Uptime Hamster: 10d 4h 26mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza blackbasta

blackbasta

2 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-29
Aliases: DEV-0569, Conti, Quantum, Black Byte, Diavol, Black Basta, Ryuk (como FIN12)
Ver en IntelTracker → APTTrail →
Black Basta is a financially motivated ransomware-as-a-service (RaaS) group that emerged in April 2022, rapidly distinguishing itself through its aggressive double-extortion tactics, combining data encryption with data theft and public shaming on its 'Basta News' leak site. Assessed with high confidence to be of Russian origin, the group quickly accumulated a significant number of victims globally, leading to speculation that it may be a rebrand or an offshoot of the Russian-speaking Conti ransomware group, or closely linked to other Russian-speaking cybercriminal organizations like FIN7, due to similar tactics, techniques, and procedures. Black Basta operates as a closed RaaS, not openly recruiting on underground forums, which contributes to its perceived exclusivity and sophistication. The group's leader, known as GG or AA, is reportedly a Russian individual, and the group maintained offices in Moscow, further cementing its suspected origin.

Aliases del actor

DEV-0569ContiQuantumBlack ByteDiavolBlack BastaRyuk (como FIN12)

Actores similares

blackbyteransomware · 147blackbyte-cruxactor · 1blacksuitransomware · 184blacknevasransomware · 16blackwaterransomware · 11black-xactor · 8blackshrantacransomware · 8blackoutransomware · 5blackfieldactor · 3blacklockransomware · 3

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Repositorioupgithub.comBlackBasta
DLS / leak siteupraw.githubusercontent.comBlackBasta
DLS / leak siteupwww.microsoft.comBlackBasta
DLS / leak siteunknownwww.cisa.govBushidoUK ToolMatrix GroupProfiles: BlackBasta
Repositoriounknowngithub.comBushidoUK ToolMatrix GroupProfiles: BlackBasta
Repositoriounknowngithub.comBushidoUK ToolMatrix GroupProfiles: BlackBasta
DLS / leak siteunknownwww.trendmicro.comBushidoUK ToolMatrix GroupProfiles: BlackBasta
Repositoriounknowngithub.comRansom Notes: blackbasta (5 notes from ThreatLabz)
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: blackbasta
Tecnicas MITRE
T1087.002, T1021.004, T1656, T1074.001, T1583, T1059.001
CVEs relacionadas
CVE-2025-23121, CVE-2025-23120, CVE-2024-37085, CVE-2024-26169, CVE-2024-1709, CVE-2024-1708
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

United Arab EmiratesAustriaAustraliaBangladeshBelgiumBrazilCanadaSwitzerlandCosta RicaCzech Republic

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsTransportation Equipment ManufacturingEnterprises & HoldingAccommodationAir Transportation

URLs nuevas detectadas en IntelTracker

github.com raw.githubusercontent.com github.com ransomware.anggipradana.com

Victimas (1)

Ransom Notes: blackbasta (5 notes from ThreatLabz)18 Jun 2026
Report
blackbasta - Ransom NotesEste grupo de ransomware tiene 5 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de re…