BlackBasta Ransomware Brand Picks Up Where Conti Left Off
ID: d9b187cb-1eb1-5d2a-afce-0f13394948fe
STIX ID: report--d9b187cb-1eb1-5d2a-afce-0f13394948fe
Feed Name: Dark Reading
Date Published: 2024-11-25
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
This article examines the evolution of the BlackBasta ransomware franchise: how it adapted after Qakbot and Conti takedowns by leveraging alternative botnets (Pikabot), buying access from initial-access brokers, developing custom tools (Cogscan for reconnaissance, Knotrock to execute ransomware), and shifting toward social engineering and vishing; the report raises concerns about increasing sophistication, impact on sectors such as healthcare, and possible (but unconfirmed) liaison with Russian state actors, recommending defenders prioritize credential and endpoint protections and monitoring of open repositories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
