RU

Black Basta

High ConfidenceHigh Threat

Basta News

Black Basta is a ransomware-as-a-service operation that emerged in April 2022, believed to have connections to the disbanded Conti ransomware group. The operation has rapidly become one of the most prolific ransomware threats, targeting hundreds of organizations across healthcare, manufacturing, and critical infrastructure sectors. Black Basta employs double extortion tactics and has demonstrated sophisticated capabilities including the use of custom tools for network reconnaissance and lateral movement. The group's operations have caused significant disruption to major organizations worldwide.

Origin: Russia
Sponsor: Cybercriminal (No State Sponsor)
Active: 2022 - Present
Victims: 500+ organizations
Advanced
Active
Financial Gain
Risk Assessment
81
Composite Risk Score
High Risk
ARCS Compliance85
Escalation Risk82
Grievance Index70
Infrastructure Impact88
History & Evolution

Black Basta is a ransomware-as-a-service operation that emerged in April 2022, believed to have connections to the disbanded Conti ransomware group. The operation has rapidly become one of the most prolific ransomware threats, targeting hundreds of organizations across healthcare, manufacturing, and critical infrastructure sectors. Black Basta employs double extortion tactics and has demonstrated sophisticated capabilities including the use of custom tools for network reconnaissance and lateral movement. The group's operations have caused significant disruption to major organizations worldwide.

Targeting

Target Sectors

HealthcareManufacturingGovernmentCritical Infrastructure

Target Regions

United StatesEuropeGlobal
Attribution & Affiliations

Attributed to Cybercriminal (No State Sponsor) (Russia). Attribution confidence: High.

Intelligence Assessment
High
Threat Level
Moderately
Targeting
Moderately
Adaptability
High
Persistence
Continuous
Op Tempo
Active
Status

Future Outlook

Black Basta is expected to continue operations targeting Healthcare sectors.

Timeline of Key Events
2022
Major

First observed activity of Black Basta

2024
Moderate

Continued active operations