Ransomware group

Black Basta

Black Basta is a Russian-speaking ransomware operation that emerged publicly in 2022 and has been widely reported as connected to the broader post-Conti crimeware ecosystem. Public reporting indicates the group operated a double-extortion model (data theft plus encryption) and relied on a multi-party ecosystem of initial access, tooling, hosting, and financial infrastructure.

In February–March 2025, large volumes of internal chat logs from a Matrix server were leaked publicly, providing visibility into operational tradecraft and third-party dependencies. Multiple analyses argue that the leak and upstream disruptions to access channels (e.g., QakBot-related disruption in 2023) contributed to fragmentation and affiliate migration rather than a clean “shutdown”.

Created by iQBlack CTI Team
Contributors 1
Last updated 2026-08-23

ATT&CK

MITRE ATT&CK

T1003OS Credential Dumping
T1021.001Remote Desktop Protocol
T1036Masquerading
T1041Exfiltration Over C2 Channel
T1046Network Service Discovery
T1047Windows Management Instrumentation
T1053.005Scheduled Task
T1059.001PowerShell
T1078Valid Accounts
T1087Account Discovery
T1105Ingress Tool Transfer
T1486Data Encrypted for Impact
T1490Inhibit System Recovery
T1543.003Windows Service
T1560Archive Collected Data
T1566.001Spearphishing Attachment

Research

Selected OSINT