logo

New ransomware variant targeting high-value organizations

ID: 2585db7c-0b40-50d0-affc-a8e2fab68cd0

STIX ID: report--2585db7c-0b40-50d0-affc-a8e2fab68cd0

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

**Black Basta Ransomware Summary:** Black Basta is an active ransomware group (since April 2022) targeting high-value organizations—notably in construction and manufacturing—with data theft and encryption (files suffixed .basta); the malware deletes shadow copies, changes boot configuration to run a hijacked FAX service in Safe Mode to perform multithreaded encryption, drops ransom notes and custom icons/wallpapers, and has an associated leak site and recovery portal similar to Conti; the report includes IoCs, MITRE ATT&CK mappings, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.