Worked example · 2022-20
Black Basta Ransomware-as-a-Service — 2022–2024
Summary
Black Basta emerged in April 2022 on Russian-language criminal forums, approximately two months into the ContiLeaks dispersal event that scattered the Conti/Wizard Spider operator-cohort into multiple successor brands (Black Basta, Akira, BlackByte, Royal, Karakurt, and others). The cluster operates as a closed RaaS — affiliates are vetted rather than openly recruited, and the operator core maintains tighter control over the encryptor codebase and negotiation infrastructure than open RaaS operations (e.g., LockBit).
The cluster's TTPs: (1) initial access via QakBot (QBot) loader chain, spear-phishing, and exploitation of public-facing vulnerabilities (particularly unpatched VMware ESXi hypervisors); (2) post-exploit tooling including Cobalt Strike, Empire, and BloodHound for lateral movement; (3) double-extortion model — data exfiltration to the "Basta News" Tor leak site prior to encryption, with the threat of public disclosure as a secondary extortion lever; (4) Bitcoin ransom demands with recommended Monero conversion.
The CISA AA24-131A advisory (May 2024) characterised Black Basta as having affected over 500 organisations across 16 critical-infrastructure sectors, with healthcare as the most frequently targeted sector. Elliptic's 2024 retrospective traced approximately $107M in confirmed Bitcoin ransom payments to Black Basta-attributable wallet clusters across the first 18 months of operation.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2022-02–05 | ContiLeaks dispersal; Conti/Wizard Spider operator-cohort fragments into successor brands | (organisational event) |
| 2022-04 | Black Basta RaaS launches on Russian-language criminal forums; "Basta News" leak site goes live | (cluster emergence) |
| 2022–2024 | 500+ victim organisations across 16 critical-infrastructure sectors; ~$107M in confirmed Bitcoin payments | T5.008 |
| 2024-05 | CISA/FBI/HHS/MS-ISAC joint advisory AA24-131A — formal Black Basta cluster characterisation | (attribution milestone) |
| 2024-late | Black Basta internal wind-down; successor activity continues under related brands | (organisational event) |
Public references
- CISA/FBI/HHS/MS-ISAC: AA24-131A — StopRansomware: Black Basta, May 10, 2024 (
[cisa2024aa24131ablackbasta]). - Elliptic: Black Basta ransomware retrospective — $107M in confirmed Bitcoin payments, 2024 (
[elliptic2024blackbasta]). - Mandiant: UNC4393 tracking — Black Basta cluster characterisation.
- Microsoft: Storm-1811 / Storm-0506 sub-cluster attribution.