Black Basta Ransomware: Internal Chat Leaks Expose $100M+ RaaS Operation — Conti Successor Unmasked
Black Basta Ransomware (TL-2026-0071) is a high-severity ransomware operation, first published 2026-02-12. It is attributed to Black Basta (Russia) with high confidence, references 5 CVEs (CVE-2024-1709, CVE-2020-1472, CVE-2021-42278), maps to 51 MITRE ATT&CK techniques (T1003, T1005, T1018), and is covered by 12 detection rules and 32 indicators of compromise.
Key facts for TL-2026-0071
- Threat ID
- TL-2026-0071
- Severity
- HIGH
- Status
- SUPERSEDED
- Category
- RANSOMWARE
- First published
- 2026-02-12
- Last reviewed
- 2026-02-12
- Attribution
- Black Basta
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- Healthcare, Government, Defense, Financial Services, Technology, Critical Infrastructure, Manufacturing, Transportation, Education
- Target regions
- North America, Europe, Australia, Global
- Detection rules
- 12
- Indicators of compromise
- 32
Malware and tooling in Black Basta Ransomware
Malware and tooling: AnyDesk, Quick Assist, Splashtop, ScreenConnect — RMM tools installed via social engineering, Backstab — Custom EDR disabling tool deployed before encryption, Backstab.exe — custom EDR-disabling tool using handle duplication and process termination, Cobalt Strike beacons — C2 and lateral movement infrastructure, RClone configured with Mega cloud storage — primary data exfiltration tool, SoftPerfect Network Scanner (netscan.exe) renamed to Intel.exe, Dell.exe, or HP.exe in C:\ root directory, netscan.exe (SoftPerfect Network Scanner) — Black Basta's primary network reconnaissance tool
Black Basta ransomware operation's internal Matrix chat logs were leaked on February 11, 2025 by an individual known as 'ExploitWhispers,' exposing operational structure, key operators, TTPs, affiliate management, and ransom negotiation tactics from September 2023 to September 2024. The leak — described as closely resembling the 2022 Conti leaks — was allegedly motivated by Black Basta targeting Russian banks. PRODAFT confirmed the group had been mostly inactive since early 2025 due to internal conflicts, with some operators scamming victims by collecting ransom payments without providing functional decryptors. Key operators identified: Tramp/GG/AA (believed to be Oleg Nefedov, group leader), YY (main administrator), Lapa (operations admin), and Cortes (linked to QakBot group). Since April 2022, Black Basta affiliates breached 500+ organizations across 12 of 16 critical infrastructure sectors, collecting an estimated $100M+ in ransom payments from 90+ victims through November 2023 alone.
How Black Basta Ransomware works
Black Basta is a Ransomware-as-a-Service (RaaS) operation that emerged in April 2022, widely assessed as a successor to the Conti ransomware syndicate. On February 11, 2025, an individual using the alias 'ExploitWhispers' leaked an archive of internal Matrix chat logs spanning September 18, 2023 to September 28, 2024 — first to MEGA (removed), then to a dedicated Telegram channel. PRODAFT attributed the leak to internal conflicts and alleged that it resulted from Black Basta targeting Russian banks, drawing parallels to the 2022 Conti leak (triggered by Conti siding with Russia during the Ukraine invasion).
KEY OPERATORS IDENTIFIED FROM CHAT LOGS: - **Tramp** (aliases: GG, AA) — Believed to be Oleg Nefedov. Group leader/boss. Strategic decision-maker. - **YY** — Main administrator. Manages operations and infrastructure. - **Lapa** — Operations admin. Handles day-to-day operational coordination. - **Cortes** — Linked to the QakBot (Qbot) group. Handles initial access distribution.
OPERATIONAL INTELLIGENCE FROM LEAKED CHATS: BleepingComputer analysis of the leaked messages revealed: - Phishing templates and ready-to-send email lures - Cryptocurrency wallet addresses (payment infrastructure) - Data drops (exfiltration staging locations) - Victim credentials (harvested during operations) - 367 unique ZoomInfo links — indicating targeted companies - Confirmation of previously reported TTPs - Internal conflicts: some operators scamming victims by collecting payments WITHOUT providing functional decryptors
INTERNAL CONFLICTS AND OPERATIONAL DECLINE: PRODAFT observed Black Basta (tracked as 'Vengeful Mantis') had been mostly inactive since early 2025 due to internal conflicts. The decryptor scam — operators pocketing ransom payments without delivering working decryption tools — eroded trust within the operation and likely motivated the leak. This pattern mirrors Conti's decline: internal conflicts → leak → operational collapse.
TTPs FROM CISA ADVISORY (AA24-131A) + CHAT LEAK CONFIRMATION:
INITIAL ACCESS: - Spearphishing with malicious attachments (T1566.001) - QakBot delivery for initial foothold (via Cortes/QakBot affiliate) - DarkGate loader distribution - Exploitation of ConnectWise CVE-2024-1709 (Feb 2024+) - Valid credential abuse (T1078) - Email bombing + social engineering via Microsoft Teams (May 2024+) — mass spam emails followed by phone calls posing as IT support, directing victims to install AnyDesk or Quick Assist - Voice phishing (vishing) campaigns targeting employees
DISCOVERY AND RECONNAISSANCE: - SoftPerfect Network Scanner (netscan.exe) for network mapping - Utilities disguised with innocuous names (Intel, Dell) in C:\ root - WMI, SNMP, SSH, PowerShell for remote system enumeration
PRIVILEGE ESCALATION: - Mimikatz for credential dumping - ZeroLogon (CVE-2020-1472) exploitation - NoPac (CVE-2021-42278, CVE-2021-42287) exploitation - PrintNightmare (CVE-2021-34527) exploitation
LATERAL MOVEMENT: - BITSAdmin for file transfer - PsExec for remote execution - Remote Desktop Protocol (RDP) - Splashtop and ScreenConnect for remote access - Cobalt Strike beacons
EXFILTRATION AND ENCRYPTION: - RClone to cloud storage (Mega) for data exfiltration - PowerShell to disable antivirus - Backstab tool to disable EDR (T1562.001) - ChaCha20 encryption with RSA-4096 public key - File extension: .basta or random extension - Ransom note: readme.txt - VSS deletion via vssadmin.exe - 10-12 day payment deadline before data publication on 'Basta News' Tor site
HIGH-PROFILE VICTIMS: Rheinmetall (German defense), Hyundai Europe, BT Group (British Telecom), Ascension Healthcare (ambulance diversions), ABB (government contractor), American Dental Association, Capita (UK outsourcing), Toronto Public Library, Yellow Pages Canada.
CONTI SUCCESSION: Black Basta is widely assessed as a Conti successor operation. The parallels between the Black Basta chat leak and the 2022 Conti leak are striking: - Conti: 170,000+ chat messages leaked after siding with Russia → operational collapse - Black Basta: Internal Matrix logs leaked after targeting Russian banks → operational decline Both demonstrate that ransomware operations are vulnerable to internal dissent when political/national loyalties conflict with operational security.
FINANCIAL SCALE: - $100M+ collected from 90+ victims through November 2023 (Corvus Insurance/Elliptic research) - 500+ organizations breached globally (April 2022 - May 2024, FBI/CISA) - 12 of 16 US critical infrastructure sectors impacted - 367 ZoomInfo links = targeted company research in leaked chat period alone
MITRE ATT&CK techniques used in TL-2026-0071
credential-access
T1003 OS Credential Dumping; T1110 Brute Force; T1558 Steal or Forge Kerberos Tickets
collection
T1005 Data from Local System; T1039 Data from Network Shared Drive; T1074 Data Staged; T1560 Archive Collected Data
discovery
T1018 Remote System Discovery; T1046 Network Service Discovery; T1069 Permission Groups Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1135 Network Share Discovery; T1482 Domain Trust Discovery
lateral-movement
T1021 Remote Services; T1570 Lateral Tool Transfer
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts; T1218 System Binary Proxy Execution
execution
T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1204 User Execution; T1569 System Services
exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service
privilege-escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
command-and-control
T1071 Application Layer Protocol; T1090 Proxy; T1219 Remote Access Tools; T1573 Encrypted Channel
persistence
T1133 External Remote Services; T1136 Create Account; T1543 Create or Modify System Process
initial-access
T1190 Exploit Public-Facing Application; T1566 Phishing
impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1491 Defacement; T1529 System Shutdown/Reboot
resource-development
T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities
reconnaissance
T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information; T1594 Search Victim-Owned Websites; T1596 Search Open Technical Databases
defense-impairment
Remediation for Black Basta Ransomware
Patches
- CVE-2024-1709 — ConnectWise ScreenConnect authentication bypass
- CVE-2020-1472 — ZeroLogon (Netlogon privilege escalation)
- CVE-2021-42278 — Active Directory sAMAccountName spoofing
- CVE-2021-42287 — Active Directory Kerberos privilege escalation
- CVE-2021-34527 — PrintNightmare (Print Spooler RCE)
Immediate actions
- Review and apply all patches for CVE-2024-1709 (ConnectWise ScreenConnect), CVE-2020-1472 (ZeroLogon), CVE-2021-42278/42287 (NoPac), CVE-2021-34527 (PrintNightmare)
- Implement phishing-resistant MFA on all accounts — Black Basta affiliates exploit valid credentials and social engineer via Teams/phone
- Restrict or monitor AnyDesk, Quick Assist, Splashtop, ScreenConnect installations — these are Black Basta's preferred RMM tools for initial access
- Monitor for SoftPerfect Network Scanner (netscan.exe) and Cobalt Strike beacon activity — primary discovery and C2 tools
- Block known Black Basta cryptocurrency wallet addresses at organizational level
Workarounds
- Disable LLMNR and NetBIOS to limit credential harvesting opportunities
- Restrict external Teams communications — Black Basta operates from legitimate external Teams accounts
- Monitor for email bombing patterns (mass spam from legitimate sources) as precursor to social engineering calls
- Implement canary files on network shares to detect encryption activity (.basta extension monitoring)
Longer-term hardening
- Deploy EDR with tamper protection — Black Basta uses Backstab tool specifically to disable EDR
- Implement network segmentation to limit lateral movement via PsExec/RDP/BITSAdmin
- Train employees on Black Basta's Teams-based social engineering — attackers pose as IT support after email bombing
- Monitor RClone usage and large outbound transfers to cloud storage (especially Mega) — primary exfiltration method
- Maintain offline/immutable backups — ChaCha20+RSA-4096 encryption has no known decryptor, and leaked chats confirm some operators don't provide working decryptors even after payment
CVEs associated with Black Basta Ransomware
CVE-2024-1709, CVE-2020-1472, CVE-2021-42278, CVE-2021-42287, CVE-2021-34527
Weaknesses (CWE) in Black Basta Ransomware
CWE-288, CWE-330, CWE-20, CWE-269
Timeline of Black Basta Ransomware
- Ukrainian security researcher leaks 170,000+ Conti internal chat messages and ransomware source code after Conti sides with Russia. This triggers Conti's operational collapse and sets the precedent for the Black Basta leak. Source: BleepingComputer
- Black Basta RaaS operation emerges, widely assessed as a Conti successor. First victims breached within weeks of launch — indicating experienced operators from Conti transitioning. Source: CISA/FBI AA24-131A
- Start date of leaked Black Basta internal Matrix chat logs. Messages from this period reveal operational structure, phishing templates, cryptocurrency addresses, victim credentials, and 367 targeted companies via ZoomInfo links. Source: BleepingComputer/ExploitWhispers
- Corvus Insurance and Elliptic joint research reveals Black Basta collected an estimated $100M+ in ransom payments from 90+ victims. Source: Corvus/Elliptic via BleepingComputer
- Black Basta affiliates begin exploiting ConnectWise ScreenConnect CVE-2024-1709 authentication bypass for initial access. Adds RMM exploitation to existing spearphishing and QakBot delivery vectors. Source: CISA Advisory AA24-131A
- Black Basta launches social engineering campaign using email bombing — mass spam emails followed by phone calls posing as IT support, directing victims to install AnyDesk or Quick Assist for remote access. Source: CISA Advisory update Nov 2024
- FBI, CISA, HHS, and MS-ISAC publish joint advisory AA24-131A — Black Basta affiliates breached 500+ organizations globally, impacting 12 of 16 critical infrastructure sectors. Healthcare sector specifically warned. Source: CISA
- End date of leaked Matrix chat logs. Covers one full year of Black Basta internal operations. Source: BleepingComputer/ExploitWhispers
- Black Basta incorporates Microsoft Teams for social engineering — operators message victims from legitimate external Teams accounts posing as IT support to resolve email spam issues. Source: CISA Advisory update Nov 2024
- PRODAFT observes Black Basta (Vengeful Mantis) mostly inactive since start of 2025 due to internal conflicts. Some operators scamming victims by collecting ransom without providing functional decryptors. Source: PRODAFT
- ExploitWhispers leaks Black Basta internal Matrix chat logs — first to MEGA (removed), then Telegram. Leak allegedly motivated by group targeting Russian banks. PRODAFT confirms authenticity and says it closely resembles the 2022 Conti leak. Key operators identified: Tramp/Oleg Nefedov (boss), YY (admin), Lapa (ops admin), Cortes (QakBot link). Source: BleepingComputer/PRODAFT
- As of 2026-05-29, Black Basta as an organized RaaS group is defunct — silent and leak-site removed since Feb 2025, with leader Oleg Nefedov on EU Most Wanted/INTERPOL Red Notice and two operators arrested (Jan 2026). However its capability is superseded by successors: former affiliates migrated to CACTUS and run active 2026 Teams-phishing/executive-targeting campaigns (surging March 2026), so the threat persists beyond mere dormancy.
Sources cited for Black Basta Ransomware
- BleepingComputer: Black Basta internal chat logs leak online
- CISA/FBI: #StopRansomware — Black Basta Advisory AA24-131A
- PRODAFT: Black Basta (Vengeful Mantis) internal conflict analysis
- SentinelOne: Black Basta custom EDR evasion tools linked to FIN7
- Unit 42: Black Basta Threat Assessment
- Corvus/Elliptic: Black Basta $100M+ ransom revenue analysis
- Kroll: Black Basta Technical Analysis
Threats related to Black Basta Ransomware
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)
- DeadLock Ransomware: Smart Contracts for Malicious Purposes — Blockchain-Automated Ransom Operations
- Storm-1175 Medusa Ransomware Zero-Day Exploitation Campaign (CVE-2026-23760, CVE-2025-10035)
- INC Ransom Affiliate Network Targeting Pacific Critical Infrastructure (AU/NZ/Tonga Joint Advisory)
- DragonForce: White-Label Ransomware Cartel — Scattered Spider Partnership & MSP Supply Chain Attacks
- FortiBleed Credential Theft Campaign: FortigateSniffer Tool Deployed Against 430,000+ FortiGate Firewalls, Linked to INC Ransom and Lynx Ransomware
Detection coverage for TL-2026-0071
As of 2026-02-12, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0071 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.