logo

Black Basta Chat Leak - Organization and Infrastructures

ID: 1519c57a-ab4a-57ff-90d1-7fa833feca6c

STIX ID: report--1519c57a-ab4a-57ff-90d1-7fa833feca6c

Feed Name: Cybercrime Diaries

Threat Score
75/100

Date Published: 2025-03-05

Date Updated: 2026-04-19

Author: Oleg

...
...

This report reviews a February 2025 leak of 196,045 internal Matrix chat messages from the Black Basta ransomware group, assessing their authenticity and using them to map the group’s hierarchy, roles (leadership, infrastructure, affiliates, coders, crypting, social engineering), and infrastructure practices. It details how Black Basta used legitimate hosts via resellers (notably Hetzner), selective bulletproof hosting (e.g., Gerry), and proxying to obfuscate C2 (including Cobalt Strike), and notes periodic server and Matrix migrations alongside indications of two office-based operations under leader “Tramp” (likely Oleg Nefedov). While the group historically impacted 500+ organizations, the report observes no new victims since Jan 2025 and a downed leak site, yet underscores that the leak provides numerous investigatory leads (handles, services, contact data, crypto addresses, and vulnerabilities).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.