OAK — OnChain Attack Knowledge

Software · OAK-S27 · ransomware

OAK-S27 — Black Basta ransomware

Type
ransomware
Aliases
Black Basta (the operator-side and leak-site-branded name from the brand's April 2022 debut); industry-side cross-attribution labels include UNC4393 (Mandiant intrusion-set naming for the operator cluster), Storm-1811 (Microsoft Threat Intelligence naming, partially overlapping the broader Conti-successor-cohort surface), and the informal "Conti Team 3" / "Conti Black" naming used in early 2022 industry reporting that documented the operator-cohort continuity from Conti at the personnel level. The brand is operationally the most-prominent direct-successor brand in the Conti-cohort dispersal network (see OAK-S26 Discussion for the broader Conti-successor framing). The internal-chat-leak event of February 2024 (the "BlackBastaGPT" / [blackbastaleaks2024] corpus) provides a primary-source record of the operator cohort's internal organisation comparable in evidentiary weight to the ContiLeaks corpus for Conti.
Active
degraded — brand-attributable extortion volume declined materially through H2 2024 and into early 2025 following the February 2024 internal-chat-leak event and subsequent affiliate migration; some affiliate-cohort members rotated onto Cactus and BlackSuit affiliate panels per Mandiant and Microsoft post-leak tracking. Brand had not been formally sunset as of v0.1 but operational-continuity is structurally damaged in the same idiom as OAK-S23 LockBit post-Cronos.
First observed
2022-04 (Black Basta leak-site debut April 2022; brand emergence is read as immediately pre-Conti-dissolution, with operator personnel migration from the Conti cohort into the new brand identity documented at the internal-chat-recovered level via the February 2024 leak corpus).
Used by Groups
OAK-G11 Black Basta (primary operator cluster — drafted in parallel with this Software entry; OAK-G11 documents the Russian-speaking Conti-successor operator cohort behind the brand, with operator continuity to the Conti / Wizard Spider cohort confirmed at the internal-chat-recovered level). Affiliate-side cross-use spans the broader Conti-successor affiliate diaspora; some Black Basta-affiliated intrusions show overlap with the Scattered-Spider / UNC3944 affiliate surface visible in OAK-S24 BlackCat / ALPHV reporting, though the operator-level brands are distinct.
Host platforms
Windows (primary, all enterprise-server variants); Linux / VMware ESXi (a dedicated ESXi-hypervisor variant emerged June 2022, mirroring the broader RaaS-sector pivot to hypervisor-targeted attacks established by LockBit and ALPHV). The Windows codebase is C++-authored with structural-and-stylistic similarities to Conti v3 documented by Trend Micro, Sophos, and Mandiant; the lineage is read as Conti-codebase-derivative-with-rewrites rather than a clean fork.
Observed Techniques
OAK-T7.001 (mixer-routed-hop, the dominant Black Basta-affiliate ransom-laundering route 2022–2023 with Sinbad pre-takedown the principal venue per Chainalysis tracking; post-Sinbad-takedown rotation onto smaller mixer infrastructure observed); OAK-T7.002 (CEX deposit-address layering, the post-2023 default with Garantex (OAK-G03) named in industry-forensic reporting as a recurring Black Basta-affiliate off-ramp); OAK-T8.001 (common-funder cluster reuse, the load-bearing Technique for Conti-to-Black-Basta operator-cohort-continuity tracking — Black Basta affiliate wallet clusters share funder addresses with documented Conti-era affiliate clusters per Chainalysis and Mandiant cross-cohort analysis).

Description

Black Basta is the ransomware encryptor codebase and brand maintained by a Russian-speaking Conti-successor operator cohort from April 2022 onward, emerging as the principal direct-successor brand in the Conti-cohort dispersal network described in OAK-S26. From a defender perspective the family occupies the same encryption-and-extortion functional role that Conti occupied 2020–2022 — large-enterprise targeting, double-extortion architecture (encryption plus data-theft-and-publication), VMware-ESXi-targeted hypervisor variant, leak-site-and-negotiation-portal infrastructure — with Conti-era operator continuity at the personnel level documented at the internal-chat-recovered level via the February 2024 BlackBastaGPT leak corpus ([blackbastaleaks2024]), which is the canonical primary-source evidence for Conti-cohort-continuity-as-Black-Basta-cohort.

The encryptor's distinguishing technical features include selective-block-encryption (a configurable speed-versus-stealth tradeoff that produces faster encryption at the cost of weaker file-recovery resistance), aggressive shadow-copy deletion via vssadmin / wmic sequences, ransom-note delivery via per-folder dropped readme.txt files, and a dedicated VMware ESXi variant for hypervisor-level deployments against virtualised enterprise infrastructure. The C++ Windows codebase's structural similarities to Conti v3 are documented by Trend Micro and Sophos in 2022 reporting; the lineage is codebase-derivative rather than a literal fork (Black Basta's developers performed substantive rewrites of the Conti v3 codebase rather than ship the leaked source as-is, and the Linux / ESXi variant is read as a fresh implementation rather than a Conti-Linux derivative). The affiliate-program structure is a textbook Conti-successor RaaS split, with affiliate-onboarding through Russian-language criminal forums and an operator-side cohort whose internal organisational structure (developers, system administrators, OSINT analysts, victim-negotiation operators) closely mirrors the Conti structure recovered in the ContiLeaks corpus per the BlackBastaGPT leak.

The family's role in the Russian-speaking-cybercrime-ecosystem monetization chain is the encryption-and-extortion node feeding Russian-speaking-cluster laundering venues — Garantex (OAK-G03) is repeatedly named in industry-forensic reporting as a Black Basta-affiliate off-ramp, mirroring the documented Conti-to-Garantex chain ([ofac2022garantex]); the broader Russian-speaking-mixer ecosystem (Sinbad pre-takedown) was the dominant 2022–2023 routing surface. The May 2024 Ascension Health incident — a major U.S. Catholic healthcare system attack that disrupted hospital operations across multiple states and produced extensive secondary patient-safety impact — is the brand's highest-profile single deployment and the principal trigger for the joint CISA / FBI / HHS / MS-ISAC advisory AA24-131A ([cisaaa24131a]) that anchors the U.S.-government confirmed-grade institutional attribution to the cluster.

Observed examples

  • Ascension Health (May 8, 2024, multi-state hospital-operations disruption). Black Basta deployment against Ascension, one of the largest non-profit Catholic healthcare systems in the United States operating approximately 140 hospitals across 19 states; the attack disrupted electronic-health-record systems, triggered diversion of ambulances from multiple Ascension hospitals, and produced extensive secondary patient-safety impact across emergency departments and operating theatres for weeks. The incident triggered the CISA / FBI / HHS / MS-ISAC joint advisory AA24-131A ([cisaaa24131a]) on May 10, 2024 — a rapid-response advisory issued within 48 hours of the deployment, structurally distinct from the post-hoc-pattern advisory pattern at OAK-S23 / S24. Confirmed-grade attribution per CISA AA24-131A and post-incident industry reporting.
  • CISA AA24-131A campaign cohort (through 2024). The advisory documents over 500 named-and-unnamed Black Basta victim organisations across U.S. critical-infrastructure sectors (healthcare and public-health prominently called out, but also manufacturing, financial services, government, and education); confirmed-grade aggregate.
  • BlackBastaGPT internal-chat leak corpus (February 2024). A pro-Ukraine cluster member published approximately 200,000 internal chat-log messages from the Black Basta operator cohort's Matrix-protocol communications, in a structurally-parallel event to the ContiLeaks disclosure of February 2022. The corpus was subsequently indexed and made public-search-accessible via the BlackBastaGPT project ([blackbastaleaks2024]); it is the primary-source evidence for Conti-cohort-continuity-as-Black-Basta-cohort and the principal record of the operator's internal organisational structure, affiliate-roster, victim-negotiation tradecraft, and operator-internal political dynamics. Mandiant and Microsoft post-leak analysis treat the corpus as evidentiary-weight comparable to ContiLeaks for the Conti cohort.
  • OAK on-chain example surface. No OAK examples/ entry exists for Black Basta-binary specifically as of v0.1; the Black-Basta-to-Garantex chain documented in industry-forensic reporting is the strongest candidate for a future OAK example entry showing the OAK-S27-binary × OAK-G03-Garantex × T7.002 worked example, structurally parallel to the Conti-to-Garantex chain anchored in [ofac2022garantex].

Detection / attribution signals

Defenders should treat Black Basta detection as a host-layer + on-chain-layer joint problem with the Conti-cohort-continuity tracking as the principal cross-cluster forensic signature:

  • Host-layer process-tree fingerprints — characteristic file-extension changes (.basta extension on encrypted files); ransom-note filenames (readme.txt per-folder); C++-Windows-binary signature with structural-and-stylistic similarities to Conti v3 documented by Trend Micro and Sophos; selective-block-encryption mode signature; aggressive vssadmin / wmic shadow-copy-deletion sequences; ESXi-variant invokes esxcli vm process list and esxcli vm process kill for VM-shutdown-before-encryption (the canonical ESXi-variant fingerprint shared across Conti-successor brands).
  • Pre-encryption tradecraft — Qakbot / QBot phishing-loader chains were the dominant initial-access vector through 2023 (the Qakbot-to-Black-Basta intrusion chain is widely documented and was a principal target of the August 2023 Qakbot takedown); post-Qakbot rotation onto DarkGate, Pikabot, and SystemBC loader chains documented through 2024; Cobalt Strike post-exploitation deployment; lateral movement via PsExec and WMI; credential theft via Mimikatz and the standard Conti-cohort tooling.
  • On-chain-layer signatures (the OAK-relevant signal) — Black Basta affiliate-controlled ransom-payment wallets exhibit the common-funder cluster reuse (OAK-T8.001) pattern that anchors Conti-to-Black-Basta operator-cohort-continuity tracking; downstream routing through Garantex (OAK-G03) is documented as a recurring affiliate off-ramp; Sinbad pre-takedown was the dominant mixer venue 2022–2023.
  • CTI vendor coverage — Mandiant (UNC4393 naming and continuous tracking through the Conti-successor-brand-network), Microsoft Threat Intelligence (Storm-1811 naming and the broader Conti-successor-cohort surface), Trend Micro (continuous version-and-codebase-comparison analysis), Sophos (sustained "State of Ransomware" reporting and the canonical Conti-codebase-comparison work), Recorded Future (Insikt Group sustained Black-Basta-and-Conti-successor-brand reporting), Chainalysis and TRM Labs (on-chain operator-cohort-continuity tracking).
  • Primary-source corpus (BlackBastaGPT leak) — the February 2024 internal-chat leak corpus ([blackbastaleaks2024]) is the canonical primary-source reference for the operator cohort's internal organisational structure; defenders writing operator-cohort tracking should treat the corpus and Mandiant / Microsoft secondary analysis as the principal evidence base for Conti-to-Black-Basta cohort-continuity attribution.

Note: omit specific file hashes from this entry. Defenders should consume current IOCs from CISA AA24-131A and live CTI-vendor feeds named above.

Citations

  • [cisaaa24131a] — CISA / FBI / HHS / MS-ISAC joint advisory AA24-131A on Black Basta ransomware following the Ascension Health incident, May 10, 2024. (NEW citation — see summary.)
  • [blackbastaleaks2024] — BlackBastaGPT internal-chat-leak corpus, February 2024; structurally parallel to ContiLeaks. (NEW citation — see summary.)
  • [mandiantunc4393] — Mandiant UNC4393 / Black Basta intrusion-set documentation and Conti-successor-brand-network tracking. (NEW citation — see summary.)
  • [microsoftstorm1811] — Microsoft Threat Intelligence Storm-1811 / Black Basta analysis. (NEW citation — see summary.)
  • [trendmicroblackbasta2022] — Trend Micro Black Basta technical analysis and Conti-codebase comparison. (NEW citation — see summary.)
  • [sophosblackbasta2022] — Sophos Black Basta tradecraft and Conti-codebase comparison. (NEW citation — see summary.)
  • [chainalysisblackbasta2024] — Chainalysis Black Basta-attributable ransom-payment-volume tracking and Conti-cohort-continuity wallet-cluster analysis. (NEW citation — see summary.)
  • [ofac2022garantex] — Treasury OFAC Garantex designation press release; Conti-successor-brand laundering-venue context.
  • [chainalysis2025ransomware] — Chainalysis 2024-recap ransomware report; cross-family context for the Black Basta volume distribution.

Discussion

On lineage as the central framing. OAK-S27's principal value as a Software entry is as the lead direct-successor brand in the Conti-cohort dispersal network (see OAK-S26 Discussion). The brand emerged April 2022 — immediately pre-Conti-dissolution — and absorbed the largest single share of Conti-cohort operator personnel into a new brand identity, with the BlackBastaGPT internal-chat leak corpus of February 2024 providing the primary-source evidence base for that continuity reading. From a defender perspective Black Basta is the principal active-detection target representing the Conti-cohort tradecraft surface in the post-Conti era; the family is to OAK-S26 Conti what BlackSuit is to Royal (rebranded continuation under different identity rather than dispersal-into-new-brand).

On predecessors. Black Basta's direct predecessor at the operator-cohort level is the Conti / Wizard Spider cohort (2020–2022, OAK-S26), which itself succeeded the Ryuk operator-cohort (2018–2020); operator continuity from Conti is documented at the internal-chat-recovered level via BlackBastaGPT and at the wallet-cluster level via the OAK-T8.001 common-funder cluster reuse pattern.

On the BlackBastaGPT leak as a structural parallel to ContiLeaks. The February 2024 leak event is one of two known cases on the public record of a major RaaS operator cohort being subjected to a substantial internal-chat-disclosure event by an internal dissenter (the other being ContiLeaks of February 2022). Both events triggered measurable affiliate-migration and operator-cohort restructuring; both produced primary-source corpora that fundamentally reshaped industry-and-academic understanding of how a major RaaS cohort actually operates internally. The structural parallelism is itself diagnostic of the Conti-to-Black-Basta cohort continuity — the same operator-internal political dynamics that produced ContiLeaks reproduced themselves in the Conti-successor brand within two years.

On the OAK Software-vs-Group split. OAK-S27 (this entry) is the Black Basta encryptor codebase and brand; OAK-G11 (drafted in parallel) is the Black Basta operator cluster — the Russian-speaking Conti-successor operator cohort. The split mirrors the OAK-S23 / OAK-G05 LockBit pattern; the principal asymmetry is that the Black Basta operator cluster's lineage to Conti is documented at the internal-chat-recovered level (an evidentiary surface with no direct equivalent in the LockBit attribution architecture), while the LockBit operator cluster's senior leadership is attributed via named-defendant indictment (an evidentiary surface with no direct equivalent in the Black Basta attribution architecture). Both attribution architectures are confirmed-grade institutionally; the underlying evidence is structurally different.

Techniques observed (3)

Used by