logo

Black Basta Ransomware Strikes 500+ Entities Across North America, Europe, and Australia

ID: 328433e1-5c6a-5eb8-833c-97a068a6fb5b

STIX ID: report--328433e1-5c6a-5eb8-833c-97a068a6fb5b

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2024-05-13

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

The advisory summarizes Black Basta ransomware-as-a-service activity since April 2022, noting over 500 targeted organizations across critical infrastructure and private industry; affiliates use phishing and known-vulnerability exploitation to gain initial access, deploy tooling such as Cobalt Strike, Mimikatz, PsExec, and RClone, exfiltrate data for double extortion, and encrypt files with ChaCha20/RSA-4096 after disabling recovery; the report also highlights continued exploitation of Qlik Sense (CVE-2023-48365) by CACTUS and an overall shifting ransomware landscape with rebranding and declines in ransom payments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.