logo

BlackBasta Ransomware Brand Picks Up Where Conti Left Off

ID: d9b187cb-1eb1-5d2a-afce-0f13394948fe

STIX ID: report--d9b187cb-1eb1-5d2a-afce-0f13394948fe

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-11-25

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

This article examines the evolution of the BlackBasta ransomware franchise: how it adapted after Qakbot and Conti takedowns by leveraging alternative botnets (Pikabot), buying access from initial-access brokers, developing custom tools (Cogscan for reconnaissance, Knotrock to execute ransomware), and shifting toward social engineering and vishing; the report raises concerns about increasing sophistication, impact on sectors such as healthcare, and possible (but unconfirmed) liaison with Russian state actors, recommending defenders prioritize credential and endpoint protections and monitoring of open repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.