Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors blackbasta

Description

"Black Basta" is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their ability to quickly amass new victims and the style of their negotiations, this is likely not a new operation but rather a rebrand of a previous top-tier ransomware gang that brought along their affiliates. Known victims: 523 5 negotiation log(s) available, 5 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Black Basta is a ransomware group emerged in April 2022, suspected to be a rebranded operation from a known top-tier gang. They target various sectors and countries, focusing on financial gain through ransomware activities.

Goals & Targeting

Black Basta aims for financial gain through ransomware, likely targeting sectors with high data loss impact—healthcare, education, corporate. Their broad targeting indicates financial motives over specific industries or regions.

Enhanced Description

Black Basta was first identified in April 2022, with signs of development since early February. The group's style suggests it might be a rebrand of an established ransomware operation, leveraging affiliates to expand victim base rapidly. They use negotiation tactics and have left behind ransom notes from at least five victims. Despite their new branding, they follow typical ransomware TTPs.

Key Capabilities

  • Ransomware deployment
  • Spear-phishing campaigns
  • Network lateral movement
  • Persistent C2 infrastructure

Campaigns & Victims

Black Basta has targeted 523 victims, focusing on organizational-gain through ransom. Their rebranding and affiliate network suggest adaptability to maintain operations.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Encrypted files with specific extensions
  • C2 communication via known protocols

Recommended Actions

  • Phishing training
  • Network segmentation
  • Regular backups
  • EDR solutions for detection

Suggested Tags

ransomware
financial-motivated
APT
healthcare

Confidence Assessment

Medium confidence; lacks specific tools, TTP details beyond typical ransomware activities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

1

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
ransomware
financial-motivated
APT
healthcare

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Apr 26, 2022
Last Seen
Jan 11, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.