Bassterlord is a Ukraine-based, financially motivated cybercriminal, initial access broker, and ransomware affiliate associated with the National Hazard Agency team. He has used the aliases Fisheye and Buster and has operated under the National Hazard Agency identity on Russian-language cybercrime forums. His ransomware partnerships have included REvil, RansomEXX, Avaddon, and LockBit. Bassterlord compromises corporate networks and sells access to other cybercriminals. His intrusion methods include automated exploitation of CVE-2019-11510 in Pulse Connect Secure VPN appliances and leveraging VPN access to reach internal systems through Remote Desktop Protocol. His access offerings have included a U.S. state government organization, a university, and an African gas and electric utility. His ransomware activity has also been linked to government, military, manufacturing, financial services, technology, and entertainment organizations. Bassterlord has authored and distributed training manuals covering corporate intrusion and ransomware operations, including SSL VPN brute forcing, and has trained other cybercriminals. In February 2023, he advertised a corporate network intrusion guide for $10,000. He publicly announced his departure from ransomware activity in March 2023; LockBit subsequently stated that his team would continue operating as affiliates and that he would retain a share of its proceeds.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An initial access broker who offered a corporate-network intrusion guide for $10,000, including chapters on SSL VPN brute forcing, and later discussed renting access to its content. The guide's author claimed to have compromised 4,865 Cisco SSL VPN services and 9,870 Fortinet VPN services using test:test credentials. Rapid7 suggested the guide might have contributed to increased Cisco ASA brute-force activity, but did not establish direct involvement in the investigated intrusions.
An initial access broker who obtained and sold access to organizations, primarily by exploiting vulnerable Pulse Secure VPN servers and leveraging that access into RDP access for resale to ransomware affiliates or for direct extortion.
Ransomware affiliate and access broker operating the National Hazard Agency, training other criminals via ransomware manuals, selling access to compromised environments, and conducting/extending ransomware attacks in partnership with multiple gangs including LockBit, REvil, RansomEXX, and Avaddon.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.