# BlackBasta

> As of 2026-06-30, BlackBasta is a threat actor tracked by Threadlinqs Intelligence across 4 threats spanning malware, ransomware, vulnerability. ATT&CK coverage spans 75 techniques across 15 tactics in 4 of 4 tracked threats. Most-observed techniques: T1059 (Command and Scripting Interpreter), T1071 (Application Layer Protocol), T1003 (OS Credential Dumping).

- **Tracked threats:** 4
- **Categories:** MALWARE, RANSOMWARE, VULNERABILITY
- **As of:** 2026-06-30

## ATT&CK techniques observed

75 techniques observed across 4 of 4 tracked threats. Tactics: Stealth (formerly Defense Evasion) (10), Command and Control (9), Discovery (9), Impact (7), Execution (6), Collection (5).

- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 4 of 4 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 4 of 4 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 3 of 4 tracked threats
- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 3 of 4 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 3 of 4 tracked threats
- [T1068](https://intel.threadlinqs.com/technique/T1068) Exploitation for Privilege Escalation — Privilege Escalation — observed in 3 of 4 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 3 of 4 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 3 of 4 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 3 of 4 tracked threats
- [T1490](https://intel.threadlinqs.com/technique/T1490) Inhibit System Recovery — Impact — observed in 3 of 4 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 2 of 4 tracked threats
- [T1048](https://intel.threadlinqs.com/technique/T1048) Exfiltration Over Alternative Protocol — Exfiltration — observed in 2 of 4 tracked threats
- [T1070](https://intel.threadlinqs.com/technique/T1070) Indicator Removal — Stealth (formerly Defense Evasion) — observed in 2 of 4 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 4 tracked threats
- [T1090](https://intel.threadlinqs.com/technique/T1090) Proxy — Command and Control — observed in 2 of 4 tracked threats

## Tracked threats

- [SystemBC (Coroxy) Malware: Tor-Based SOCKS5 Proxy Backdoor Enabling Ransomware Persistence and C2 Obfuscation](https://intel.threadlinqs.com/threat/TL-2026-1005) — CRITICAL
- [Capita Black Basta Ransomware Incident (March 2023) — Record £14M UK ICO Fine for 6M+ Affected Individuals](https://intel.threadlinqs.com/threat/TL-2026-0767) — HIGH
- [Veeam Backup & Replication 8 Critical Vulnerabilities — Domain User to Backup Server RCE (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708)](https://intel.threadlinqs.com/threat/TL-2026-0232) — CRITICAL
- [Black Basta Ransomware: Internal Chat Leaks Expose $100M+ RaaS Operation — Conti Successor Unmasked](https://intel.threadlinqs.com/threat/TL-2026-0071) — HIGH

## Related CVEs

13 CVEs referenced by tracked BlackBasta activity.

- [CVE-2026-21708](https://intel.threadlinqs.com/cve/CVE-2026-21708)
- [CVE-2026-21672](https://intel.threadlinqs.com/cve/CVE-2026-21672)
- [CVE-2026-21671](https://intel.threadlinqs.com/cve/CVE-2026-21671)
- [CVE-2026-21670](https://intel.threadlinqs.com/cve/CVE-2026-21670)
- [CVE-2026-21669](https://intel.threadlinqs.com/cve/CVE-2026-21669)
- [CVE-2026-21668](https://intel.threadlinqs.com/cve/CVE-2026-21668)
- [CVE-2026-21667](https://intel.threadlinqs.com/cve/CVE-2026-21667)
- [CVE-2026-21666](https://intel.threadlinqs.com/cve/CVE-2026-21666)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-34527](https://intel.threadlinqs.com/cve/CVE-2021-34527)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/BlackBasta
