logo

Back in Black... Basta

ID: 0a08de53-4c0b-5d9a-9112-f82295659ee3

STIX ID: report--0a08de53-4c0b-5d9a-9112-f82295659ee3

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-12-30

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz details BlackBasta 2.0, a significantly rewritten ransomware variant that replaces RSA/GMP and ChaCha20 with NIST P-521 ECC (Crypto++) and XChaCha20, introduces stack-based string obfuscation and randomized filenames/extensions, appends a per-file cryptographic footer, and alters encryption patterns to evade AV/EDR; the report includes feature comparisons to the prior version, observed behavioral changes, example IOCs, and notes several confirmed victims.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.