Ransomware group profile · #365 by claimed victims
Black Basta ransomwarealso Storm-1811 (access operations), Basta
A closed ransomware-as-a-service operation, widely assessed as a Conti successor, notable for abandoning phishing in favour of live social engineering: mass email bombing followed by a Microsoft Teams call from a fake IT helpdesk, ending with the victim granting remote control through Quick Assist. The technique works because it uses only tools the organisation already trusts.
Tactics, techniques and procedures
11 MITRE ATT&CK techniques mapped to Black Basta from public advisories and VULONE's own analysis.
| Tactic | Technique | Procedure | Confidence |
|---|---|---|---|
| Initial Access | T1219 Remote Access Tools | Quick Assist, the remote assistance tool built into Windows, used as the actual foothold. Nothing is installed and nothing is malicious, which is what makes it … | Confirmed |
| Initial Access | T1566 Phishing | Early operations relied on QakBot delivered by phishing. After QakBot was disrupted the crew moved to live social engineering instead. | Confirmed |
| Initial Access | T1656 Impersonation | Impersonation of internal IT support. The victim is first buried in thousands of newsletter subscriptions, then called on Microsoft Teams by an account styled a… | Confirmed |
| Privilege Escalation | T1068 Exploitation for Privilege Escalation | Exploited unpatched domain controller flaws where present: ZeroLogon (CVE-2020-1472), NoPac (CVE-2021-42278 and CVE-2021-42287) and PrintNightmare (CVE-2021-345… | Confirmed |
| Credential Access | T1003.001 LSASS Memory | Mimikatz for credential dumping, and Kerberoasting for service accounts. | Confirmed |
| Discovery | T1046 Network Service Discovery | SoftPerfect network scanner for host discovery, BloodHound for mapping privilege paths through the domain. | Confirmed |
| Lateral Movement | T1021.002 SMB/Windows Admin Shares | PsExec and SMB to move and to stage the encryptor. | Confirmed |
| Exfiltration | T1567.002 Exfiltration to Cloud Storage | Rclone to cloud storage, consistent with almost every other crew here. | Confirmed |
| Impact | T1486 Data Encrypted for Impact | ChaCha20 per file with an RSA-4096 wrapped key, appending a distinctive extension and dropping a readme in each directory. | Confirmed |
| Impact | T1490 Inhibit System Recovery | Shadow copies deleted via vssadmin before the encryption run. | Confirmed |
| Defense Evasion | T1562.001 Disable or Modify Tools | Endpoint protection disabled with purpose-built tooling before encryption, including Backstab and PowerShell scripts targeting AV services. | Confirmed |
Tooling observed
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Attack playbook
How a typical Black Basta intrusion unfolds, section by section.
Social engineering
Email bombing into a fake help desk call — The sequence is deliberate. Thousands of mailing list subscriptions arrive in minutes, which is disruptive but not alarming. A Teams call follows from an external tenant styled as internal IT, offering to fix exactly the…
Hosting and infrastructure
Rented infrastructure and legitimate SaaS — Beacon infrastructure on rented hosts, but the social engineering stage runs entirely through Microsoft tenants the crew registers itself, which are cheap, disposable and trusted by the target by default.
Beaconing and C2
Cobalt Strike after the human stage — Automated tooling only appears once an operator has hands on the host. That inverts the usual detection order: the first anomaly is a person on a call, not a process.
Encryption
ChaCha20 with an RSA-4096 wrapped key — A stream cipher chosen for throughput, with the key wrapped asymmetrically so recovery without the private key is not feasible. The practical implication is the same as elsewhere: prevention and backups, not decryption.
Operational security
Internal friction, visible in the archive — Internal coordination shows disputes over payment splits, complaints about affiliates burning access, and discussion of which victims to avoid. That material is useful for attribution and for understanding target selecti…
Frequently asked
Is Black Basta ransomware still active?
How many victims has Black Basta claimed?
Which industries does Black Basta target?
Which countries are most affected by Black Basta?
Where does VULONE get Black Basta victim data?
Public sources
| Title | Publisher | Date |
|---|---|---|
| VULONE primary-source research | VULONE | 11 Feb 2025 |
| #StopRansomware: Black Basta (AA24-131A) | CISA / FBI / HHS / MS-ISAC | 10 May 2024 |
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 28 August 2026. Questions or corrections: [email protected].