LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S1070: Black Basta

Black Basta is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since at least April 2022; there are variants that target Windows and VMWare ESXi servers. Black Basta operations have included the double extortion technique where in addition to demanding ransom for decrypting the files of targeted organizations the cyber actors also threaten to post sensitive information to a leak site if the ransom is not paid. Black Basta affiliates have targeted multiple high-value organizations, with the largest number of victims based in the U.S. Based on similarities in TTPs, leak sites, payment sites, and negotiation tactics, security researchers assess the Black Basta RaaS operators could include current or former members of the Conti group.[1][2][3][4][5][6]

EnterpriseS1070MalwareObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Black Basta matters because ATT&CK describes it as C++ ransomware offered through a ransomware-as-a-service model with Windows and VMware ESXi variants and reported double-extortion operations. For leaders, this is not just an endpoint malware issue: ESXi involvement makes virtualization recovery, backup integrity, and business continuity central to readiness.

Executive priority

Prioritize Black Basta as a resilience and incident-decision scenario: can the organization detect suspicious execution and discovery before encryption, protect recovery options, and make evidence-based decisions during extortion pressure? Validate that ransomware readiness covers Windows estates, ESXi servers, sensitive-data exposure concerns, and executive communications for double-extortion events.

Technical view

ATT&CK provides no official detection text for S1070, so coverage should be validated through the related behaviors: command execution via PowerShell, Windows Command Shell, WMI, and Native API; discovery of services, systems, files, directories, and system information; registry and Windows service modification; masquerading and resource-name abuse; virtualization/sandbox evasion; recovery inhibition; shutdown or reboot; internal defacement; and data encryption for impact. SOC and IR teams should test whether telemetry links these behaviors into a ransomware progression rather than treating each event as isolated administration.

Likely telemetry

  • Windows process creation and command-line telemetry for PowerShell, cmd, WMI, service control, registry modification, and discovery commands
  • Windows service creation/modification and service-name/display-name change logs
  • Registry modification events, especially changes associated with persistence or defense impairment
  • File and directory enumeration, large-scale file modification, and encryption-like activity on endpoints and servers
  • ESXi host management logs, shell/command activity, VM datastore access, shutdown/reboot events, and recovery-impacting actions

Detection direction

  • Because MITRE lists no official detection guidance, start with behavior-based analytics mapped to the related techniques rather than hash-only detection.
  • Correlate discovery activity followed by service/registry changes, suspicious script or shell execution, and rapid file modification as a higher-priority ransomware pattern.
  • Tune carefully for administrative false positives: WMI, PowerShell, service management, registry tools, and ESXi commands are legitimate in IT operations, so detections need asset role, user context, timing, and change-ticket context.
  • Validate ESXi visibility explicitly; many organizations have stronger Windows endpoint logging than hypervisor logging, creating a material blind spot for ransomware variants that target virtualization infrastructure.
  • Review whether security tools can inspect large or modified binaries, since the related Binary Padding behavior can undermine simple static or hash-based controls.

Mitigation priorities

  • Strengthen backup and recovery resilience first: maintain tested, protected recovery paths for Windows and ESXi systems and monitor for recovery inhibition.
  • Harden and monitor administrative execution paths including PowerShell, cmd, WMI, Windows services, registry modification, and ESXi management access.
  • Reduce exposure to user-driven execution by reinforcing attachment/file handling controls and user reporting workflows for suspicious files and social engineering.
  • Apply least privilege and administrative separation so service creation, registry modification, ESXi administration, and backup changes require appropriate authorization.
  • Maintain ransomware incident response playbooks that cover double extortion, sensitive-data assessment, legal/compliance evidence preservation, executive communications, and restoration sequencing.
Additional notes and limits

ATT&CK links Storm-1811 to Black Basta ransomware deployment and notes social-engineering mechanisms involving spam overload and fake help-desk interaction. That relationship supports validating help-desk, identity, and user-reporting processes as part of readiness, but the core S1070 object itself is malware-focused and does not provide a complete intrusion chain.

This take is limited to the supplied ATT&CK S1070 fields, external references, and relationships. MITRE provides no official detection text and no object-level tactics for Black Basta. Local conclusions about exposure, active exploitation, attribution, or detection coverage require environment-specific telemetry and incident evidence.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Black Basta

Black Basta is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since at least April 2022; there are variants that target Windows and VMWare ESXi servers. Black Basta operations have included the double extortion technique where in addition to demanding ransom for decrypting the files of targeted organizations the cyber actors also threaten to post sensitive information to a leak site if the ransom is not paid. Black Basta affiliates have targeted multiple high-value organizations, with the largest number of victims based in the U.S. Based on similarities in TTPs, leak sites, payment sites, and negotiation tactics, security researchers assess the Black Basta RaaS operators could include current or former members of the Conti group.[1][2][3][4][5][6]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

26 rows
DomainIDNameRelationship / procedure
EnterpriseT1490Inhibit System Recovery

Black Basta can delete shadow copies using vssadmin.exe.[3][6][7][4][5][2][1][8][8][9]

EnterpriseT1082System Information Discovery

Black Basta can collect system boot configuration and CPU information.[3][6]

EnterpriseT1553.002Code SigningSub-technique

The Black Basta dropper has been digitally signed with a certificate issued by Akeo Consulting for legitimate executables used for creating bootable USB drives.[9]

EnterpriseT1497Virtualization/Sandbox Evasion

Black Basta can make a random number of calls to the `kernel32.beep` function to hinder log analysis.[9]

EnterpriseT1491.001Internal DefacementSub-technique

Black Basta has set the desktop wallpaper on victims' machines to display a ransom note.[3][12][6][7][4][5][2][1][9]

EnterpriseT1018Remote System Discovery

Black Basta can use LDAP queries to connect to AD and iterate over connected workstations.[9]

EnterpriseT1112Modify Registry

Black Basta has modified the Registry to enable itself to run in safe mode, to change the icons and file extensions for encrypted files, and to add the malware path for persistence.[3][6][7][5][2][1]

EnterpriseT1083File and Directory Discovery

Black Basta can enumerate specific files for encryption.[6][4][5][13][2][1][8][9]

EnterpriseT1486Data Encrypted for Impact

Black Basta can encrypt files with the ChaCha20 cypher and using a multithreaded process to increase speed.[3][12][6][5][13][2][1][8][9] Black Basta has also encrypted files while the victim system is in safe mode, appending `.basta` upon completion.[7]

EnterpriseT1622Debugger Evasion

The Black Basta dropper can check system flags, CPU registers, CPU instructions, process timing, system libraries, and APIs to determine if a debugger is present.[9]

EnterpriseT1204.002Malicious FileSub-technique

Black Basta has been downloaded and executed from malicious Excel files.[7][8]

EnterpriseT1222.002Linux and Mac PermissionsSub-technique

The Black Basta binary can use `chmod` to gain full permissions to targeted files.[13]

EnterpriseT1059.003Windows Command ShellSub-technique

Black Basta can use `cmd.exe` to enable shadow copy deletion.[2]

EnterpriseT1007System Service Discovery

Black Basta can check whether the service name `FAX` is present.[6]

EnterpriseT1680Local Storage Discovery

Black Basta can enumerate volumes.[3][6]

EnterpriseT1497.001System ChecksSub-technique

Black Basta can check system flags and libraries, process timing, and API's to detect code emulation or sandboxing.[1][9]

EnterpriseT1059.001PowerShellSub-technique

Black Basta has used PowerShell scripts for discovery and to execute files over the network.[7][8][5]

EnterpriseT1543.003Windows ServiceSub-technique

Black Basta can create a new service to establish persistence.[3][4]

EnterpriseT1047Windows Management Instrumentation

Black Basta has used WMI to execute files over the network.[5]

EnterpriseT1688Safe Mode Boot

Black Basta can reboot victim machines in safe mode with networking via `bcdedit /set safeboot network`.[3][6][7][4][1]

EnterpriseT1027.001Binary PaddingSub-technique

Black Basta had added data prior to the Portable Executable (PE) header to prevent automatic scanners from identifying the payload.[9]

EnterpriseT1106Native API

Black Basta has the ability to use native APIs for numerous functions including discovery and defense evasion.[3][6][4][9][7]

EnterpriseT1529System Shutdown/Reboot

Black Basta has used `ShellExecuteA` to shut down and restart the victim system.[7]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

The Black Basta dropper has mimicked an application for creating USB bootable drivers.[9]

EnterpriseT1480.002Mutual ExclusionSub-technique

Black Basta will check for the presence of a hard-coded mutex `dsajdhas.0` before executing.[2]

EnterpriseT1036.004Masquerade Task or ServiceSub-technique

Black Basta has established persistence by creating a new service named `FAX` after deleting the legitimate service by the same name.[3][6][7]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G1046: Storm-1811

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake "help desk" interaction leading to the deployment of adversary tools and capabilities.[1][2][3][4]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
866178ff76062797...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundle866178ff7606…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  2. [2]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  3. [3]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  4. [4]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  5. [5]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  6. [6]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  7. [7]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  8. [8]
    Trend Micro Black Basta Spotlight September 2022

    Trend Micro. (2022, September 1). Ransomware Spotlight Black Basta. Retrieved March 8, 2023.

    Open source URL
  9. [9]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  10. [10]
    Microsoft Storm-1811 2024

    Microsoft Threat Intelligence. (2024, May 15). Threat actors misusing Quick Assist in social engineering attacks leading to ransomware. Retrieved March 14, 2025.

    Open source URL
  11. [11]
    rapid7-email-bombing

    Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

    Open source URL
  12. [12]
    BlackBerry Black Basta May 2022

    Ballmer, D. (2022, May 6). Black Basta: Rebrand of Conti or Something New?. Retrieved March 7, 2023.

    Open source URL
  13. [13]
    Uptycs Black Basta ESXi June 2022

    Sharma, S. and Hegde, N. (2022, June 7). Black basta Ransomware Goes Cross-Platform, Now Targets ESXi Systems. Retrieved March 8, 2023.

    Open source URL
  14. [14]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  15. [15]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  16. [16]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  17. [17]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  18. [18]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  19. [19]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  20. [20]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  21. [21]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  22. [22]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  23. [23]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  24. [24]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  25. [25]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  26. [26]
    mitre-attackS1070
    Open source URL
  27. [27]
    mitre-attackS1070
    Open source URL
  28. [28]
    mitre-attackS1070
    Open source URL
  29. [29]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  30. [30]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  31. [31]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  32. [32]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  33. [33]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  34. [34]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  35. [35]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  36. [36]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  37. [37]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  38. [38]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  39. [39]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  40. [40]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  41. [41]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  42. [42]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  43. [43]
    Trend Micro Black Basta Spotlight September 2022

    Trend Micro. (2022, September 1). Ransomware Spotlight Black Basta. Retrieved March 8, 2023.

    Open source URL
  44. [44]
    Microsoft Storm-1811 2024

    Microsoft Threat Intelligence. (2024, May 15). Threat actors misusing Quick Assist in social engineering attacks leading to ransomware. Retrieved March 14, 2025.

    Open source URL
  45. [45]
    rapid7-email-bombing

    Tyler McGraw, Thomas Elkins, and Evan McCann. (2024, May 10). Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators. Retrieved January 31, 2025.

    Open source URL
  46. [46]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  47. [47]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  48. [48]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  49. [49]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  50. [50]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  51. [51]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  52. [52]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  53. [53]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  54. [54]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  55. [55]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  56. [56]
    BlackBerry Black Basta May 2022

    Ballmer, D. (2022, May 6). Black Basta: Rebrand of Conti or Something New?. Retrieved March 7, 2023.

    Open source URL
  57. [57]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  58. [58]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  59. [59]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  60. [60]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  61. [61]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  62. [62]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  63. [63]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  64. [64]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  65. [65]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  66. [66]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  67. [67]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  68. [68]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  69. [69]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  70. [70]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  71. [71]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  72. [72]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  73. [73]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  74. [74]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  75. [75]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  76. [76]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  77. [77]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  78. [78]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  79. [79]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  80. [80]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  81. [81]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  82. [82]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  83. [83]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  84. [84]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  85. [85]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  86. [86]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  87. [87]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  88. [88]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  89. [89]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  90. [90]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  91. [91]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  92. [92]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  93. [93]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  94. [94]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  95. [95]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  96. [96]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  97. [97]
    Trend Micro Black Basta Spotlight September 2022

    Trend Micro. (2022, September 1). Ransomware Spotlight Black Basta. Retrieved March 8, 2023.

    Open source URL
  98. [98]
    Trend Micro Black Basta Spotlight September 2022

    Trend Micro. (2022, September 1). Ransomware Spotlight Black Basta. Retrieved March 8, 2023.

    Open source URL
  99. [99]
    Uptycs Black Basta ESXi June 2022

    Sharma, S. and Hegde, N. (2022, June 7). Black basta Ransomware Goes Cross-Platform, Now Targets ESXi Systems. Retrieved March 8, 2023.

    Open source URL
  100. [100]
    BlackBerry Black Basta May 2022

    Ballmer, D. (2022, May 6). Black Basta: Rebrand of Conti or Something New?. Retrieved March 7, 2023.

    Open source URL
  101. [101]
    BlackBerry Black Basta May 2022

    Ballmer, D. (2022, May 6). Black Basta: Rebrand of Conti or Something New?. Retrieved March 7, 2023.

    Open source URL
  102. [102]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  103. [103]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  104. [104]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  105. [105]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  106. [106]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  107. [107]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  108. [108]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  109. [109]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  110. [110]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  111. [111]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  112. [112]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  113. [113]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  114. [114]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  115. [115]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  116. [116]
    Trend Micro Black Basta Spotlight September 2022

    Trend Micro. (2022, September 1). Ransomware Spotlight Black Basta. Retrieved March 8, 2023.

    Open source URL
  117. [117]
    Trend Micro Black Basta Spotlight September 2022

    Trend Micro. (2022, September 1). Ransomware Spotlight Black Basta. Retrieved March 8, 2023.

    Open source URL
  118. [118]
    Uptycs Black Basta ESXi June 2022

    Sharma, S. and Hegde, N. (2022, June 7). Black basta Ransomware Goes Cross-Platform, Now Targets ESXi Systems. Retrieved March 8, 2023.

    Open source URL
  119. [119]
    Uptycs Black Basta ESXi June 2022

    Sharma, S. and Hegde, N. (2022, June 7). Black basta Ransomware Goes Cross-Platform, Now Targets ESXi Systems. Retrieved March 8, 2023.

    Open source URL
  120. [120]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  121. [121]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  122. [122]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  123. [123]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  124. [124]
    Trend Micro Black Basta Spotlight September 2022

    Trend Micro. (2022, September 1). Ransomware Spotlight Black Basta. Retrieved March 8, 2023.

    Open source URL
  125. [125]
    Trend Micro Black Basta Spotlight September 2022

    Trend Micro. (2022, September 1). Ransomware Spotlight Black Basta. Retrieved March 8, 2023.

    Open source URL
  126. [126]
    Uptycs Black Basta ESXi June 2022

    Sharma, S. and Hegde, N. (2022, June 7). Black basta Ransomware Goes Cross-Platform, Now Targets ESXi Systems. Retrieved March 8, 2023.

    Open source URL
  127. [127]
    Uptycs Black Basta ESXi June 2022

    Sharma, S. and Hegde, N. (2022, June 7). Black basta Ransomware Goes Cross-Platform, Now Targets ESXi Systems. Retrieved March 8, 2023.

    Open source URL
  128. [128]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  129. [129]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  130. [130]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  131. [131]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  132. [132]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  133. [133]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  134. [134]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  135. [135]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  136. [136]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  137. [137]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  138. [138]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  139. [139]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  140. [140]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  141. [141]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  142. [142]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  143. [143]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  144. [144]
    Trend Micro Black Basta Spotlight September 2022

    Trend Micro. (2022, September 1). Ransomware Spotlight Black Basta. Retrieved March 8, 2023.

    Open source URL
  145. [145]
    Trend Micro Black Basta Spotlight September 2022

    Trend Micro. (2022, September 1). Ransomware Spotlight Black Basta. Retrieved March 8, 2023.

    Open source URL
  146. [146]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  147. [147]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  148. [148]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  149. [149]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  150. [150]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  151. [151]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  152. [152]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  153. [153]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  154. [154]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  155. [155]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  156. [156]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  157. [157]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  158. [158]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  159. [159]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  160. [160]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  161. [161]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  162. [162]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  163. [163]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  164. [164]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  165. [165]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  166. [166]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  167. [167]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  168. [168]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  169. [169]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  170. [170]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  171. [171]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  172. [172]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  173. [173]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  174. [174]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  175. [175]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  176. [176]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  177. [177]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  178. [178]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  179. [179]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  180. [180]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  181. [181]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.