Black Basta, also written BlackBasta, is a financially motivated, Russian-speaking ransomware-as-a-service operation first observed in April 2022. Its core operation supplies ransomware, technical support, and payment and negotiation infrastructure to affiliates conducting intrusions. By May 2024, Black Basta had affected more than 500 organizations across North America, Europe, and Australia, including entities in 12 of the 16 critical infrastructure sectors. Its victims include healthcare providers and manufacturing organizations. It uses double extortion, stealing sensitive information before encrypting systems and threatening to publish the stolen data unless a ransom is paid. Affiliates obtain initial access through spearphishing, malware loaders such as QakBot, and exploitation of public-facing applications, including ConnectWise ScreenConnect vulnerability CVE-2024-1709. Beginning in 2024, campaigns also used mass email flooding followed by voice calls or Microsoft Teams messages impersonating IT support. Attackers persuaded employees to grant remote access through Quick Assist or AnyDesk and then executed malicious scripts disguised as updates. Post-compromise activity includes credential theft with Mimikatz, network discovery with SoftPerfect Network Scanner and native Windows utilities, privilege escalation, process injection, and lateral movement using PsExec, remote desktop connections, and administrative shares. Operators abuse PowerShell, Cobalt Strike, and legitimate remote-administration software, and establish persistence through scheduled tasks and registry autorun mechanisms. Data exfiltration uses Rclone, WinSCP, and cURL, including transfers to cloud storage. Defense-evasion measures include tampering with Windows Defender, disabling endpoint protection, and deploying custom defense-impairment tools. Operators also delete volume shadow copies to obstruct recovery before encrypting local and network data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
68 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 malware families attributed to this actor across reporting.
21 additional families tracked in Mallory.
22 CVEs this actor has used in observed campaigns. 22 of them exploited in the wild.
↑のプロセスを脆弱なNsecSoft NSecKrnlドライバで止める CVE-2025-68947に関連するNsecSoft NSecKrnlドライバでサービス作成を試みて、そのサービスで脆弱性悪用によりカーネルレベルからプロセスキルや検知機能阻害を行う感じ。
The Black Basta report lists CVE-2021-34527 under MITRE CONTEXT → Exploit Vulns.
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527).
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527).
The Black Basta report lists CVE-2023-4966 under MITRE CONTEXT → Exploit Vulns.
17 more CVEs tied to this actor tracked in Mallory.
360 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware group whose affiliates used loaders to gain access to victim networks. The article reports more than 500 affected organizations as of May 2024 and describes a shift toward other loaders, including DarkGate, following QakBot’s 2023 disruption.
Named as a ransomware group whose proceeds flowed through Cryptomus and Heleket. No specific attack, victim, malware deployment, or exploitation method is described.
A ransomware group referenced as the source of former affiliates whose tradecraft is tied to Payouts King.
Affiliates are referenced as using email bombing followed by voice-phishing calls impersonating IT helpdesk staff, a technique comparable to the Sauron Loader delivery campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.