← All actors

Black Basta

Aliases: BlackBasta, Black Basta ransomware

Source profile review date: 2026-05-31

Added to the source registry: 2022-04-26 · Source snapshot: 2026-09-15

Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.

Research status: Existing researched dossier

Executive summary

Black Basta is a professional ransomware operation with strong focus on enterprise impact, data theft, lateral movement and disruption of recovery.

Black Basta should be investigated as an enterprise intrusion where access, credential abuse, security-tool impairment, data theft and encryption converge in a short but severe impact phase.

Latest five known victim claims

Loading stored claims…

    These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.

    Executive summary

    Black Basta matters at leadership level because it affects organisations where continuity, Windows domains, identity, backups and data volume are tightly connected. CISA, FBI, HHS and MS-ISAC published a #StopRansomware advisory with TTPs and IOC context for known Black Basta affiliates, including impact on enterprises and critical infrastructure such as healthcare-like environments.

    The threat is not only encryption. Black Basta-like incidents usually start with access and control build-up, followed by discovery, privilege escalation, credential access, lateral movement, data staging, security-tool impairment and only later visible encryption or publication.

    A Black Basta dossier must answer five questions: how the actor entered, which privileges were used, which data was accessed or stolen, which recovery resources were affected and which controls could have stopped the chain.

    Group and development

    Black Basta has been named in public threat reporting since 2022 and is generally treated as a financially motivated ransomware operation with professionally executed intrusions. The group uses pressure through data theft and publication and targets organisations where downtime and confidential data create enough leverage.

    The group is relevant for sectors with complex Windows environments, sensitive data, much external access and dependency on central IT. Healthcare, manufacturing, services, transport and enterprise environments are typical risk profiles.

    As with other RaaS-like ecosystems, the profile must allow variation. Not every Black Basta claim uses the same route; the dossier therefore provides a forensic framework rather than a fixed attack button.

    Methods and attack chain

    Start with initial access. Investigate phishing, stolen credentials, remote access, VPN, RDP, exposed services, vulnerable edge systems and brokered access. Collect authentication logs, VPN events, firewall logs, mailbox activity, SSO events and EDR signals.

    In the middle phase, credential access and lateral movement are critical. Look for LSASS access, domain discovery, group membership changes, remote service creation, PowerShell, WMI, PsExec-like behaviour, RDP hops, admin share access and domain-controller access.

    Security-tool impairment and recovery disruption must be investigated explicitly. Check EDR alerts, service stops, driver or tool abuse, policy changes, deleted logs, shadow-copy actions, backup-server access and recovery-job changes.

    Data theft needs its own track. Look for large file reads, compression, staging directories, cloud uploads, Rclone-like behaviour and traffic to unknown destinations. Distinguish between data access, staging and proven exfiltration.

    Attack pattern from public cases

    CISA, FBI, HHS and MS-ISAC describe Black Basta as a RaaS variant active since April 2022. The group is associated with enterprise intrusions combining access, credential abuse, Cobalt Strike-like infrastructure, data theft and encryption.

    A typical defensive picture is initial access through phishing, remote access or existing credentials, followed by privilege escalation and lateral movement in the Windows domain. The actor searches file shares, backup systems, security tooling and data with extortion value.

    Black Basta is especially relevant for organisations with strong central Windows dependency. If domain accounts are broadly reused and backups are reachable through the same administration path, one foothold can become business-wide impact.

    The key defensive lesson is to view Cobalt Strike-like network communication, Rclone/WinSCP-like data movement, EDR disruption and large file-share reads together. Separately they may look like administration; together they form a ransomware chain.

    Known IOCs and artefacts

    CISA AA24-131A names current network indicators from November 2024, including 170.130.165[.]73 and 45.11.181[.]44 as likely Cobalt Strike infrastructure.

    The same update names 79.132.130[.]211 as likely Cobalt Strike infrastructure and 66.42.118[.]54 as an exfiltration server. Validate these indicators against internal logs and use them for historical searches.

    Historical Black Basta indicator lists include rclone.exe and WinSCP.exe hashes associated with data movement. Such artefacts must be tied to command lines and destinations.

    Other historical hashes are useful mainly for retro-hunting. They should not be the only current detection layer.

    Victims and historical context

    Black Basta has been publicly associated with organisations in North America, Europe and Australia and with critical infrastructure. Victim history should be recorded as sector, country, data types, access pattern and impact form, not only names.

    Record per claim whether encryption, data theft, pure extortion, supply-chain impact or republication is involved. That makes the feed useful for risk interpretation rather than only news monitoring.

    Detection and follow-up

    Recommended controls include phishing-resistant MFA, restricted remote access, fast patching of edge systems, least privilege, separated admin accounts, PAM, EDR hardening, application control, central logging, segmentation and immutable backups.

    A Black Basta hit should immediately trigger triage of whether the same access routes are open at customers. The profile translates public CTI into concrete questions about VPN, MFA, admin rights, EDR and backup separation.

    Deep forensic dossier

    Black Basta investigation must begin with enterprise context. The group is most dangerous where Windows domains, file shares, backup servers, remote management and EDR are tightly interwoven. The report must show how far the actor reached into the administration layer.

    Credential access is a core question. Look for LSASS access, dumping tools, suspicious handles, unusual process access, admin-group changes and use of accounts outside their normal hosts. Document every privileged account by time, source host and follow-up action.

    EDR impairment must be described as an incident phase. Stopping security processes, modifying policies, disabling services or abusing vulnerable drivers is preparation for impact, not background noise.

    Data exfiltration needs business interpretation. Which shares were read, which departments were affected, and did the volume match normal processes? Confidentiality impact can outweigh encryption impact.

    Recovery investigation must test whether backups were outside actor control. Check backup-console logins, job changes, deleted restore points, repository access, service-account use and network reachability.

    For customer communication, translate Black Basta into control points: remote access, MFA, privileged access, EDR, backups, segmentation, logging and data flows. Every finding should end in a control action or explicit uncertainty.

    What to watch for

    Black Basta is especially dangerous in Windows and enterprise environments where privileged accounts, file shares, backups and EDR administration are tightly connected. Watch valid accounts suddenly accessing servers, domain discovery, credential access, new admin rights and stopped security tools.

    Important signals include LSASS access, suspicious PowerShell, WMI or PsExec-like behaviour, RDP hops, admin-group changes, large file reads, compression, staging directories, backup-console logins and EDR tampering alerts.

    Black Basta attacks become severe when the actor affects recovery resources as well as data or systems. Always check backup servers, domain controllers, privileged accounts and EDR management.

    How to defend against Black Basta

    Limit privilege. Use separated admin accounts, prevent daily high-privilege use, monitor group changes and check service accounts. Combine this with strong MFA for remote access and administrators plus fast patching of internet-facing systems.

    Make EDR and logging resilient. Limit who can disable security software, forward logs centrally, detect event-log clearing and service stops, and alert on credential dumping.

    Protect backups and recovery procedures. Use immutable or offline backups, restrict console access, use separate credentials and test recovery when the domain cannot be trusted.

    Victim pattern and lessons

    Black Basta is publicly connected to multiple sectors, including healthcare, manufacturing, services and critical infrastructure. The common factor is often complexity: many systems, many accounts, much data and high dependency on central IT.

    The lesson for visitors is that enterprise ransomware often moves through normal administration channels. What looks like administration in quiet times can be lateral movement during an attack.

    If a Black Basta claim appears in your supply chain, immediately check supplier dependency, shared accounts, remote management paths and data flows.

    Indicators of compromise (IOCs)

    Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.

    TypeValueSourceContext
    ip170.130.165[.]73CISA AA24-131ALikely Cobalt Strike infrastructure, first seen Oct. 14 2024
    ip45.11.181[.]44CISA AA24-131ALikely Cobalt Strike infrastructure, first seen Oct. 24 2024
    ip66.42.118[.]54CISA AA24-131AExfiltration server, first seen Oct. 15 2024
    ip79.132.130[.]211CISA AA24-131ALikely Cobalt Strike infrastructure, first seen Oct. 24 2024
    sha2560112e3b20872760dda5f658f6b546c85f126e803e27f0577b294f335ffa5a298CISA AA24-131A historical tablerclone.exe
    sha256d3683beca3a40574e5fd68d30451137e4a8bbaca8c428ebb781d565d6a70385eCISA AA24-131A historical tableWinSCP.exe

    Sources

    Evidence and limitations

    Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.