Black Basta is a ransomware family and financially motivated, Russian-speaking ransomware-as-a-service operation first observed in April 2022. It uses double extortion, encrypting victims’ data after stealing sensitive information and threatening publication to pressure victims into paying. By May 2024, its affiliates had affected more than 500 organizations across North America, Europe, and Australia, spanning 12 of the 16 critical infrastructure sectors. Victims include healthcare providers, manufacturers, and businesses across numerous other industries.
Affiliates obtain initial access through phishing, exploitation of internet-facing applications, compromised credentials, and purchased network access. Black Basta campaigns have extensively used QakBot, with subsequent use of other loaders including DarkGate. Operators have exploited the ConnectWise ScreenConnect authentication-bypass vulnerability CVE-2024-1709. Social-engineering campaigns overwhelm employees with unsolicited email, then impersonate IT support through telephone calls or Microsoft Teams messages. Victims are persuaded to grant remote access through Quick Assist or AnyDesk, enabling attackers to execute malicious scripts and deploy additional tooling.
Black Basta operations against Windows environments involve network discovery and scanning, credential theft using Mimikatz, privilege escalation, and lateral movement through tools and services such as PsExec and Remote Desktop Protocol. Operators use Cobalt Strike and legitimate remote-administration software, establish persistence through scheduled tasks and registry autorun mechanisms, and employ process injection and security-tool tampering to evade detection. Rclone and WinSCP are used to exfiltrate information before encryption of local and network-accessible data. Operators disable antivirus protections and delete volume shadow copies to impede recovery.
Black Basta attacks have deployed custom endpoint-defense evasion tools linked to FIN7. Its personnel have included former Conti participants, although this does not establish Black Basta as a direct Conti rebrand. Internal communications leaked in February 2025 exposed its specialized operational roles, criminal partnerships, and attack workflows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
39 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Black Basta report lists CVE-2021-34527 under MITRE CONTEXT → Exploit Vulns. | Black Basta Ransomware, operating under a RaaS (Ransomware as a Service) model and first identified in 2022, employs TTPs (Tactics, Techniques and Procedures) that begin with typical initial access techniques.
“Path Traversal: This secondary vulnerability provides attackers with a method to access unauthorized files, further compromising the integrity of the system. (CVE-2024-1708)”
“Authentication Bypass ... allows nefarious actors to generate their own administrative user on the platform, granting them complete control over the platform. (CVE-2024-1709)”
Previously, it was seen to exploit the PrintNightmare (CVE-2021-34527), ZeroLogon (CVE-2020-1472) and Follina (CVE-2022-30190) vulnerabilities for priviledge escalation. | Black Basta is a type of ransomware-as-a-service (RaaS) that was first discovered in April 2022. Since then, its affiliates have targeted numerous businesses and critical infrastructure in North America, Europe, and Australia.
The Black Basta report lists CVE-2024-3400 under MITRE CONTEXT → Exploit Vulns. | Black Basta Ransomware, operating under a RaaS (Ransomware as a Service) model and first identified in 2022, employs TTPs (Tactics, Techniques and Procedures) that begin with typical initial access techniques.
The Black Basta report lists CVE-2021-4436 under MITRE CONTEXT → Exploit Vulns. | Black Basta Ransomware, operating under a RaaS (Ransomware as a Service) model and first identified in 2022, employs TTPs (Tactics, Techniques and Procedures) that begin with typical initial access techniques.
Previously, it was seen to exploit the PrintNightmare (CVE-2021-34527), ZeroLogon (CVE-2020-1472) and Follina (CVE-2022-30190) vulnerabilities for priviledge escalation. | Black Basta is a type of ransomware-as-a-service (RaaS) that was first discovered in April 2022. Since then, its affiliates have targeted numerous businesses and critical infrastructure in North America, Europe, and Australia.
The Black Basta report lists CVE-2023-4966 under MITRE CONTEXT → Exploit Vulns. | Black Basta Ransomware, operating under a RaaS (Ransomware as a Service) model and first identified in 2022, employs TTPs (Tactics, Techniques and Procedures) that begin with typical initial access techniques.
The author reports strong indications that Akira and Fog were exploiting CVE-2024-40766 for unauthorized access, with more than 100 suspected victim organizations as of December 23, 2024. However, the article explicitly states that exploitation had not been definitively established. At least 48,933 internet-exposed SonicWall devices reportedly remained unpatched as of December 24, 2024.
The threat actor gained initial access to the organization via Qakbot infection, followed by the exploitation of a Windows CLFS vulnerability (CVE-2023-28252) to elevate their privileges on affected devices.
VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named “ESX Admins” to have full administrative access by default. | An engineering firm in North America was affected by a Black Basta ransomware deployment by Storm-0506.
The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Recently, there has been a series of secret chat logs leaked from a group of people that distribute the ransomware known as ‘Black Basta’.
Group members also discussed CVE-2024-23113 and CVE-2024-25600 in internal communications prior to their formal release. This once again indicates a proactive focus on monitoring emerging vulnerabilities and an ability to rapidly transition from awareness to exploitation. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers.
A particularly significant mention is CVE-2024-24919 (CheckPoint VPN authentication bypass), which was evidently purchased by a GG. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
The chat logs include discussions about CVE-2023-36884 (Windows HTML-based RCE), CVE-2022-30190 (Follina), CVE-2021-40444 (MSHTML exploit), and CVE-2017-11882 (Equation Editor RCE), with specific mentions of embedding these exploits into phishing lures. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Microsoft Exchange and other email server-related vulnerabilities play a key role in the group’s attack chain. Chat logs indicate that exploits such as ProxyShell and ProxyLogon (CVE-2022-41082, CVE-2021-42321, CVE-2021-28482, CVE-2021-26855) were actively leveraged to gain access to corporate email servers. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Group members also discussed CVE-2024-23113 and CVE-2024-25600 in internal communications prior to their formal release. This once again indicates a proactive focus on monitoring emerging vulnerabilities and an ability to rapidly transition from awareness to exploitation. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
The chat logs include discussions about CVE-2023-36884 (Windows HTML-based RCE), CVE-2022-30190 (Follina), CVE-2021-40444 (MSHTML exploit), and CVE-2017-11882 (Equation Editor RCE), with specific mentions of embedding these exploits into phishing lures. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Exploits such as CVE-2023-4966 (Citrix NetScaler), CVE-2024-3400 (Palo Alto GlobalProtect RCE), and CVE-2024-23108/CVE-2024-23109 (Fortinet FortiOS) appear in multiple conversations related to mass exploitation efforts. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
CVE-2023-42115, a vulnerability in Exim – a widely used mail transfer agent (MTA) for Unix-based systems – is another notable example. At the time of its disclosure, over 3.5 million Exim servers were exposed to the internet globally. Chat discussions suggest early awareness of this vulnerability within the group. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
Exploits such as CVE-2023-4966 (Citrix NetScaler), CVE-2024-3400 (Palo Alto GlobalProtect RCE), and CVE-2024-23108/CVE-2024-23109 (Fortinet FortiOS) appear in multiple conversations related to mass exploitation efforts. | Since its emergence in April 2022, the Black Basta ransomware group successfully maintained a relatively low profile while establishing itself as one of the most dominant players in the ransomware landscape.
20 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After QakBot’s 2023 disruption, researchers reported that Black Basta shifted toward other loaders, including DarkGate.
FIN7 ... has been linked to other ransomware families such as Black Basta, DarkSide, REvil, and LockBit.
An engineering firm in North America was affected by a Black Basta ransomware deployment by Storm-0506.
Following Conti's 2022 disbandment, members of the Cyrillic-language group rebranded under subgroups including Black Basta.
Ransomware operators such as BlackByte, Storm-0506, Storm-1175, Octo Tempest, and Manatee Tempest have been actively exploiting CVE-2024-37085 ... where some of these cases have led to Akira and Black Basta ransomware deployments.
Ransomware operators such as BlackByte, Storm-0506, Storm-1175, Octo Tempest, and Manatee Tempest have been actively exploiting CVE-2024-37085 ... where some of these cases have led to Akira and Black Basta ransomware deployments.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
267 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation whose affiliates use spearphishing and loader-based initial access. The article explicitly associates it with QakBot and DarkGate and reports more than 500 affected organizations as of May 2024.
Ransomware mentioned as a statistical comparison with Akira. It accounted for 16% of successful attacks investigated by Coveware in the second quarter of 2023.
Mentioned only in comparison with prior vishing and email-bombing campaigns; it is not linked to use of Sauron Loader in this reference.
Ransomware group/family identified as a rebrand or successor subgroup formed by former Conti members after Conti disbanded.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.