Back to ThreatBox
ThreatBox · Threat Actor Attribution

Black Basta

a.k.a. UNC4393, BlackBasta
Financial (RaaS) Russia (former Conti members attributed) First seen 2022-04

Black Basta emerged in April 2022 shortly after Conti's shutdown, and shares significant TTP, tooling and infrastructure overlap with Conti. Notorious for using Qakbot → Cobalt Strike → BlackBasta chain and, more recently, Microsoft Teams impersonation of IT staff. Leaked internal chats (Feb 2025) exposed ~$107M in ransom revenue and internal disputes.

Targeted sectors
HealthcareManufacturingConstructionLegal services
Targeted regions
North AmericaEurope

Known TTPs (4)

Click any technique to open the MITRE ATT&CK reference.

Attack Timeline

  1. 2022-04
    First observed on RAMP forum recruiting affiliates
  2. 2024-05
    CISA/FBI/HHS joint advisory (Ascension Health & Synlab hits)
  3. 2025-02
    Internal chat logs leaked to Telegram — 'Bloody Wolf' insider dump

References

End of dossier · Black Basta
Back to ThreatBox

Made with Emergent