blackbasta logo

blackbasta

3 incidentes 2 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Ver en IntelTracker → APTTrail →
Black Basta is a financially motivated ransomware-as-a-service (RaaS) group that emerged in April 2022, rapidly distinguishing itself through its aggressive double-extortion tactics, combining data encryption with data theft and public shaming on its 'Basta News' leak site. Assessed with high confidence to be of Russian origin, the group quickly accumulated a significant number of victims globally, leading to speculation that it may be a rebrand or an offshoot of the Russian-speaking Conti ransomware group, or closely linked to other Russian-speaking cybercriminal organizations like FIN7, due to similar tactics, techniques, and procedures. Black Basta operates as a closed RaaS, not openly recruiting on underground forums, which contributes to its perceived exclusivity and sophistication. The group's leader, known as GG or AA, is reportedly a Russian individual, and the group maintained offices in Moscow, further cementing its suspected origin.
Tecnicas MITRE
T1087.002, T1021.004, T1656, T1074.001, T1583, T1059.001
CVEs relacionadas
CVE-2025-23121, CVE-2025-23120, CVE-2024-37085, CVE-2024-26169, CVE-2024-1709, CVE-2024-1708

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United Kingdom (1) United States (1)

Paises objetivo (SOCRadar)

United Arab EmiratesAustriaAustraliaBangladeshBelgiumBrazilCanadaSwitzerlandCosta RicaCzech Republic

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsTransportation Equipment ManufacturingEnterprises & HoldingAccommodationAir Transportation

URLs nuevas detectadas en IntelTracker

github.com raw.githubusercontent.com github.com ransomware.anggipradana.com

Victimas (1)

Ransom Notes: blackbasta (5 notes from ThreatLabz)18 Jun 2026
Report
blackbasta - Ransom NotesEste grupo de ransomware tiene 5 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de re…