Bassterlord is a Ukraine-linked financially motivated cybercriminal best known as a ransomware affiliate, access broker, and operator associated with the team name National Hazard Agency. He has been tied to multiple ransomware ecosystems, including REvil, RansomEXX, Avaddon, and LockBit, and has also used aliases including Fisheye and Buster. Reporting places him in Luhansk, Ukraine, and indicates he operated within Russian-speaking underground communities. Bassterlord’s activity spans both initial access brokerage and hands-on ransomware intrusion support. He has been described as selling access to compromised enterprise environments and as using automated exploitation of Pulse Connect Secure systems via CVE-2019-11510 to obtain footholds that could later be monetized or handed off for ransomware deployment. His operations also reportedly leveraged remote access pathways such as VPN-derived access and RDP, fitting the broader initial-access-broker role in the ransomware supply chain. He is also known for producing ransomware training materials and mentoring other criminals. Two ransomware manuals have been attributed to him, along with accompanying collections of tools, exploits, and scripts. His standing in underground forums reportedly helped him gain credibility and recruitment opportunities with major ransomware programs, and he was publicly associated with LockBit’s affiliate ecosystem. After the leak of a LockBit builder in 2022, National Hazard Agency was assessed to have used modified LockBit-derived code in its own ransomware activity. Victimology attributed to Bassterlord includes government entities, universities, defense-related organizations, and private-sector companies. Specific reporting links him to intrusions or claimed involvement affecting organizations in the United States, India, Uruguay, South Africa, Australia, Spain, and Thailand. Publicly attributed targets include public-sector bodies, higher-education institutions, utilities, and defense-related contractors. Bassterlord has been portrayed as a long-running participant in the ransomware economy who evolved from earlier spam-delivered malware activity into organizational compromise, access sales, and affiliate operations. Although he publicly claimed to retire from ransomware activity in 2023, subsequent reporting assessed that he likely remained involved behind the scenes through National Hazard Agency and continued financial ties to LockBit-linked operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An initial access broker who obtained and sold access to organizations, primarily by exploiting vulnerable Pulse Secure VPN servers and leveraging that access into RDP access for resale to ransomware affiliates or for direct extortion.
Ransomware affiliate and access broker operating the National Hazard Agency, training other criminals via ransomware manuals, selling access to compromised environments, and conducting/extending ransomware attacks in partnership with multiple gangs including LockBit, REvil, RansomEXX, and Avaddon.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.