Black Basta Ransomware: Internal Chat Leaks Expose $100M+ RaaS Operation — Conti Successor Unmasked — Threadlinqs Intelligence
As of 2026-05-30, Black Basta Ransomware: Internal Chat Leaks Expose $100M+ RaaS Operation — Conti Successor Unmasked is a high-severity ransomware threat attributed to Black Basta (Russia), tracked by Threadlinqs Intelligence with 12 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-0071 · Severity: HIGH · Status: SUPERSEDED · Category: RANSOMWARE
Attribution: Black Basta · Russia · FINANCIAL
Black Basta ransomware operation's internal Matrix chat logs were leaked on February 11, 2025 by an individual known as 'ExploitWhispers,' exposing operational structure, key operators, TTPs,
Black Basta is a Ransomware-as-a-Service (RaaS) operation that emerged in April 2022, widely assessed as a successor to the Conti ransomware syndicate. On February 11, 2025, an individual using the alias 'ExploitWhispers' leaked an archive of internal Matrix chat logs spanning September 18, 2023 to September 28, 2024 — first to MEGA (removed), then to a dedicated Telegram channel. PRODAFT attributed the leak to internal conflicts and alleged that it resulted from Black Basta targeting Russian banks, drawing parallels to the 2022 Conti leak (triggered by Conti siding with Russia during the Ukraine invasion).
KEY OPERATORS IDENTIFIED FROM CHAT LOGS:
- **Tramp** (aliases: GG, AA) — Believed to be Oleg Nefedov. Group leader/boss. Strategic decision-maker.
- **YY** — Main administrator. Manages operations and infrastructure.
- **Lapa** — Operations admin. Handles day-to-day operational coordination.
- **Cortes** — Linked to the QakBot (Qbot) group. Handles initial access distribution.
OPERATIONAL INTELLIGENCE FROM LEAKED CHATS:
BleepingComputer analysis of the leaked messages revealed:
- Phishing templates and ready-to-send email lures
- Cryptocurrency wallet addresses (payment infrastructure)
- Data drops (exfiltration staging locations)
- Victim credentials (harvested during operations)
- 367 unique ZoomInfo links — indicating targeted companies
- Confirmation of previously reported TTPs
- Internal conflicts: some operators scamming victims by collecting payments WITHOUT providing functional decryptors
INTERNAL CONFLICTS AND OPERATIONAL DECLINE:
PRODAFT observed Black Basta (tracked as 'Vengeful Mantis') had been mostly inactive since early 2025 due to internal conflicts. The decryptor scam — operators pocketing ransom payments without delivering working decryption tools — eroded trust within the operation and likely motivated the leak. This pattern mirrors Conti's decline: internal conflicts → leak → operational collapse.
TTPs FROM CISA ADVISORY (AA24-131A) + CHAT LEAK CONFIRMATION:
INITIAL ACCESS:
- Spearphishing with malicious attachments (T1566.001)
- QakBot delivery for initial foothold (via Cortes/QakBot affiliate)
- DarkGate loader distribution
- Exploitation of ConnectWise CVE-2024-1709 (Feb 2024+)
- Valid credential abuse (T1078)
- Email bombing + social engineering via Microsoft Teams (May 2024+) — mass spam emails followed by phone calls posing as IT support, directing victims to install AnyDesk or Quick Assist
- Voice phishing (vishing) campaigns targeting employees
DISCOVERY AND RECONNAISSANCE:
- SoftPerfect Network Scanner (netscan.exe) for network mapping
- Utilities disguised with innocuous names (Intel, Dell) in C:\ root
- WMI, SNMP, SSH, PowerShell for remote system enumeration
PRIVILEGE ESCALATION:
- Mimikatz for credential dumping
- ZeroLogon (CVE-2020-1472) exploitation
- NoPac (CVE-2021-42278, CVE-2021-42287) exploitation
- PrintNightmare (CVE-2021-34527) exploitation
LATERAL MOVEMENT:
- BITSAdmin for file transfer
- PsExec for remote execution
- Remote Desktop Protocol (RDP)
- Splashtop and ScreenConnect for remote access
- Cobalt Strike beacons
EXFILTRATION AND ENCRYPTION:
- RClone to cloud storage (Mega) for data exfiltration
- PowerShell to disable antivirus
- Backstab tool to disable EDR (T1562.001)
- ChaCha20 encryption with RSA-4096 public key
- File extension: .basta or random extension
- Ransom note: readme.txt
- VSS deletion via vssadmin.exe
- 10-12 day payment deadline before data publication on 'Basta News' Tor site
HIGH-PROFILE VICTIMS:
Rheinmetall (German defense), Hyundai Europe, BT Group (British Telecom), Ascension Healthcare (ambulance diversions), ABB (government contractor), American Dental Association, Capita (UK outsourcing), Toronto Public Library, Yellow Pages Canada.
CONTI SUCCESSION:
Black Basta is widely assessed as a Conti successor operation. The parallels between the Black Basta chat leak and the 2022 Conti leak are striking:
- Conti: 170,000+ chat messages leaked aft
Weaknesses (CWE)
CWE-288, CWE-330, CWE-20, CWE-269
Target sectors: Healthcare, Government, Defense, Financial Services, Technology, Critical Infrastructure, Manufacturing, Transportation, Education
Target regions: North America, Europe, Australia, Global
Detections & IOCs
As of 2026-07-26, this threat has 12 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, CVE-2024-1709, CVE-2020-1472, CVE-2021-42278, CVE-2021-42287, CVE-2021-34527, T1591, T1588, T1566, T1566, T1190, T1078, T1059, T1204, T1569, T1133