Black Basta Ransomware: What You Need to Know
ID: e14b5f5c-d7de-56a7-b7a7-5b2981290738
STIX ID: report--e14b5f5c-d7de-56a7-b7a7-5b2981290738
Feed Name: Qualys Blog
Black Basta is a ransomware-as-a-service (RaaS) group first observed in April 2022 that uses double-extortion (data theft + encryption) across multiple industries; affiliates gain access via phishing, Qakbot, Cobalt Strike, RDP, and known CVE exploits, then exfiltrate with tools like Rclone/WinSCP and encrypt files using ChaCha20 with an RSA-4096-wrapped key while disabling recovery and defenses. The report provides detailed TTPs, MITRE ATT&CK mappings, Qualys EDR hunting queries, and an extensive list of IoCs (SHA256 hashes and C2 domains) for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
