022 or April 2022. Authorities later tied the group to hundreds of extortion incidents worldwide involving data theft and system encryption.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

65 LINKEDOpen in app
Affected products
4 linked
InstagramGithubVercelGithub
Organizations
28 linked
Microsoft CorporationAmazon Web ServicesPenteraGitHubJamfVercelGoogleKryptexTrellixAscension HealthDataBreachesABBRecorded FutureResecurityNew Horizons MedicalSuspectFileDXSSouthern WaterTrend MicroBT GroupCapitaHyundai Motor CompanyFlashpointRheinmetallReliaQuestToronto Public LibraryYellow Pages CanadaAmerican Dental Association
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.