Skip to main content
Back to Ransomware Database
Ransomware Group

blackbasta

"Black Basta" is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their ability to quickly amass new victims and the style of their negotiations, this is likely not a new operation but rather a rebrand of a previous top-tier ransomware gang that brought along their affiliates.

Known victims523

Threat Level

CRITICAL

Tactics, Techniques & Procedures (TTPs)

CredentialTheft

  • Mimikatz

DefenseEvasion

  • Backstab (Process Explorer driver)

DiscoveryEnum

  • AdFind
  • Bloodhound
  • PSNmap
  • PowerView
  • SoftPerfect NetScan

Exfiltration

  • Qaz[.]im
  • RClone

LOLBAS

  • BITSAdmin
  • PsExec
  • Quick Assist

Offsec

  • Brute Ratel C4
  • Cobalt Strike
  • Metasploit
  • PowerSploit

RMM-Tools

  • AnyDesk
  • Atera
  • NetSupport
  • ScreenConnect
  • Splashtop
  • +1 more
0

Check If You're Affected

Search our database to see if your organization appears in blackbasta's victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request