logo

Response to CISA Advisory (AA24-131A): #StopRansomware: Black Basta

ID: 19a6948a-3fc6-53c0-8994-b3bd33db6f03

STIX ID: report--19a6948a-3fc6-53c0-8994-b3bd33db6f03

Feed Name: Security Boulevard

Threat Score
80/100

Date Published: 2024-05-17

Date Updated: 2026-04-22

Author: Francis Guibernau

...
...

AttackIQ describes an emulated attack graph based on CISA and vendor reporting for Black Basta ransomware: a Ransomware-as-a-Service strain that has conducted double-extortion operations against multiple critical infrastructure sectors since 2022. The report maps observed TTPs to MITRE ATT&CK (debugger checks, system/account discovery and creation, disabling defenses, RDP lateral movement, vssadmin shadow copy deletion, and RSA-4096+ChaCha20 file encryption), and provides detection and mitigation recommendations for defenders to validate and improve controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.