logo

UNC4393: Collaboration Leads to BASTA Ransomware Attacks

ID: f0c598ba-2cef-5097-a8a5-95069888caf8

STIX ID: report--f0c598ba-2cef-5097-a8a5-95069888caf8

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2024-07-30

Date Updated: 2026-04-13

Author: Kaaviya

...
...

UNC4393, the core operator behind the BASTA ransomware, conducts financially motivated ransomware and extortion campaigns across multiple industries (over 40 intrusions), has a growing presence in healthcare, and uses a complex, evolving toolset (BASTA, SYSTEMBC, DAWNCRY, PORTYARD, KNOTROCK, COGSCAN, SILENTNIGHT) and varied access methods (QAKBOT historically, now malvertising) to perform reconnaissance, lateral movement, exfiltration, and automated encryption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.