HackerFeeds
All ransomware groups

blackbasta

523 tracked victims
·first seen 2022-04-26·last activity 2025-01-11

Group profile

"Black Basta" is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their ability to quickly amass new victims and the style of their negotiations, this is likely not a new operation but rather a rebrand of a previous top-tier ransomware gang that brought along their affiliates.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1566.001Phishing: Spear phishing Attachment

    Victims receive spear phishing emails with attached malicious zip files - typically password protected. That contains malicious doc including .doc, .pdf, .xls

TA0002

Execution

  • T1047Windows Management Instrumentation

    Utilizes Invoke-TotalExec to push out the ransomware binary.

  • T1059.001Command and Scripting Interpreter: PowerShell

    Black Basta has encoded PowerShell scripts to download additional scripts.

  • T1569.002System Services: Service Execution

    Black Basta has installed and used PsExec to execute payloads on remote hosts.

TA0003

Persistence

  • T1098Account Manipulation

    Added newly created accounts to the administrators' group to maintain elevated access.

  • T1136Create Account

    Black Basta threat actors created accounts with names such as temp, r, or admin.

  • T1543.003Create or Modify System Process: Windows Service

    Creates benign-looking services for the ransomware binary.

  • T1574.001Hijack Execution Flow: DLL Search Order Hijacking

    Black Basta used Qakbot, which has the ability to exploit Windows 7 Calculator to execute malicious payloads.

TA0004

Privilege Escalation

  • T1484.001Domain Policy Modification: Group Policy Modification

    Black Basta can modify group policy for privilege escalation and defense evasion.

  • T1543.003Create or Modify System Process: Windows Service

    Creates benign-looking services for the ransomware binary.

  • T1574.001Hijack Execution Flow: DLL Search Order Hijacking

    Black Basta used Qakbot, which has the ability to exploit Windows 7 Calculator to execute malicious payloads.

Recent victims

showing 50 of 523
DateWebsite / victimSectorCountry
2024-11-20
schuff.com
schuff.comschuff.com
Business ServicesUS
2024-11-21
granbyindustries.com
granbyindustries.comgranbyindustries.com
ManufacturingUS
2024-12-12
plasmatherm.com
plasmatherm.complasmatherm.com
TechnologyUS
2024-12-10
arunestates.co.uk
arunestates.co.ukarunestates.co.uk
Business ServicesGB
2024-12-11
brachot.com
brachot.combrachot.com
ManufacturingBE
2024-12-12
avril.ca
avril.caavril.ca
Agriculture and Food ProductionCA
2025-01-11
migonline.com
migonline.commigonline.com
Financial ServicesUS
2024-12-17
bnext.nl
bnext.nlbnext.nl
TechnologyNL
2024-11-12
fote.com
fote.comfote.com
Consumer ServicesUS
2024-10-31
bender.de
bender.debender.de
ManufacturingDE
2024-11-26
valveworksusa.com
valveworksusa.comvalveworksusa.com
ManufacturingUS
2024-11-21
wikov.com
wikov.comwikov.com
ManufacturingCZ
2024-11-20
activedynamics.com
activedynamics.comactivedynamics.com
ManufacturingCA
2024-12-05
bathfitter.com
bathfitter.combathfitter.com
Business ServicesCA
2024-11-27
grimaldialliance.com
grimaldialliance.comgrimaldialliance.com
Transportation/LogisticsIT
2024-12-18
medion.com
medion.commedion.com
TechnologyDE
2024-10-10
furmanos.com
furmanos.comfurmanos.com
Agriculture and Food ProductionUS
2024-10-17
interspiro.com
interspiro.cominterspiro.com
ManufacturingUS
2024-10-22
hamptonsecurities.com
hamptonsecurities.comhamptonsecurities.com
Financial ServicesCA
2024-10-24
g-s.co.uk
g-s.co.ukg-s.co.uk
Agriculture and Food ProductionGB
2024-10-24
cafezupas.com
cafezupas.comcafezupas.com
Hospitality and TourismUS
2024-10-29
westbankcorp.com
westbankcorp.comwestbankcorp.com
ConstructionCA
2024-10-25
btci.com
btci.combtci.com
TechnologyGB
2024-10-31
beko-technologies.com
beko-technologies.combeko-technologies.com
ManufacturingDE
2024-12-04
snatt.it
snatt.itsnatt.it
Transportation/LogisticsIT
2024-11-13
medicacorp.com
medicacorp.commedicacorp.com
HealthcareUS
2024-11-14
lornestewartgroup.com
lornestewartgroup.comlornestewartgroup.com
Business ServicesGB
2024-12-04
vossko.de
vossko.devossko.de
Agriculture and Food ProductionDE
2024-10-17
mcleanmortgage.com
mcleanmortgage.commcleanmortgage.com
Financial ServicesUS
2024-10-16
suit-kote.com
suit-kote.comsuit-kote.com
Business ServicesUS
2024-10-23
andyfrain.com
andyfrain.comandyfrain.com
Business ServicesUS
2024-11-04
rembe.de
rembe.derembe.de
ManufacturingDE
2024-10-31
gfemlaw.com
gfemlaw.comgfemlaw.com
Business ServicesUS
2024-10-16
instinctpetfood.com
instinctpetfood.cominstinctpetfood.com
Agriculture and Food ProductionUS
2024-10-17
eatonmetal.com
eatonmetal.comeatonmetal.com
ManufacturingUS
2024-10-18
continentalserves.com
continentalserves.comcontinentalserves.com
Transportation/LogisticsUS
2024-10-16
wachter.com
wachter.comwachter.com
Business ServicesUS
2024-10-18
jonti-craft.com
jonti-craft.comjonti-craft.com
ManufacturingUS
2024-10-22
isaitaly.com
isaitaly.comisaitaly.com
ManufacturingIT
2024-10-05
rockportmortgage.com
rockportmortgage.comrockportmortgage.com
Financial ServicesUS
2024-10-14
kmcglobal.com
kmcglobal.comkmcglobal.com
ManufacturingUS
2024-10-23
rauch.de
rauch.derauch.de
Agriculture and Food ProductionDE
2024-10-10
daserv.com
daserv.comdaserv.com
TechnologyUS
2024-10-10
celo.com
celo.comcelo.com
TechnologyUS
2024-10-09
rosenlegal.com
rosenlegal.comrosenlegal.com
Business ServicesUS
2024-10-08
weberpackaging.com
weberpackaging.comweberpackaging.com
ManufacturingUS
2024-10-01
tuggleduggins.com
tuggleduggins.comtuggleduggins.com
Business ServicesUS
2024-09-28
temple-inc.com
temple-inc.comtemple-inc.com
ManufacturingUS
2024-10-03
milleredge.com
milleredge.commilleredge.com
ManufacturingUS
2024-10-08
gkcorp.com
gkcorp.comgkcorp.com
ManufacturingUS