Skip to content

Black Basta

Black Basta is a ransomware-as-a-service operation that emerged in 2022 and became a prominent double-extortion threat targeting organizations worldwide, including healthcare and critical infrastructure.

Profile source: Mallory opens in a new tab

Black Basta

Family profile

Black Basta is a ransomware-as-a-service operation that emerged in 2022 and became a prominent double-extortion threat targeting organizations worldwide, including healthcare and critical infrastructure. It has been associated with attacks across numerous industries and has been reported to affect multiple U.S. critical infrastructure sectors. The operation is widely linked to the Russian-speaking ransomware ecosystem and has shown personnel, tradecraft, and tooling overlaps with other major crimeware clusters, including actors historically associated with Conti and, in later reporting, possible overlap or migration toward Cactus. Public reporting has also named Oleg Nefedov as an alleged leader, although that attribution has not been independently verified in all cases.

Black Basta combines data theft and file encryption with aggressive victim pressure during negotiations. Its operators and affiliates have been described as using intelligence-driven victim selection, evaluating factors such as revenue, downtime sensitivity, industry, and cyber-insurance posture to prioritize targets likely to pay. Internal communications attributed to the group indicate use of prolonged and adaptive ransom negotiations, panic-inducing tactics, and in some cases additional coercive measures consistent with multi-extortion operations.

Initial access associated with Black Basta has included phishing and social-engineering campaigns, exploitation of vulnerabilities, use of exposed remote access services, and procurement of access from initial access brokers. The group has also been repeatedly linked to email-bombing followed by Microsoft Teams impersonation of IT or help-desk staff, with victims persuaded to launch remote-support tools such as Quick Assist. Black Basta has also been observed delivered through malicious Excel files, and post-QakBot disruption reporting indicates increased reliance on more manual intrusion methods including phishing, social engineering, and brute-force activity.

On compromised Windows systems, Black Basta has been observed modifying the Registry to support execution in Safe Mode and to alter encrypted-file presentation, and creating new services for persistence. Reporting on related intrusion activity tied to Black Basta deployment also shows hands-on-keyboard post-compromise behavior including reconnaissance, credential and access abuse, lateral movement via remote administration channels, and data theft prior to ransomware execution. The group has been associated with a mature affiliate ecosystem and use of supporting malware and access tooling during operations.

Black Basta remains one of the better-known ransomware brands of the mid-2020s, notable for organized operations, double-extortion tradecraft, and repeated use of social-engineering-led enterprise intrusions that can progress rapidly from initial contact to ransomware deployment.

Capabilities

  • Brute Force
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Lateral Movement
  • Persistence
  • Reconnaissance
  • Scanning
  • Spoofing

Operational record

1
YARA rules
5
Ransom notes
5
Negotiations
3
Leak sites
0 available

Credential Theft

  • Mimikatz

Defense Evasion

  • Backstab (Process Explorer driver)

Discovery Enum

  • AdFind
  • Bloodhound
  • PSNmap
  • PowerView
  • SoftPerfect NetScan

Exfiltration

  • Qaz[.]im
  • RClone

LOLBAS

  • BITSAdmin
  • PsExec
  • Quick Assist

Offsec

  • Brute Ratel C4
  • Cobalt Strike
  • Metasploit
  • PowerSploit

RMM Tools

  • AnyDesk
  • Atera
  • NetSupport
  • ScreenConnect
  • Splashtop
  • Supremo

Reported operators

Threat actors

15 named in public reporting
Storm-1811

It is the signature opening move of cyber-criminal crews linked to the notorious Black Basta ransomware operation, alongside a rising tide of copycats executing the same play.

FIN7

Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.

Conti

Conti disbanded later that year, but members of the Cyrillic-language group rebranded under three subgroups: Zeon, Black Basta and Quantum, which quickly rebranded to Royal, before rebranding again to BlackSuit in 2024.

Black Basta

This blog post documents some of the TTPs employed by a threat actor group who were observed deploying Black Basta ransomware during a recent incident response engagement, as well as a breakdown of the executable file which performs the encryption.

DEV-0506

For example, DEV-0506 was deploying BlackBasta part-time before the Conti shutdown and is now deploying it regularly.

Tramp

Devman declined by 70%, from 82 victims to 25. The ransomware’s operator “Tramp”, a former Conti and Black Basta affiliate, was added to Interpol’s wanted list in January 2026.

Payouts King

BlackBasta was one of the most active ransomware groups since it launched in February 2022 as a successor to the notorious Conti ransomware gang.

Storm-1175

In July 2024, Microsoft also linked the Storm-1175 threat group, along with three other cybercrime gangs, to Black Basta and Akira ransomware attacks that exploited a VMware ESXi authentication-bypass flaw.

Storm-0506

Ransomware groups—including BlackCat/ALPHV, Black Basta, RansomHub, and Dark Angels—are increasingly targeting VMware ESXi...

Scattered Spider

"In several cases, the use of this technique has led to Akira and Black Basta ransomware deployments."

Indrik Spider

"In several cases, the use of this technique has led to Akira and Black Basta ransomware deployments."

TA505

"Black Basta ransomware emerged in April 2022..."

Cardinal

“A recent Black Basta attack campaign was notable because the ransomware contained a bring-your-own-vulnerable-driver (BYOVD) defense evasion component embedded within the ransomware payload itself… the vulnerable driver (an NsecSoft NSecKrnl driver) was bundled with the ransomware itself.”

STAC5777

Early tactics in the attack align with those of “Storm-1811” (aka “STAC5777”), a threat group known to deploy “Black Basta” ransomware.

Blitz Brigantine

"...a financially motivated cluster Microsoft has linked to Black Basta ransomware operations."; "...eventually Black Basta ransomware."

Exploited software

Vulnerabilities linked to Black Basta

17 CVEs

MITRE ATT&CK

Black Basta in ATT&CK

60 distinct techniques

Techniques

60 techniques
T1082 System Information Discovery T1112 Modify Registry T1083 File and Directory Discovery T1059.001 PowerShell T1486 Data Encrypted for Impact T1059.006 Python T1543.003 Windows Service T1204.002 Malicious File T1598.004 Spearphishing Voice T1547.001 Registry Run Keys / Startup Folder T1133 External Remote Services T1562.001 Disable or Modify Tools T1041 Exfiltration Over C2 Channel T1490 Inhibit System Recovery T1566 Phishing T1021 Remote Services T1036 Masquerading T1656 Impersonation T1059.003 Windows Command Shell T1562.009 Safe Mode Boot T1036.003 Rename Legitimate Utilities T1047 Windows Management Instrumentation T1021.003 Distributed Component Object Model T1204 User Execution T1018 Remote System Discovery T1484.001 Group Policy Modification T1482 Domain Trust Discovery T1566.001 Spearphishing Attachment T1491.001 Internal Defacement T1190 Exploit Public-Facing Application T1070.004 File Deletion T1105 Ingress Tool Transfer T1553.002 Code Signing T1074 Data Staged T1529 System Shutdown/Reboot T1567 Exfiltration Over Web Service T1072 Software Deployment Tools T1057 Process Discovery T1120 Peripheral Device Discovery T1007 System Service Discovery T1068 Exploitation for Privilege Escalation T1485 Data Destruction T1491 Defacement T1562 Impair Defenses T1537 Transfer Data to Cloud Account T1078 Valid Accounts T1497 Virtualization/Sandbox Evasion T1106 Native API T1622 Debugger Evasion T1497.001 System Checks T1027.001 Binary Padding T1036.005 Match Legitimate Resource Name or Location T1480.002 Mutual Exclusion T1036.004 Masquerade Task or Service T1222.002 Linux and Mac File and Directory Permissions Modification T1680 Local Storage Discovery T1569.002 System Services: Service Execution T1098 Account Manipulation T1136 Create Account T1574.001 Hijack Execution Flow: DLL Search Order Hijacking

Reporting

Research mentioning Black Basta

Jul 20
Zdnet

Qui sont les pirates russes visés par les nouvelles sanctions eur ...

The European Union imposed sanctions on eight individuals accused of participating in Russian-linked cyberattacks and cybercrime, targeting figures tied to Conti, TrickBot, Wizard Spider, LockBit, EvilCorp, BlackBasta, the Lumma infostealer, and the pro-Russian Cyber Army of Russia Reborn. Those named include alleged Conti leader Vitaly Nikolayevich Kovalev, bulletproof hosting operator Alexander Volosovik, two operators associated with Lumma, two members linked to Cyber Army of Russia Reborn, and two alleged members of GRU Unit 29155. The sanctions were issued amid broader Western attribution of Russian state and criminal cyber activity, including disruptive operations against Ukraine and its supporters and espionage and sabotage campaigns linked to the GRU. UK government reporting has profiled Russian military intelligence cyber and hybrid operations, including activity attributed to Unit 29155, while the EU action also cites links to the WhisperGate campaign and follows French accusations of Russian cyber espionage. The measures underscore continued efforts to publicly identify and financially isolate operators supporting both state-directed and criminal cyber operations.

Jul 16
Register Security

Telegram shortlinks knocked offline over sanctioned VPN connection

The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.

Jul 15
Scworld

U.S. sanctions VPN provider and cryptor seller for aiding ransomware gangs | brief | SC Media

Jul 15
Xakep

Власти США наложили санкции на First VPN из-за связей с вымогателями - Хакер

Jul 14
Security Affairs

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

Jul 14
Cyberscoop

US sanctions First VPN and administrator for supporting ransomware | CyberScoop

Jul 14
Chainalysis

“Stern” Ransomware Operator Sanctioned by EU

Jul 14
Cyber Security News

US Treasury Sanctions VPN Service that Helped Ransomware Actors to Attack Organizations

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.