S1070Windows
S1070Black Basta
Platforms
1
ATT&CK
14.1
References
7
Description
[Black Basta](https://attack.mitre.org/software/S1070) is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since at least April 2022; there are variants that target Windows and VMWare ESXi servers. [Black Basta](https://attack.mitre.org/software/S1070) operations have included the double extortion technique where in addition to demanding ransom for decrypting the files of targeted organizations the cyber actors also threaten to post sensitive information to a leak site if the ransom is not paid. [Black Basta](https://attack.mitre.org/software/S1070) affiliates have targeted multiple high-value organizations, with the largest number of victims based in the U.S. Based on similarities in TTPs, leak sites, payment sites, and negotiation tactics, security researchers assess the [Black Basta](https://attack.mitre.org/software/S1070) RaaS operators could include current or former members of the [Conti](https://attack.mitre.org/software/S0575) group.(Citation: Palo Alto Networks Black Basta August 2022)(Citation: Deep Instinct Black Basta August 2022)(Citation: Minerva Labs Black Basta May 2022)(Citation: Avertium Black Basta June 2022)(Citation: NCC Group Black Basta June 2022)(Citation: Cyble Black Basta May 2022)
Platforms· 1
Windows
References
- https://attack.mitre.org/software/S1070
- https://www.avertium.com/resources/threat-reports/in-depth-look-at-black-basta-ransomware
- https://blog.cyble.com/2022/05/06/black-basta-ransomware/
- https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware
- https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/
- https://www.deepinstinct.com/blog/black-basta-ransomware-threat-emergence
- https://minerva-labs.com/blog/new-black-basta-ransomware-hijacks-windows-fax-service/
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.