Credential Theft
- Mimikatz
Black Basta is a ransomware-as-a-service operation that emerged in 2022 and is associated with the Cardinal cybercrime group, also tracked as Storm-1811 and UNC4393.
Profile source: Mallory opens in a new tabBlack Basta
Black Basta is a ransomware-as-a-service operation that emerged in 2022 and is associated with the Cardinal cybercrime group, also tracked as Storm-1811 and UNC4393. It conducts double-extortion attacks, exfiltrating victim data before encrypting systems and threatening publication through leak-site operations if payment is not made. The group has targeted hundreds of organizations across numerous sectors, including healthcare, construction, finance, manufacturing, energy, and public services, with heavily affected regions including the United States, Germany, the United Kingdom, Canada, Italy, and Switzerland.
Black Basta ransomware has Windows and VMware ESXi/Linux-targeting variants. Windows variants encrypt files using ChaCha20 or XChaCha20 with asymmetric cryptographic protection of encryption material; a major revised codebase also adopted elliptic-curve cryptography and per-victim file extensions. Its impact and recovery-inhibition behaviors include deleting Volume Shadow Copies, stopping services and processes, and rebooting hosts into Safe Mode for encryption. Some variants alter the desktop wallpaper to display ransom instructions. ESXi-focused variants encrypt virtual-machine storage, creating data-center-scale operational risk.
Black Basta operations commonly obtain access through phishing and spearphishing, credential abuse against exposed remote-access services, exploitation of perimeter-device and Microsoft vulnerabilities, and social engineering. Observed campaigns have used malicious attachments and links, HTML smuggling, weaponized Excel add-ins, QR-code phishing, email bombing followed by Microsoft Teams impersonation, and fraudulent IT-support calls intended to persuade users to install remote-access software. QakBot was extensively used as an initial-access and post-exploitation precursor before its disruption, while later activity has been associated with DarkGate, PikaBot, Lumma, and other malware services.
Post-compromise operations use reconnaissance, credential theft, privilege escalation, lateral movement, persistence, and defense evasion. Black Basta affiliates have used Cobalt Strike, remote execution, Windows administrative services, credential cracking, and exploitation of Windows privilege-escalation vulnerabilities. Leaked internal communications indicate a structured criminal operation with specialized infrastructure, social-engineering, access, malware-development, data-exfiltration, and negotiation functions. Activity reportedly declined following internal conflict and exposure of internal chats in early 2025, though personnel and tradecraft may reappear under other ransomware brands.
Reported operators
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.
The Cybereason Global SOC (GSOC) team is investigating Qakbot infections observed in customer environments related to a potentially widespread ransomware campaign run by Black Basta.
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.
Proofpoint has associated TA577 campaigns with follow-on ransomware infections including Black Basta.
Black Basta is a ransomware-as-a-service (RaaS) group that emerged in April 2022 and has since attacked over 500 organizations worldwide.
Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.
Conti disbanded later that year, but members of the Cyrillic-language group rebranded under three subgroups: Zeon, Black Basta and Quantum, which quickly rebranded to Royal, before rebranding again to BlackSuit in 2024.
For example, DEV-0506 was deploying BlackBasta part-time before the Conti shutdown and is now deploying it regularly.
Devman declined by 70%, from 82 victims to 25. The ransomware’s operator “Tramp”, a former Conti and Black Basta affiliate, was added to Interpol’s wanted list in January 2026.
BlackBasta was one of the most active ransomware groups since it launched in February 2022 as a successor to the notorious Conti ransomware gang.
In July 2024, Microsoft also linked the Storm-1175 threat group, along with three other cybercrime gangs, to Black Basta and Akira ransomware attacks that exploited a VMware ESXi authentication-bypass flaw.
Ransomware groups—including BlackCat/ALPHV, Black Basta, RansomHub, and Dark Angels—are increasingly targeting VMware ESXi...
"In several cases, the use of this technique has led to Akira and Black Basta ransomware deployments."
"In several cases, the use of this technique has led to Akira and Black Basta ransomware deployments."
"Black Basta ransomware emerged in April 2022..."
"Black Basta ransomware emerged in April 2022..."
Early tactics in the attack align with those of “Storm-1811” (aka “STAC5777”), a threat group known to deploy “Black Basta” ransomware.
"...a financially motivated cluster Microsoft has linked to Black Basta ransomware operations."; "...eventually Black Basta ransomware."
Exploited software
MITRE ATT&CK
Reporting
Researchers reported that the Agenda ransomware operation, also tracked as Qilin, is conducting highly customized enterprise attacks across Asia and Africa and has now been linked to a victim in South Africa. A recent victim listing identified Trends And Concepts in South Africa, associated with the domain www.trendsandconceptsinteriors.com, as impacted by the Qilin group. Trend researchers said Agenda operators build victim-specific Go-based payloads that can include leaked account credentials, unique company identifiers, customized RSA keys, and ransom demands ranging from $50,000 to $800,000, with observed targeting of healthcare and education organizations in Indonesia, Saudi Arabia, South Africa, and Thailand. The intrusion methods described across the reports show a flexible and increasingly sophisticated playbook. In one case, attackers accessed a public-facing Citrix server using a valid account, moved laterally with RDP and leaked Active Directory credentials, scanned networks with Nmap and Nping, and deployed ransomware through Group Policy in under two days. A separate Trend investigation found Agenda actors using fake Google CAPTCHA pages to deliver credential stealers, then abusing legitimate remote-management tools including ATERA, AnyDesk, ScreenConnect, and Splashtop, while deploying COROXY SOCKS proxies, targeting Veeam backup infrastructure, and using BYOVD techniques with vulnerable drivers such as eskle.sys; the final ransomware payload was reportedly a Linux variant executed on Windows, likely through Windows Subsystem for Linux.
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.