Black Basta

MITRE ATT&CK: S1070 View on attack.mitre.org

Aliases: Black Basta

First seen
2022-04-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows, esxi
Related IoCs
83 (80 malicious)
Last IoC activity
2026-09-02 03:48:41
Profile updated
2026-07-07 13:48:27

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing energy-and-utilities technology-and-telecommunications

Targeted regions: country_code:us

Context

Black Basta is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since at least April 2022; there are variants that target Windows and VMWare ESXi servers. Black Basta operations have included the double extortion technique where in addition to demanding ransom for decrypting the files of targeted organizations the cyber actors also threaten to post sensitive information to a leak site if the ransom is not paid. Black Basta affiliates have targeted multiple high-value organizations, with the largest number of victims based in the U.S. Based on similarities in TTPs, leak sites, payment sites, and negotiation tactics, security researchers assess the Black Basta RaaS operators could include current or former members of the Conti group.

Recent IoC activity

81 malicious indicators in Maltiverse are attributed to Black Basta (S1070). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 2026-09-01_906ad01db039a0a104b80e161e957fc0_amadey_cobalt-strike_elex_luca-st... 2026-09-02 1
file sample 2026-09-01_d4fadf7c1de824809bdef071586b04ca_amadey_cobalt-strike_elex_luca-st... 2026-09-02 1
file sample 2026-08-31_a2590a35f843c9b1a7756abc9e96dc09_amadey_cobalt-strike_darkgate_ele... 2026-08-31 1
file sample 260602-q97b3aez9t.bin 2026-07-30 2
file sample 96339a7e87ffce6ced247feb9b4cb7c05b83ca315976a9522155bad726b8e5be 2026-07-29 2
file sample sub_df5b004be717.bin 2026-07-29 4
file sample sub_9a55f5588628.bin 2026-07-29 2
file sample sub_5942143614d8.bin 2026-07-29 2
file sample sub_3090a37e5915.bin 2026-07-29 2
file sample 48976d7bf38cca4e952507e9ab27e3874ca01092eed53d0fde89c5966e9533bb.exe 2026-07-29 2
file sample 15abbff9fbce7f5782c1654775938dcd2ce0a8ebd683a008547f8a4e421888c4 2026-07-29 1
file sample cce74c82a718be7484abf7c51011793f2717cfb2068c92aa35416a93cbd13cfa.exe 2026-07-29 2
file sample 449d87ca461823bb85c18102605e23997012b522c4272465092e923802a745e9 2026-07-29 1
file sample d943a4aabd76582218fd1a9a0a77b2f6a6715b198f9994f0feae6f249b40fdf9 2026-07-29 1
file sample dc56a30c0082145ad5639de443732e55dd895a5f0254644d1b1ec1b9457f04ff 2026-07-29 1
file sample 2026-03-11_aebd07b814de50142b44ffa03f0a7bc5_amadey_cobalt-strike_elex_glasswo... 2026-07-27 1
file sample 6bd8a0291b268d32422139387864f15924e1db05dbef8cc75a6677f8263fa11d.bin 2026-07-17 2
file sample 5d2204f3a20e163120f52a2e3595db19890050b2faa96c6cba6b094b0a52b0aa.zip 2026-07-12 1
file sample 2026-03-11_2c22eaf1a508e0a95b850a82b6ba99ea_amadey_black-basta_cobalt-strike_... 2026-07-04 1
file sample 2026-03-11_45a835f12d67f28bb01ec30cb773fc40_amadey_cobalt-strike_darkgate_ele... 2026-07-03 1

Detection coverage

  • 556 Sigma rules

Malware & tools used

  • Inhibit System Recovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Code Signing (attack-pattern)
  • Virtualization/Sandbox Evasion (attack-pattern)
  • Internal Defacement (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Modify Registry (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Debugger Evasion (attack-pattern)
  • Malicious File (attack-pattern)
  • Linux and Mac Permissions (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • System Checks (attack-pattern)
  • PowerShell (attack-pattern)
  • Windows Service (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Safe Mode Boot (attack-pattern)
  • Binary Padding (attack-pattern)
  • Native API (attack-pattern)
  • System Shutdown/Reboot (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Mutual Exclusion (attack-pattern)

Used by threat actors

  • Storm-1811 (threat-actor)
  • Black Basta Operator Social Engineering Campaign (campaign)
  • Pikabot Distribution Campaigns 2023 (campaign)

Reports & references

  • avertium.com — In Depth Look At Black Basta Ransomware (report)
  • research.nccgroup.com — Shining The Light On Black Basta (report)
  • Palo Alto Unit 42 — Threat Assessment Black Basta Ransomware (report)
  • MITRE ATT&CK — S1070 (report)
  • minerva-labs.com — New Black Basta Ransomware Hijacks Windows Fax Service (report)
  • web.archive.org — Black Basta Ransomware (report)
  • deepinstinct.com — Black Basta Ransomware Threat Emergence (report)

External references