ThreatBox · Threat Actor Attribution
Black Basta
a.k.a. UNC4393, BlackBasta
Financial (RaaS) Russia (former Conti members attributed) First seen 2022-04
Black Basta emerged in April 2022 shortly after Conti's shutdown, and shares significant TTP, tooling and infrastructure overlap with Conti. Notorious for using Qakbot → Cobalt Strike → BlackBasta chain and, more recently, Microsoft Teams impersonation of IT staff. Leaked internal chats (Feb 2025) exposed ~$107M in ransom revenue and internal disputes.
Targeted sectors
HealthcareManufacturingConstructionLegal services
Targeted regions
North AmericaEurope
Known TTPs (4)
T1566.001Spearphishing Attachment (Qakbot)
T1105Ingress Tool Transfer (Cobalt Strike)
T1486Data Encrypted for Impact
T1567.002Exfiltration to Cloud Storage (rclone)
Click any technique to open the MITRE ATT&CK reference.
Attack Timeline
- 2022-04First observed on RAMP forum recruiting affiliates
- 2024-05CISA/FBI/HHS joint advisory (Ascension Health & Synlab hits)
- 2025-02Internal chat logs leaked to Telegram — 'Bloody Wolf' insider dump
References
End of dossier · Black Basta
Back to ThreatBox