Black Basta Ransomware

Description Summary

Black Basta is a ransomware-as-a-service operation first observed in April 2022. It uses double extortion, with a Tor leak site for victim shaming. The group is widely believed to be a re-branding of (or to have heavy overlap with) the Conti ransomware cartel. CISA assesses Black Basta affiliates impacted more than 500 organizations across 12+ critical-infrastructure sectors. Internal chat logs leaked in 2025 confirmed the group's structure and tooling.

Threat Actor

Russian-speaking operators with direct lineage to Conti/QakBot operations. Affiliates frequently chain QakBot, Cobalt Strike, and BRC4 with social-engineering via Teams/voice phishing for access.

Technical Indicators

Encryption Extension
.basta
Encryption Algorithm
ChaCha20 (file content) + RSA-4096 (key wrapping)
Ransom Note Name
readme.txt / instructions_read_me.txt
Targeted Industries
Healthcare, Manufacturing, Construction, Critical infrastructure
First Seen
April 2022
Last Seen
Collapsed February 2025 (chat-log leak; affiliates migrated to Cactus/Akira)
Geographical Location
Worldwide; heavily concentrated in the United States and Europe

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 4 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
T1566.004 Spearphishing via Service (Teams voice phishing)
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop
Command and Control x 1 T1219 Remote Access Software (AnyDesk, Quick Assist)