# Black Basta

> As of 2026-08-24, Black Basta is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 5 threats spanning malware, ransomware. Also known as BlackBasta, Storm-1811, UNC4393, Penta. ATT&CK coverage spans 104 techniques across 15 tactics in 5 of 5 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1486 (Data Encrypted for Impact), T1685 (Disable or Modify Tools).

- **Nation:** Russia
- **Tracked threats:** 5
- **Categories:** MALWARE, RANSOMWARE
- **Also known as:** BlackBasta, Storm-1811, UNC4393, Penta, Vengeful Mantis
- **As of:** 2026-08-24

## ATT&CK techniques observed

104 techniques observed across 5 of 5 tracked threats. Tactics: Command and Control (14), Resource Development (12), Discovery (10), Stealth (formerly Defense Evasion) (10), Credential Access (8), Impact (8).

- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 4 of 5 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 4 of 5 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 4 of 5 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 3 of 5 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 5 tracked threats
- [T1048](https://intel.threadlinqs.com/technique/T1048) Exfiltration Over Alternative Protocol — Exfiltration — observed in 3 of 5 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 3 of 5 tracked threats
- [T1070](https://intel.threadlinqs.com/technique/T1070) Indicator Removal — Stealth (formerly Defense Evasion) — observed in 3 of 5 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 3 of 5 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 3 of 5 tracked threats
- [T1090](https://intel.threadlinqs.com/technique/T1090) Proxy — Command and Control — observed in 3 of 5 tracked threats
- [T1133](https://intel.threadlinqs.com/technique/T1133) External Remote Services — Persistence — observed in 3 of 5 tracked threats
- [T1204](https://intel.threadlinqs.com/technique/T1204) User Execution — Execution — observed in 3 of 5 tracked threats
- [T1219](https://intel.threadlinqs.com/technique/T1219) Remote Access Tools — Command and Control — observed in 3 of 5 tracked threats
- [T1482](https://intel.threadlinqs.com/technique/T1482) Domain Trust Discovery — Discovery — observed in 3 of 5 tracked threats

## Tracked threats

- [CrossC2 Cross-Platform Cobalt Strike Loader Deployed with ReadNimeLoader in Attacks Linked to BlackBasta Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2135) — HIGH
- [Black Basta Ransomware Operation - Organizational Breakdown & 2025 Shutdown](https://intel.threadlinqs.com/threat/TL-2026-1015) — CRITICAL
- [Capita Black Basta Ransomware Incident (March 2023) — Record £14M UK ICO Fine for 6M+ Affected Individuals](https://intel.threadlinqs.com/threat/TL-2026-0767) — HIGH
- [Ransomware C2 Infrastructure Abuse — Bulletproof Hosting Procurement, VPS Exploitation, Hosting Panel Compromise, Cobalt Strike on Legitimate Infrastructure, Multi-Jurisdictional Takedown Complexity](https://intel.threadlinqs.com/threat/TL-2026-0099) — HIGH
- [Black Basta Ransomware: Internal Chat Leaks Expose $100M+ RaaS Operation — Conti Successor Unmasked](https://intel.threadlinqs.com/threat/TL-2026-0071) — HIGH

## Related CVEs

5 CVEs referenced by tracked Black Basta activity.

- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-34527](https://intel.threadlinqs.com/cve/CVE-2021-34527)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Black%20Basta
