Skip to content

Black Basta

Black Basta is a ransomware-as-a-service operation that emerged in 2022 and is associated with the Cardinal cybercrime group, also tracked as Storm-1811 and UNC4393.

Profile source: Mallory opens in a new tab

Black Basta

Family profile

Black Basta is a ransomware-as-a-service operation that emerged in 2022 and is associated with the Cardinal cybercrime group, also tracked as Storm-1811 and UNC4393. It conducts double-extortion attacks, exfiltrating victim data before encrypting systems and threatening publication through leak-site operations if payment is not made. The group has targeted hundreds of organizations across numerous sectors, including healthcare, construction, finance, manufacturing, energy, and public services, with heavily affected regions including the United States, Germany, the United Kingdom, Canada, Italy, and Switzerland.

Black Basta ransomware has Windows and VMware ESXi/Linux-targeting variants. Windows variants encrypt files using ChaCha20 or XChaCha20 with asymmetric cryptographic protection of encryption material; a major revised codebase also adopted elliptic-curve cryptography and per-victim file extensions. Its impact and recovery-inhibition behaviors include deleting Volume Shadow Copies, stopping services and processes, and rebooting hosts into Safe Mode for encryption. Some variants alter the desktop wallpaper to display ransom instructions. ESXi-focused variants encrypt virtual-machine storage, creating data-center-scale operational risk.

Black Basta operations commonly obtain access through phishing and spearphishing, credential abuse against exposed remote-access services, exploitation of perimeter-device and Microsoft vulnerabilities, and social engineering. Observed campaigns have used malicious attachments and links, HTML smuggling, weaponized Excel add-ins, QR-code phishing, email bombing followed by Microsoft Teams impersonation, and fraudulent IT-support calls intended to persuade users to install remote-access software. QakBot was extensively used as an initial-access and post-exploitation precursor before its disruption, while later activity has been associated with DarkGate, PikaBot, Lumma, and other malware services.

Post-compromise operations use reconnaissance, credential theft, privilege escalation, lateral movement, persistence, and defense evasion. Black Basta affiliates have used Cobalt Strike, remote execution, Windows administrative services, credential cracking, and exploitation of Windows privilege-escalation vulnerabilities. Leaked internal communications indicate a structured criminal operation with specialized infrastructure, social-engineering, access, malware-development, data-exfiltration, and negotiation functions. Activity reportedly declined following internal conflict and exposure of internal chats in early 2025, though personnel and tradecraft may reappear under other ransomware brands.

Capabilities

  • Brute Force
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Privilege Escalation
  • Reconnaissance

Operational record

1
YARA rules
5
Ransom notes
5
Negotiations
3
Leak sites
0 available

Credential Theft

  • Mimikatz

Defense Evasion

  • Backstab (Process Explorer driver)

Discovery Enum

  • AdFind
  • Bloodhound
  • PSNmap
  • PowerView
  • SoftPerfect NetScan

Exfiltration

  • Qaz[.]im
  • RClone

LOLBAS

  • BITSAdmin
  • PsExec
  • Quick Assist

Offsec

  • Brute Ratel C4
  • Cobalt Strike
  • Metasploit
  • PowerSploit

RMM Tools

  • AnyDesk
  • Atera
  • NetSupport
  • ScreenConnect
  • Splashtop
  • Supremo

Reported operators

Threat actors

19 named in public reporting
Storm-1811

The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.

UNC4393

The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.

Black Basta

The Cybereason Global SOC (GSOC) team is investigating Qakbot infections observed in customer environments related to a potentially widespread ransomware campaign run by Black Basta.

Cardinal

The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.

TA577

Proofpoint has associated TA577 campaigns with follow-on ransomware infections including Black Basta.

Conti Team 3

Black Basta is a ransomware-as-a-service (RaaS) group that emerged in April 2022 and has since attacked over 500 organizations worldwide.

FIN7

Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.

Conti

Conti disbanded later that year, but members of the Cyrillic-language group rebranded under three subgroups: Zeon, Black Basta and Quantum, which quickly rebranded to Royal, before rebranding again to BlackSuit in 2024.

DEV-0506

For example, DEV-0506 was deploying BlackBasta part-time before the Conti shutdown and is now deploying it regularly.

Tramp

Devman declined by 70%, from 82 victims to 25. The ransomware’s operator “Tramp”, a former Conti and Black Basta affiliate, was added to Interpol’s wanted list in January 2026.

Payouts King

BlackBasta was one of the most active ransomware groups since it launched in February 2022 as a successor to the notorious Conti ransomware gang.

Storm-1175

In July 2024, Microsoft also linked the Storm-1175 threat group, along with three other cybercrime gangs, to Black Basta and Akira ransomware attacks that exploited a VMware ESXi authentication-bypass flaw.

Storm-0506

Ransomware groups—including BlackCat/ALPHV, Black Basta, RansomHub, and Dark Angels—are increasingly targeting VMware ESXi...

Scattered Spider

"In several cases, the use of this technique has led to Akira and Black Basta ransomware deployments."

INDRIK SPIDER

"In several cases, the use of this technique has led to Akira and Black Basta ransomware deployments."

TA505

"Black Basta ransomware emerged in April 2022..."

STAC5777

Early tactics in the attack align with those of “Storm-1811” (aka “STAC5777”), a threat group known to deploy “Black Basta” ransomware.

Blitz Brigantine

"...a financially motivated cluster Microsoft has linked to Black Basta ransomware operations."; "...eventually Black Basta ransomware."

Exploited software

Vulnerabilities linked to Black Basta

48 CVEs
CVE-2024-26169 Windows Error Reporting Service Elevation of Privilege Vulnerability CVE-2024-1708 Path Traversal in ConnectWise ScreenConnect CVE-2023-23397 Microsoft Outlook NTLM Hash Disclosure via Crafted TNEF Message CVE-2023-35628 Windows MSHTML Platform Remote Code Execution Vulnerability CVE-2024-3400 PAN-OS GlobalProtect Command Injection CVE-2024-21338 Windows AppLocker Driver Elevation of Privilege in appid.sys CVE-2022-27925 Directory Traversal in Zimbra Collaboration mboximport ZIP Extraction CVE-2020-1472 Zerologon CVE-2024-1086 Linux kernel nf_tables use-after-free local privilege escalation CVE-2017-5753 Spectre Variant 1 Bounds Check Bypass CVE-2023-3519 Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway CVE-2023-3466 Reflected XSS in Citrix ADC and Citrix Gateway CVE-2024-21412 Microsoft Windows Internet Shortcut Files Security Feature Bypass CVE-2024-21762 Fortinet FortiOS and FortiProxy SSL-VPN Out-of-Bounds Write RCE CVE-2023-4966 Citrix Bleed CVE-2023-3467 Privilege Escalation to nsroot in Citrix NetScaler ADC and Gateway CVE-2017-5754 Meltdown (Spectre Variant 3) CVE-2023-36844 PHP External Variable Modification in Juniper Junos OS J-Web CVE-2023-36745 Remote Code Execution in Microsoft Exchange Server CVE-2023-36845 PHP External Variable Modification in Juniper Junos OS J-Web CVE-2024-1709 ConnectWise ScreenConnect Authentication Bypass CVE-2017-5715 Spectre Variant 2 Branch Target Injection CVE-2023-36884 Office and Windows HTML Remote Code Execution Vulnerability CVE-2024-25600 Unauthenticated RCE in WordPress Bricks Builder CVE-2021-34473 ProxyShell Pre-authentication ACL Bypass in Microsoft Exchange Server CVE-2024-24919 Check Point Security Gateway Remote Access VPN Arbitrary File Read CVE-2021-40444 MSHTML Remote Code Execution in Microsoft Office Documents CVE-2022-41082 ProxyNotShell RCE in Microsoft Exchange Server CVE-2022-30190 Follina CVE-2024-23113 Fortinet FortiOS fgfmd Format String Remote Code Execution CVE-2017-11882 Microsoft Office Equation Editor Remote Code Execution Vulnerability CVE-2024-23109 FortiSIEM Supervisor Unauthenticated OS Command Injection CVE-2023-42115 Exim AUTH Out-of-Bounds Write Remote Code Execution CVE-2024-23108 Fortinet FortiSIEM phMonitor Second-Order Command Injection CVE-2021-28482 Microsoft Exchange Server post-auth deserialization RCE in MeetingPollHandler CVE-2021-42321 Microsoft Exchange Server Deserialization Remote Code Execution CVE-2021-26855 Microsoft Exchange Server Pre-Authentication SSRF (ProxyLogon) CVE-2023-38831 WinRAR Arbitrary Code Execution via Same-Name File and Folder in Archive CVE-2021-42287 NoPac Domain Controller Impersonation in Active Directory Domain Services CVE-2021-34527 PrintNightmare CVE-2021-42278 sAMAccountName Spoofing in Active Directory Domain Services CVE-2022-47966 Zoho ManageEngine SAML XML Signature Validation RCE CVE-2024-37085 Authentication Bypass in VMware ESXi Active Directory Integration CVE-2023-28252 Windows Common Log File System Driver Elevation of Privilege CVE-2023-34992 FortiSIEM Supervisor Unauthenticated OS Command Injection CVE-2025-25256 Fortinet FortiSIEM Pre-Authentication OS Command Injection CVE-2025-68947 Improper authorization in NSecsoft NSecKrnl driver allows arbitrary process termination CVE-2021-1675 Windows Print Spooler - HIGH - CVSS 8.8

MITRE ATT&CK

Black Basta in ATT&CK

68 distinct techniques

Techniques

68 techniques
T1657 Financial Theft T1486 Data Encrypted for Impact T1218.003 CMSTP T1070.004 File Deletion T1036 Masquerading T1490 Inhibit System Recovery T1574.012 COR_PROFILER T1059.003 Windows Command Shell T1068 Exploitation for Privilege Escalation T1027 Obfuscated Files or Information T1218.007 Msiexec T1105 Ingress Tool Transfer T1562.009 Safe Mode Boot T1537 Transfer Data to Cloud Account T1047 Windows Management Instrumentation T1562.001 Disable or Modify Tools T1562 Impair Defenses T1218 System Binary Proxy Execution T1222 File and Directory Permissions Modification T1543.003 Windows Service T1059 Command and Scripting Interpreter T1082 System Information Discovery T1112 Modify Registry T1083 File and Directory Discovery T1059.001 PowerShell T1059.006 Python T1204.002 Malicious File T1598.004 Spearphishing Voice T1547.001 Registry Run Keys / Startup Folder T1133 External Remote Services T1041 Exfiltration Over C2 Channel T1566 Phishing T1021 Remote Services T1656 Impersonation T1036.003 Rename Legitimate Utilities T1021.003 Distributed Component Object Model T1204 User Execution T1018 Remote System Discovery T1484.001 Group Policy Modification T1482 Domain Trust Discovery T1566.001 Spearphishing Attachment T1491.001 Internal Defacement T1190 Exploit Public-Facing Application T1553.002 Code Signing T1074 Data Staged T1529 System Shutdown/Reboot T1567 Exfiltration Over Web Service T1072 Software Deployment Tools T1057 Process Discovery T1120 Peripheral Device Discovery T1007 System Service Discovery T1485 Data Destruction T1491 Defacement T1078 Valid Accounts T1497 Virtualization/Sandbox Evasion T1106 Native API T1622 Debugger Evasion T1497.001 System Checks T1027.001 Binary Padding T1036.005 Match Legitimate Resource Name or Location T1480.002 Mutual Exclusion T1036.004 Masquerade Task or Service T1222.002 Linux and Mac File and Directory Permissions Modification T1680 Local Storage Discovery T1569.002 System Services: Service Execution T1098 Account Manipulation T1136 Create Account T1574.001 Hijack Execution Flow: DLL Search Order Hijacking

Reporting

Research mentioning Black Basta

Aug 20
Hookphish

Ransomware Group qilin Hits: Trends And Concepts

Researchers reported that the Agenda ransomware operation, also tracked as Qilin, is conducting highly customized enterprise attacks across Asia and Africa and has now been linked to a victim in South Africa. A recent victim listing identified Trends And Concepts in South Africa, associated with the domain www.trendsandconceptsinteriors.com, as impacted by the Qilin group. Trend researchers said Agenda operators build victim-specific Go-based payloads that can include leaked account credentials, unique company identifiers, customized RSA keys, and ransom demands ranging from $50,000 to $800,000, with observed targeting of healthcare and education organizations in Indonesia, Saudi Arabia, South Africa, and Thailand. The intrusion methods described across the reports show a flexible and increasingly sophisticated playbook. In one case, attackers accessed a public-facing Citrix server using a valid account, moved laterally with RDP and leaked Active Directory credentials, scanned networks with Nmap and Nping, and deployed ransomware through Group Policy in under two days. A separate Trend investigation found Agenda actors using fake Google CAPTCHA pages to deliver credential stealers, then abusing legitimate remote-management tools including ATERA, AnyDesk, ScreenConnect, and Splashtop, while deploying COROXY SOCKS proxies, targeting Veeam backup infrastructure, and using BYOVD techniques with vulnerable drivers such as eskle.sys; the final ransomware payload was reportedly a Linux variant executed on Windows, likely through Windows Subsystem for Linux.

Aug 19
Trendai Security

Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques | TrendAI (US)

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Aug 14
Trendai Security

New Golang Ransomware Agenda Customizes Attacks | TrendAI (US)

Aug 12
Hookphish

Ransomware Group clop Hits: HONGHE-TECH.COM

The Clop ransomware operation has repeatedly targeted enterprise networks with intrusions that begin with phishing or exploitation of exposed systems, followed by manual lateral movement, credential theft, and domain-wide deployment. Reporting from ANSSI and AhnLab linked earlier campaigns to TA505, describing attacks in which operators used tools such as Cobalt Strike and Mimikatz, encrypted files with .Clop or .CIop extensions, and disrupted business operations at victims including E-Land Group, Software AG, and reportedly Indiabulls Group. Analysts also observed Clop using signed malware components, targeting Active Directory environments, stopping business-critical services before encryption, and in some cases preserving shadow copies depending on the variant. The group increasingly shifted from encryption-only attacks to double extortion and broader data-leak pressure tactics. Clop operators published stolen files on leak sites, demanded multimillion-dollar payments, contacted victims' customers directly to intensify pressure, and were tied to mass data-theft campaigns exploiting managed file transfer flaws such as CVE-2023-0669 in Fortra GoAnywhere MFT, which was linked to theft from about 130 companies. More recent victim listings attributed to Clop include organizations in the U.S., Canada, Peru, China, Taiwan, and Europe across technology, manufacturing, retail, and other sectors, underscoring the group's continued global focus on enterprise-scale ransomware and data-breach operations.

Aug 12
Hookphish

Ransomware Group clop Hits: 9ALTITUDES.COM

Aug 12
Hookphish

Ransomware Group clop Hits: WATERLANDPE.COM

Aug 12
Hookphish

Ransomware Group clop Hits: NETPOWER.COM

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.