New ransomware variant targeting high-value organizations
ID: 2585db7c-0b40-50d0-affc-a8e2fab68cd0
STIX ID: report--2585db7c-0b40-50d0-affc-a8e2fab68cd0
Feed Name: Cyble Blog
**Black Basta Ransomware Summary:** Black Basta is an active ransomware group (since April 2022) targeting high-value organizations—notably in construction and manufacturing—with data theft and encryption (files suffixed .basta); the malware deletes shadow copies, changes boot configuration to run a hijacked FAX service in Safe Mode to perform multithreaded encryption, drops ransom notes and custom icons/wallpapers, and has an associated leak site and recovery portal similar to Conti; the report includes IoCs, MITRE ATT&CK mappings, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
