Black Basta (Windows)

Aliases: no_name_software

First seen
2022-02-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:02:13

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing professional-services technology-and-telecommunications

Context

"Black Basta" is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their ability to quickly amass new victims and the style of their negotiations, this is likely not a new operation but rather a rebrand of a previous top-tier ransomware gang that brought along their affiliates.

Reports & references

  • pwc.com — 2022 Year In Retrospect Report (report)
  • services.google.com — M Trends 2025 En (report)
  • Microsoft — Ransomware Operators Exploit Esxi Hypervisor Vulnerability For Mass Encryption (report)
  • cloud.google.com — Unc4393 Goes Gently Into Silentnight (report)
  • security.com — Black Basta Ransomware Zero Day (report)
  • Microsoft — Threat Actors Misusing Quick Assist In Social Engineering Attacks Leading To Ransomware (report)
  • esentire.com — Ongoing Email Bombing Campaigns Leading To Remote Access And Post Exploitation (report)
  • CrowdStrike — Wandering Spider (report)
  • rapid7.com — Ongoing Social Engineering Campaign Linked To Black Basta Ransomware Operators (report)
  • Microsoft — Re54L7V (report)
  • Kaspersky — 106950 (report)
  • advintel.io — Discontinued The End Of Conti S Brand Marks New Chapter For Cybercrime Landscape (report)
  • therecord.media — German Wind Farm Operator Confirms Cybersecurity Incident After Ransomware Group (report)
  • sentinelone.com — Crimeware Trends Ransomware Developers Turn To Intermittent Encryption To Evade Detection (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Blackbasta (report)
  • bleepingcomputer.com — American Dental Association Hit By New Black Basta Ransomware (report)
  • bleepingcomputer.com — New Black Basta Ransomware Springs Into Action With A Dozen Breaches (report)
  • Trend Micro — Examining The Black Basta Ransomwares Infection Routine (report)
  • securityintelligence.com — Black Basta Ransomware Group Besting Network (report)
  • avertium.com — In Depth Look At Black Basta Ransomware (report)
  • research.nccgroup.com — Shining The Light On Black Basta (report)
  • gbhackers.com — Black Basta Ransomware (report)
  • Trend Micro — Black Basta Ransomware Operators Expand Their Attack Arsenal Wit (report)
  • securityscorecard.com — A Deep Dive Into Black Basta Ransomware (report)
  • Palo Alto Unit 42 — Threat Assessment Black Basta Ransomware (report)

External references