logo

Black Basta: Defense Evasion Capability Embedded in Ransomware Payload

ID: f178c25c-79d1-5513-b1ff-8bd852e14b5b

STIX ID: report--f178c25c-79d1-5513-b1ff-8bd852e14b5b

Feed Name: security.com

Threat Score
78/100

Date Published: 2026-02-05

Date Updated: 2026-04-29

Author: Threat Hunter Team

...
...

This Symantec-style intelligence brief describes a Black Basta (Cardinal) ransomware campaign that unusually embedded a vulnerable NsecSoft NSecKrnl kernel driver (CVE-2025-68947) inside the ransomware payload to terminate security/EDR processes (BYOVD), appending ".locked" to encrypted files; the report also notes a prior suspicious side-loaded loader, post-deployment presence of the GotoHTTP RAT, and provides hashes and IOCs for the ransomware, driver, loader and webshell.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.