Blackbasta

Inactive
"Black Basta" is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their ability to quickly amass new victims and the style of their negotiations, this is likely not a new operation but rather a rebrand of a previous top-tier ransomware gang that brought along their affiliates.
523 Victims
Apr 26, 2022 First Discovered
Jan 11, 2025 Last Discovered
614 Days Inactive
0% Infostealer
0/3 Sites Online
Known Locations (3)
Chat Black Basta
bastad5huzwkepdixedg2gekg7jk22ato24zyllp6lnjx7wdtyctgvyd.onion
Chat Black Basta
aazsbsgya565vlu2c6bzy6yfiebkcbtvvcytvolt33s77xypi7nypxyd.onion
Black Basta Blog
stniiomyjliimcgkvdszvgen3eaaoz55hreqqx6o77yvmpwt7gklffqd.onion
Tools Used
CredentialTheft
Mimikatz
DefenseEvasion
Backstab (Process Explorer driver)
DiscoveryEnum
AdFind, Bloodhound, PSNmap, PowerView, SoftPerfect NetScan
Exfiltration
Qaz[.]im, RClone
LOLBAS
BITSAdmin, PsExec, Quick Assist
Offsec
Brute Ratel C4, Cobalt Strike, Metasploit, PowerSploit
RMM-Tools
AnyDesk, Atera, NetSupport, ScreenConnect, Splashtop, Supremo
Intelligence
Victims (523)

Detailed victim list temporarily unavailable

This group has 523 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.