Uptime Hamster: 21d 6h 7mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza blackbasta

blackbasta

2 incidentes 1 paises 0 sectores threat-actor RU Ultimo: 2026-06-29
Aliases: DEV-0569, Conti, Quantum, Black Byte, Diavol, Black Basta, Ryuk (como FIN12)
Ver en IntelTracker → APTTrail →
Black Basta is a financially motivated ransomware-as-a-service (RaaS) group that emerged in April 2022, rapidly distinguishing itself through its aggressive double-extortion tactics, combining data encryption with data theft and public shaming on its 'Basta News' leak site. Assessed with high confidence to be of Russian origin, the group quickly accumulated a significant number of victims globally, leading to speculation that it may be a rebrand or an offshoot of the Russian-speaking Conti ransomware group, or closely linked to other Russian-speaking cybercriminal organizations like FIN7, due to similar tactics, techniques, and procedures. Black Basta operates as a closed RaaS, not openly recruiting on underground forums, which contributes to its perceived exclusivity and sophistication. The group's leader, known as GG or AA, is reportedly a Russian individual, and the group maintained offices in Moscow, further cementing its suspected origin.

Aliases del actor

DEV-0569ContiQuantumBlack ByteDiavolBlack BastaRyuk (como FIN12)

Actores similares

blackbyteransomware · 147blackbyte-cruxactor · 1BlackBytethreat-actor · 0blacksuitransomware · 184blacknevasthreat-actor · 16blackwaterthreat-actor · 11blackshrantacthreat-actor · 8black-xactor · 6blackoutthreat-actor · 4blackfieldactor · 3

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: blackbasta
Repositorioupgithub.comBlackBasta
DLS / leak siteupraw.githubusercontent.comBlackBasta
DLS / leak siteupwww.microsoft.comBlackBasta
Webunknownwww.cisa.govOSINT
Repositoriounknowngithub.comBushidoUK ToolMatrix GroupProfiles: BlackBasta
Repositoriounknowngithub.comBushidoUK ToolMatrix GroupProfiles: BlackBasta
Webunknownwww.trendmicro.comOSINT
Repositoriounknowngithub.comRansom Notes: blackbasta (5 notes from ThreatLabz)
DLS / onionofflinestniiomyjliimcgkvdszvgen3eaaoz55hreqqx6o77yvmpwt7gklffqd.onionmarktsec
DLS / onionofflineaazsbsgya565vlu2c6bzy6yfiebkcbtvvcytvolt33s77xypi7nypxyd.onionCTI.FYI
DLS / onionofflinebastad5huzwkepdixedg2gekg7jk22ato24zyllp6lnjx7wdtyctgvyd.onionCTI.FYI
DLS / leak siteunknowncloud.google.comOSINT
Tecnicas MITRE
T1087.002, T1021.004, T1656, T1074.001, T1583, T1059.001
CVEs relacionadas
CVE-2025-23121, CVE-2025-23120, CVE-2024-37085, CVE-2024-26169, CVE-2024-1709, CVE-2024-1708
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (OSINT)

United Arab EmiratesAustriaAustraliaBangladeshBelgiumBrazilCanadaSwitzerlandCosta RicaCzech Republic

Sectores objetivo (OSINT)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsTransportation Equipment ManufacturingEnterprises & HoldingAccommodationAir Transportation

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com github.com raw.githubusercontent.com github.com

Victimas (1)

Ransom Notes: blackbasta (5 notes from ThreatLabz)18 Jun 2026
Report
blackbasta - Ransom NotesEste grupo de ransomware tiene 5 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de re…