logo

DNS Early Detection – Breaking the Black Basta Ransomware Kill Chain

ID: a3bf091e-efff-5bf3-bf9d-5c0ddb842540

STIX ID: report--a3bf091e-efff-5bf3-bf9d-5c0ddb842540

Feed Name: Infoblox Threat Intel Blog

Threat Score
78/100

Date Published: 2024-08-01

Date Updated: 2026-04-28

Author: Michael Zuckerman

...
...

**Executive Summary:** This Infoblox bulletin summarizes the Black Basta ransomware campaign (active since April 2022) which has impacted critical infrastructure—particularly healthcare—using phishing and exploitation of known vulnerabilities to perform double-extortion; it maps MITRE ATT&CK TTPs, lists malicious domains and demonstrates that Infoblox DNS early-detection flagged ~78% of those domains an average of 59.5 days before OSINT, recommending Protective DNS and threat-intel feeds to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.