← All ransomware groups

Ransomware group profile · #365 by claimed victims

Black Basta ransomwarealso Storm-1811 (access operations), Basta

A closed ransomware-as-a-service operation, widely assessed as a Conti successor, notable for abandoning phishing in favour of live social engineering: mass email bombing followed by a Microsoft Teams call from a fake IT helpdesk, ending with the victim granting remote control through Quick Assist. The technique works because it uses only tools the organisation already trusts.

Active Russia First seen Apr 2022 ATT&CK G1044 ChaCha20 per file with an RSA-4096 wrapped key Russian
0Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
0Countries hit
0Leak-site URLs tracked
Latest claim recorded

Tactics, techniques and procedures

11 MITRE ATT&CK techniques mapped to Black Basta from public advisories and VULONE's own analysis.

TacticTechniqueProcedureConfidence
Initial Access T1219 Remote Access Tools Quick Assist, the remote assistance tool built into Windows, used as the actual foothold. Nothing is installed and nothing is malicious, which is what makes it … Confirmed
Initial Access T1566 Phishing Early operations relied on QakBot delivered by phishing. After QakBot was disrupted the crew moved to live social engineering instead. Confirmed
Initial Access T1656 Impersonation Impersonation of internal IT support. The victim is first buried in thousands of newsletter subscriptions, then called on Microsoft Teams by an account styled a… Confirmed
Privilege Escalation T1068 Exploitation for Privilege Escalation Exploited unpatched domain controller flaws where present: ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42278 and CVE-2021-42287) and PrintNightmare (CVE-2021-345… Confirmed
Credential Access T1003.001 LSASS Memory Mimikatz for credential dumping, and Kerberoasting for service accounts. Confirmed
Discovery T1046 Network Service Discovery SoftPerfect network scanner for host discovery, BloodHound for mapping privilege paths through the domain. Confirmed
Lateral Movement T1021.002 SMB/Windows Admin Shares PsExec and SMB to move and to stage the encryptor. Confirmed
Exfiltration T1567.002 Exfiltration to Cloud Storage Rclone to cloud storage, consistent with almost every other crew here. Confirmed
Impact T1486 Data Encrypted for Impact ChaCha20 per file with an RSA-4096 wrapped key, appending a distinctive extension and dropping a readme in each directory. Confirmed
Impact T1490 Inhibit System Recovery Shadow copies deleted via vssadmin before the encryption run. Confirmed
Defense Evasion T1562.001 Disable or Modify Tools Endpoint protection disabled with purpose-built tooling before encryption, including Backstab and PowerShell scripts targeting AV services. Confirmed

Tooling observed

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Attack playbook

How a typical Black Basta intrusion unfolds, section by section.

Social engineering

Email bombing into a fake help desk call — The sequence is deliberate. Thousands of mailing list subscriptions arrive in minutes, which is disruptive but not alarming. A Teams call follows from an external tenant styled as internal IT, offering to fix exactly the…

Hosting and infrastructure

Rented infrastructure and legitimate SaaS — Beacon infrastructure on rented hosts, but the social engineering stage runs entirely through Microsoft tenants the crew registers itself, which are cheap, disposable and trusted by the target by default.

Beaconing and C2

Cobalt Strike after the human stage — Automated tooling only appears once an operator has hands on the host. That inverts the usual detection order: the first anomaly is a person on a call, not a process.

Encryption

ChaCha20 with an RSA-4096 wrapped key — A stream cipher chosen for throughput, with the key wrapped asymmetrically so recovery without the private key is not feasible. The practical implication is the same as elsewhere: prevention and backups, not decryption.

Operational security

Internal friction, visible in the archive — Internal coordination shows disputes over payment splits, complaints about affiliates burning access, and discussion of which victims to avoid. That material is useful for attribution and for understanding target selecti…

Frequently asked

Is Black Basta ransomware still active?
Black Basta is tracked as active.
How many victims has Black Basta claimed?
VULONE has recorded 0 leak-site victim claims attributed to Black Basta, across 0 countries and 0 sectors.
Which industries does Black Basta target?
Sector data for Black Basta victims is not yet available.
Which countries are most affected by Black Basta?
Country data for Black Basta victims is not yet available.
Where does VULONE get Black Basta victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Public sources

TitlePublisherDate
VULONE primary-source researchVULONE11 Feb 2025
#StopRansomware: Black Basta (AA24-131A)CISA / FBI / HHS / MS-ISAC10 May 2024

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 28 August 2026. Questions or corrections: [email protected].