Black Basta is a ransomware-as-a-service operation and associated ransomware family that emerged in early 2022 following the collapse of Conti and is widely linked to former Conti and Ryuk ecosystem members. It is known for double-extortion operations in which data is stolen prior to encryption and victims are pressured to pay both for decryption and to prevent publication of stolen information. The group has targeted organizations across multiple sectors, including healthcare, manufacturing, construction, technology, and other enterprise environments, with substantial activity against organizations in North America and Europe.
Black Basta commonly gains access through phishing and spearphishing, often using precursor malware and access-broker ecosystems. Reported intrusion chains have involved QakBot and later DarkGate, as well as Microsoft Teams-based social engineering, email bombing, vishing, QR-code lures, malicious scripts, and abuse of remote support tools. Leaked internal communications and incident reporting also indicate use of credential stuffing, brute-force activity, reverse-proxy phishing against Microsoft 365 to bypass MFA, exploitation of perimeter-device and Windows vulnerabilities, and targeting of exposed remote access services such as VPN portals, Citrix, RDWeb, and similar enterprise access points.
Post-compromise, Black Basta operators have used reconnaissance tooling and frameworks such as Cobalt Strike, along with credential theft, privilege escalation, lateral movement, persistence, and defense evasion. Observed tradecraft includes process injection, use of Safe Mode boot manipulation to reduce endpoint protection interference, service and process termination, deletion of shadow copies, and attempts to disable or remove security tooling. The ransomware encryptor has been documented using ChaCha20 with asymmetric-key protection in earlier variants, while later versions introduced revised cryptographic implementation and stronger obfuscation. Black Basta also developed a Linux encryptor aimed primarily at VMware ESXi environments, reflecting a focus on high-impact virtualization infrastructure.
The malware runs on Windows and Linux, with Linux variants particularly associated with ESXi targeting. Black Basta has been tied to the Cardinal cybercrime group, also tracked as Storm-1811 and UNC4393, and has maintained close operational relationships with broader criminal services including loaders, stealers, proxy infrastructure, and code-signing abuse. Internal leaks from 2025 exposed a structured, business-like organization with specialized roles spanning infrastructure, phishing, credential operations, malware delivery, exfiltration, and negotiations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
41 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Group members also discussed CVE-2024-23113 and CVE-2024-25600 in internal communications prior to their formal release. This once again indicates a proactive focus on monitoring emerging vulnerabilities and an ability to rapidly transition from awareness to exploitation. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers.
A particularly significant mention is CVE-2024-24919 (CheckPoint VPN authentication bypass), which was evidently purchased by a GG. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
The chat logs include discussions about CVE-2023-36884 (Windows HTML-based RCE), CVE-2022-30190 (Follina), CVE-2021-40444 (MSHTML exploit), and CVE-2017-11882 (Equation Editor RCE), with specific mentions of embedding these exploits into phishing lures. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
The chat logs include discussions about CVE-2023-36884 (Windows HTML-based RCE), CVE-2022-30190 (Follina), CVE-2021-40444 (MSHTML exploit), and CVE-2017-11882 (Equation Editor RCE), with specific mentions of embedding these exploits into phishing lures. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Group members also discussed CVE-2024-23113 and CVE-2024-25600 in internal communications prior to their formal release. This once again indicates a proactive focus on monitoring emerging vulnerabilities and an ability to rapidly transition from awareness to exploitation. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
The chat logs include discussions about CVE-2023-36884 (Windows HTML-based RCE), CVE-2022-30190 (Follina), CVE-2021-40444 (MSHTML exploit), and CVE-2017-11882 (Equation Editor RCE), with specific mentions of embedding these exploits into phishing lures. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Exploits such as CVE-2023-4966 (Citrix NetScaler), CVE-2024-3400 (Palo Alto GlobalProtect RCE), and CVE-2024-23108/CVE-2024-23109 (Fortinet FortiOS) appear in multiple conversations related to mass exploitation efforts. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
CVE-2023-42115, a vulnerability in Exim – a widely used mail transfer agent (MTA) for Unix-based systems – is another notable example. At the time of its disclosure, over 3.5 million Exim servers were exposed to the internet globally. Chat discussions suggest early awareness of this vulnerability within the group. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Exploits such as CVE-2023-4966 (Citrix NetScaler), CVE-2024-3400 (Palo Alto GlobalProtect RCE), and CVE-2024-23108/CVE-2024-23109 (Fortinet FortiOS) appear in multiple conversations related to mass exploitation efforts. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Another key mention is CVE-2023-38831 (WinRAR RCE), used for executing secondary-stage malware. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527). | Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.
In one intrusion, we observed the Black Basta operator exploiting the PrintNightmare vulnerability and dropping spider.dll as the payload. | Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.
Beyond the reconnaissance stage, Black Basta attempts local and domain level privilege escalation through a variety of exploits. We have seen the use of ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42287, CVE-2021-42278) and PrintNightmare (CVE-2021-34527). | Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022.
19 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.
The Cybereason Global SOC (GSOC) team is investigating Qakbot infections observed in customer environments related to a potentially widespread ransomware campaign run by Black Basta.
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.
Proofpoint has associated TA577 campaigns with follow-on ransomware infections including Black Basta.
Black Basta is a ransomware-as-a-service (RaaS) group that emerged in April 2022 and has since attacked over 500 organizations worldwide.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
the threat actor moved laterally on many machines through Windows Management Instrumentation (WMI) ... WMI is leveraged to execute the malicious commands and the ransomware
After infecting the target network the ransomware performs the following actions:- Reconnaissance Collect data Credentials Move laterally Download payloads Execute payloads
YY later inquired if GG's suggestion was to rewrite C# in C#, revealing that Tramp instructed to rewrite the malware from C# to Python using ChatGPT.
These included the use of batch scripts masquerading as software updates.
YY (coder of Black Basta) was instructed to rewrite the tools in Python as some of the gang’s malware got detected by AV/EDR. GG asked YY to use ChatGPT for that... Tramp instructed to rewrite the malware from C# to Python using ChatGPT.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
The exploit takes advantage of this to create a "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WerFault.exe" registry key where it sets the "Debugger" value as its own executable pathname. This allows the exploit to start a shell with administrative privileges.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day. The vulnerability (CVE-2024-26169) occurs in the Windows Error Reporting Service. If exploited on affected systems, it can permit an attacker to elevate their privileges.
BlackBasta ransomware developer appears to be experimenting with stack-based string obfuscation using ADVObfuscator... Many of the malware’s strings have been obfuscated and the filenames have been randomized, which may hinder static-based antivirus detection and behavioral-based EDR detection.
In order to start in safe mode, the ransomware executes the following commands: C:\Windows\SysNative\bcdedit /set safeboot networkChanges C:\Windows\System32\bcdedit /set safeboot networkChanges
BlackBasta 2.0 opens the ransom note in Windows Notepad via the command cmd.exe /c start /MAX notepad.exe .
the script calls the msiexec.exe, trying to uninstall the corresponding package of the EDR/antivirus.
The exploit takes advantage of this to create a "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WerFault.exe" registry key where it sets the "Debugger" value as its own executable pathname. This allows the exploit to start a shell with administrative privileges.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Multiple entries describe enumerating local, logical, or physical drives and disk/volume information, e.g., 'can enumerate local drives,' 'GetLogicalDrives,' 'fsutil fsinfo drives,' 'list drives,' and 'discover logical drive information including the drive type, free space, and volume information.'
235 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family stated to have used leaked Conti source code as a basis.
Mentioned as a prior example of ransomware affiliates using Microsoft Teams for social engineering.
A ransomware family active in 2025 using double-extortion tactics against healthcare and critical infrastructure targets.
Ransomware family/group mentioned as using the bulletproof hosting service.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.