Back to Ransomware Database
Ransomware Group
blackbasta
"Black Basta" is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their ability to quickly amass new victims and the style of their negotiations, this is likely not a new operation but rather a rebrand of a previous top-tier ransomware gang that brought along their affiliates.
Known victims523
Threat Level
CRITICAL
Tactics, Techniques & Procedures (TTPs)
CredentialTheft
- Mimikatz
DefenseEvasion
- Backstab (Process Explorer driver)
DiscoveryEnum
- AdFind
- Bloodhound
- PSNmap
- PowerView
- SoftPerfect NetScan
Exfiltration
- Qaz[.]im
- RClone
LOLBAS
- BITSAdmin
- PsExec
- Quick Assist
Offsec
- Brute Ratel C4
- Cobalt Strike
- Metasploit
- PowerSploit
RMM-Tools
- AnyDesk
- Atera
- NetSupport
- ScreenConnect
- Splashtop
- +1 more
Check If You're Affected
Search our database to see if your organization appears in blackbasta's victim list.
Try it nowFree⌘K
Try
risk score · threat categories · sources · age · confidence — in one request