Threat actor
Black Basta
FBI, CISA, HHS and MS-ISAC describe Black Basta as a ransomware-as-a-service variant, first identified in April 2022, whose actors encrypted and stole data from at least 12 of 16 critical infrastructure sectors.Source [1]
What authorities and investigators report
- The advisory says Black Basta affiliates primarily used spearphishing to obtain initial access and, in some instances, abused valid credentials.Source [1]
- The November 2024 update says that, in a campaign launched in May 2024, affiliates sent targeted users a large volume of spam email, then called them acting as technical support and asked them to download a remote access tool.Source [1]
- It says that from October 2024 the campaign also used Microsoft Teams, with operators messaging victims from external organizations' Teams accounts while posing as technical support.Source [1]
- It says affiliates used credential scraping tools like Mimikatz for privilege escalation.Source [1]
- It says affiliates used a double-extortion model, both encrypting systems and exfiltrating data.Source [1]
Techniques
Attack vectors
Sources
- #StopRansomware: Black Basta (AA24-131A) — CISA, 2024-11-08
Last reviewed Oct 2, 2026