Avatier

Threat actor

Black Basta

FBI, CISA, HHS and MS-ISAC describe Black Basta as a ransomware-as-a-service variant, first identified in April 2022, whose actors encrypted and stole data from at least 12 of 16 critical infrastructure sectors.Source [1]

What authorities and investigators report

  • The advisory says Black Basta affiliates primarily used spearphishing to obtain initial access and, in some instances, abused valid credentials.Source [1]
  • The November 2024 update says that, in a campaign launched in May 2024, affiliates sent targeted users a large volume of spam email, then called them acting as technical support and asked them to download a remote access tool.Source [1]
  • It says that from October 2024 the campaign also used Microsoft Teams, with operators messaging victims from external organizations' Teams accounts while posing as technical support.Source [1]
  • It says affiliates used credential scraping tools like Mimikatz for privilege escalation.Source [1]
  • It says affiliates used a double-extortion model, both encrypting systems and exfiltrating data.Source [1]

Techniques

Attack vectors

Sources

  1. #StopRansomware: Black Basta (AA24-131A) — CISA, 2024-11-08

Last reviewed Oct 2, 2026