Overview
Platforms:
Windows · ESXi
Variants:
—
Extensions:
—
ATT&CK software:
—
Initial access:
—
Top countries:
US · GB · DE · CA · IT
Observed sectors:
Manufacturing · Professional Services · Technology · Agriculture and Food Production · Transportation
Tracked victims:
526
Attribution
Storm-1811
VERIFIED
Vendor-tracked threat actor
MITRE ATT&CK identifies Storm-1811 as a financially motivated entity associated with deployment of Black Basta ransomware.
Relationships
Conti
PROBABLE
Reported operator lineage
Multiple security researchers assess that Black Basta operators may include current or former members of the Conti ransomware ecosystem.
Affiliates
No affiliate information available.
Activity
Initial Access
Email bombing and fake helpdesk interaction
Storm-1811 has flooded victim inboxes with non-malicious spam and then impersonated IT support to establish contact and gain access.
Social engineering through Microsoft Teams
Storm-1811 has used Microsoft Teams accounts spoofing IT support or helpdesk identities during Black Basta-related intrusion activity.
Recent Observations
Last sustained victim publication
January 2025
Leak-site activity
Black Basta's leak-site dataset shows its most recent sustained victim publication in January 2025.
Joint Black Basta advisory
May 2024
Government advisory
FBI, CISA, HHS and MS-ISAC published a joint advisory documenting Black Basta tactics, techniques and indicators.
Black Basta emerges
April 2022
Operational activity
Black Basta began operating as a ransomware-as-a-service operation targeting Windows and VMware ESXi environments.
TTPs
ATT&CK coverage:
9 techniques
· 7 tactics
T1667
Email Bombing
VERIFIEDInitial Access
Storm-1811 has flooded victim inboxes with large volumes of non-malicious spam to trigger follow-up social engineering.
T1585.003
Establish Accounts: Cloud Accounts
VERIFIEDResource Development
Storm-1811 has created cloud accounts used to impersonate IT support in Microsoft Teams.
T1059.001
PowerShell
VERIFIEDExecution
PowerShell has been used for discovery, payload execution and persistent SSH-related activity.
Show more TTPs (6)
T1059.003
Windows Command Shell
VERIFIEDExecution
Black Basta can use cmd.exe and batch scripts for execution and system modification.
T1074.001
Local Data Staging
VERIFIEDCollection
Storm-1811 has staged captured credentials locally prior to exfiltration.
T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
VERIFIEDExfiltration
Storm-1811 has exfiltrated captured credentials using SCP.
T1490
Inhibit System Recovery
VERIFIEDImpact
Black Basta can delete shadow copies and interfere with system recovery.
T1688
Safe Mode Boot
VERIFIEDDefense Impairment
Black Basta can reboot compromised Windows systems into Safe Mode with networking.
T1486
Data Encrypted for Impact
VERIFIEDImpact
Black Basta encrypts Windows and VMware ESXi systems as part of its extortion activity.
Victims
CVEs
ConnectWise
— ScreenConnect
The joint CISA/FBI/HHS/MS-ISAC advisory documents exploitation of this ScreenConnect authentication-bypass vulnerability by Black Basta affiliates for initial access.
Associated since:
February 2024
Infrastructure
Black Basta leak site
Black Basta operated Tor-hosted leak infrastructure used to publish victim claims and stolen information as part of its double-extortion model.
Black Basta affiliate panel
Black Basta operated through a ransomware-as-a-service model in which affiliates gained access to victim environments and deployed the ransomware.
Timeline
2025-01
Last sustained leak-site activity
The currently indexed leak-site dataset shows Black Basta's last sustained victim publication in January 2025.
2024-05
Joint government advisory
FBI, CISA, HHS and MS-ISAC published a joint advisory documenting Black Basta tradecraft and indicators.
2023-01
Expanded global activity
Black Basta continued targeting high-value organisations across multiple countries and sectors.
Show more events (1)
2022-04
Black Basta emerges
Black Basta appeared publicly as a ransomware-as-a-service operation targeting Windows and VMware ESXi environments.
Sources
Show more sources (4)
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
Microsoft Threat Intelligence
Vendor research