Skip to main content

Operator dossier

blackbasta is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 523 public victims claimed by this operator between April 26, 2022 and January 11, 2025. Black Basta is a highly sophisticated ransomware group that emerged in April 2022 and operates with a primary motivation of financial extortion, having rapidly established itself as one of the most prolific ransomware operations of the modern era with over 500 confirmed victims globally. The group is widely assessed by researchers including Mandiant and CISA to have likely ties to former members of the Conti ransomware syndicate following that group's dissolution in mid-2022, and operates as a private Ransomware-as-a-Service (RaaS) model with a closed affiliate structure rather than open recruitment, with suspected links to the FIN7 threat actor cluster based on observed tooling overlaps documented by SentinelOne and Microsoft. Black Basta employs a double extortion methodology, exfiltrating sensitive victim data prior to encryption and threatening publication on their Tor-based leak site "Basta News" to compound pressure on victims; initial access is predominantly achieved through phishing campaigns, purchase of stolen credentials, and exploitation of known vulnerabilities including QakBot malware distribution, with the group subsequently deploying tools such as Cobalt Strike, SystemBC, and their custom encryptor targeting both Windows and VMware ESXi environments using a ChaCha20 encryption algorithm. Per CISA and FBI joint advisory AA24-131A published in May 2024, the group has struck over 500 organizations across North America, Europe, and Australia, with high-profile victims including Ascension Health, Capita, the American Dental Association, and Rheinmetall, demonstrating a clear preference for manufacturing, business services, technology, transportation, and food production sectors across the United States, United Kingdom, Germany, Canada, and Italy. As of the time of available public reporting, Black Basta remained operationally active, though internal chat logs leaked in early 2025 revealed significant internal tensions and potential organizational fragmentation that security researchers assessed could impact the group's near-term operational cohesion.

Most-targeted sectors

Most-affected countries

Recent disclosures by blackbasta

Most recent 150 of 523 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for blackbasta

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

blackbasta

523 victims indexed · first seen 4 years ago · last activity 2 years ago

523
Victims indexed
#21 of 370 tracked operators
2y 9m
Active period
Apr 2022 → Jan 2025
25
Countries hit
top US · 187

At a glance

Status
inactive
First seen
4 years ago
Last activity
2 years ago
Onion sites
4 known endpoints
Primary sector
Manufacturing · 148 hits

About

Black Basta is a highly sophisticated ransomware group that emerged in April 2022 and operates with a primary motivation of financial extortion, having rapidly established itself as one of the most prolific ransomware operations of the modern era with over 500 confirmed victims globally. The group is widely assessed by researchers including Mandiant and CISA to have likely ties to former members of the Conti ransomware syndicate following that group's dissolution in mid-2022, and operates as a private Ransomware-as-a-Service (RaaS) model with a closed affiliate structure rather than open recruitment, with suspected links to the FIN7 threat actor cluster based on observed tooling overlaps documented by SentinelOne and Microsoft. Black Basta employs a double extortion methodology, exfiltrating sensitive victim data prior to encryption and threatening publication on their Tor-based leak site "Basta News" to compound pressure on victims; initial access is predominantly achieved through phishing campaigns, purchase of stolen credentials, and exploitation of known vulnerabilities including QakBot malware distribution, with the group subsequently deploying tools such as Cobalt Strike, SystemBC, and their custom encryptor targeting both Windows and VMware ESXi environments using a ChaCha20 encryption algorithm. Per CISA and FBI joint advisory AA24-131A published in May 2024, the group has struck over 500 organizations across North America, Europe, and Australia, with high-profile victims including Ascension Health, Capita, the American Dental Association, and Rheinmetall, demonstrating a clear preference for manufacturing, business services, technology, transportation, and food production sectors across the United States, United Kingdom, Germany, Canada, and Italy. As of the time of available public reporting, Black Basta remained operationally active, though internal chat logs leaked in early 2025 revealed significant internal tensions and potential organizational fragmentation that security researchers assessed could impact the group's near-term operational cohesion.

References

23 links

External sources curated by the MISP threat-intel community.

Timeline

24 months
2022-10-01T00:00:00+00:00 · 242022-11-01T00:00:00+00:00 · 82022-12-01T00:00:00+00:00 · 162023-03-01T00:00:00+00:00 · 482023-04-01T00:00:00+00:00 · 212023-05-01T00:00:00+00:00 · 82023-06-01T00:00:00+00:00 · 112023-07-01T00:00:00+00:00 · 62023-08-01T00:00:00+00:00 · 62023-10-01T00:00:00+00:00 · 182023-11-01T00:00:00+00:00 · 412023-12-01T00:00:00+00:00 · 152024-01-01T00:00:00+00:00 · 172024-02-01T00:00:00+00:00 · 242024-03-01T00:00:00+00:00 · 352024-04-01T00:00:00+00:00 · 202024-05-01T00:00:00+00:00 · 192024-06-01T00:00:00+00:00 · 152024-07-01T00:00:00+00:00 · 72024-09-01T00:00:00+00:00 · 22024-10-01T00:00:00+00:00 · 122024-11-01T00:00:00+00:00 · 142024-12-01T00:00:00+00:00 · 202025-01-01T00:00:00+00:00 · 8
2022-10-01T00:00:00+00:002025-01-01T00:00:00+00:00

Top countries

🇺🇸 United States
187
🇬🇧 United Kingdom
39
🇩🇪 Germany
28
🇨🇦 Canada
27
🇮🇹 Italy
18
🇨🇭 Switzerland
8
🇳🇱 Netherlands
7
🇫🇷 France
7

Top sectors

Manufacturing
148
Business Services
125
Technology
40
Agriculture and Food Production
39
Transportation/Logistics
30
Consumer Services
28
Financial Services
22
Construction
21

MITRE ATT&CK

39 techniques · 10 tactics

Tactics

Initial AccessExecutionPrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationImpact

Techniques

  • T1190Exploit Public-Facing Application
  • T1566.001Phishing: Spearphishing Attachment
  • T1566.002Phishing: Spearphishing Link
  • T1078Valid Accounts
  • T1133External Remote Services
  • T1059.001Command and Scripting Interpreter: PowerShell
  • T1059.003Command and Scripting Interpreter: Windows Command Shell
  • T1059.005Command and Scripting Interpreter: Visual Basic
  • T1047Windows Management Instrumentation
  • T1106Native API
  • T1548.002Abuse Elevation Control Mechanism: Bypass User Account Control
  • T1068Exploitation for Privilege Escalation
  • T1055Process Injection
  • T1562.001Impair Defenses: Disable or Modify Tools
  • T1562.009Impair Defenses: Safe Mode Boot
  • T1070.004Indicator Removal: File Deletion
  • T1027Obfuscated Files or Information
  • T1036Masquerading
  • T1003.001OS Credential Dumping: LSASS Memory
  • T1003.003OS Credential Dumping: NTDS
  • T1110Brute Force
  • T1018Remote System Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1135Network Share Discovery
  • T1087Account Discovery
  • T1069Permission Groups Discovery
  • T1021.001Remote Services: Remote Desktop Protocol
  • T1021.002Remote Services: SMB/Windows Admin Shares
  • T1570Lateral Tool Transfer
  • T1560.001Archive Collected Data: Archive via Utility
  • T1005Data from Local System
  • T1039Data from Network Shared Drive
  • T1048Exfiltration Over Alternative Protocol
  • T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage
  • T1486Data Encrypted for Impact
  • T1489Service Stop
  • T1490Inhibit System Recovery
  • T1491.001Defacement: Internal Defacement

Recent victims

Loading…

Onion infrastructure

4 known
  • http://aazsbsgya565vlu2c6bzy6yfiebkcbtvvcytvolt33s77xypi7nypxyd.onion
  • http://bastad5huzwkepdixedg2gekg7jk22ato24zyllp6lnjx7wdtyctgvyd.onion
  • http://databasebb.top
  • http://stniiomyjliimcgkvdszvgen3eaaoz55hreqqx6o77yvmpwt7gklffqd.onion

Source

Updated 2 years ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time blackbasta posts a victim.

Add blackbasta to your watchlist — Pro pings you within 5 minutes of any new blackbasta leak-site post, Telegram callout, or affiliate-rebrand inference.