Black Basta
MITRE ATT&CK: S1070 View on attack.mitre.org
Aliases: Black Basta
- First seen
- 2022-04-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows, esxi
- Related IoCs
- 83 (80 malicious)
- Last IoC activity
- 2026-09-02 03:48:41
- Profile updated
- 2026-07-07 13:48:27
Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing energy-and-utilities technology-and-telecommunications
Targeted regions: country_code:us
Context
Black Basta is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since at least April 2022; there are variants that target Windows and VMWare ESXi servers. Black Basta operations have included the double extortion technique where in addition to demanding ransom for decrypting the files of targeted organizations the cyber actors also threaten to post sensitive information to a leak site if the ransom is not paid. Black Basta affiliates have targeted multiple high-value organizations, with the largest number of victims based in the U.S. Based on similarities in TTPs, leak sites, payment sites, and negotiation tactics, security researchers assess the Black Basta RaaS operators could include current or former members of the Conti group.
Recent IoC activity
81 malicious indicators in Maltiverse are attributed to Black Basta (S1070). The 20 most recently updated:
Detection coverage
- 556 Sigma rules
Malware & tools used
- Inhibit System Recovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Code Signing (attack-pattern)
- Virtualization/Sandbox Evasion (attack-pattern)
- Internal Defacement (attack-pattern)
- Remote System Discovery (attack-pattern)
- Modify Registry (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Debugger Evasion (attack-pattern)
- Malicious File (attack-pattern)
- Linux and Mac Permissions (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Service Discovery (attack-pattern)
- Local Storage Discovery (attack-pattern)
- System Checks (attack-pattern)
- PowerShell (attack-pattern)
- Windows Service (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Safe Mode Boot (attack-pattern)
- Binary Padding (attack-pattern)
- Native API (attack-pattern)
- System Shutdown/Reboot (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Mutual Exclusion (attack-pattern)
Used by threat actors
- Storm-1811 (threat-actor)
- Black Basta Operator Social Engineering Campaign (campaign)
- Pikabot Distribution Campaigns 2023 (campaign)
Reports & references
- avertium.com — In Depth Look At Black Basta Ransomware (report)
- research.nccgroup.com — Shining The Light On Black Basta (report)
- Palo Alto Unit 42 — Threat Assessment Black Basta Ransomware (report)
- MITRE ATT&CK — S1070 (report)
- minerva-labs.com — New Black Basta Ransomware Hijacks Windows Fax Service (report)
- web.archive.org — Black Basta Ransomware (report)
- deepinstinct.com — Black Basta Ransomware Threat Emergence (report)
External references
- mitre-attack — S1070
- Avertium Black Basta June 2022
- Cyble Black Basta May 2022
- Palo Alto Networks Black Basta August 2022
- NCC Group Black Basta June 2022
- Deep Instinct Black Basta August 2022
- Minerva Labs Black Basta May 2022
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy