Overview

Platforms: Windows · ESXi
Variants: —
Extensions: —
ATT&CK software: —
Initial access: —
Top countries: US · GB · DE · CA · IT
Observed sectors: Manufacturing · Professional Services · Technology · Agriculture and Food Production · Transportation
Tracked victims: 526

Attribution

Storm-1811 VERIFIED
Vendor-tracked threat actor
MITRE ATT&CK identifies Storm-1811 as a financially motivated entity associated with deployment of Black Basta ransomware.

Relationships

Conti PROBABLE
Reported operator lineage
Multiple security researchers assess that Black Basta operators may include current or former members of the Conti ransomware ecosystem.

Affiliates

No affiliate information available.

Activity

Initial Access

Email bombing and fake helpdesk interaction
Storm-1811 has flooded victim inboxes with non-malicious spam and then impersonated IT support to establish contact and gain access.
Social engineering through Microsoft Teams
Storm-1811 has used Microsoft Teams accounts spoofing IT support or helpdesk identities during Black Basta-related intrusion activity.

Recent Observations

Last sustained victim publication
January 2025
Leak-site activity
Black Basta's leak-site dataset shows its most recent sustained victim publication in January 2025.
Joint Black Basta advisory
May 2024
Government advisory
FBI, CISA, HHS and MS-ISAC published a joint advisory documenting Black Basta tactics, techniques and indicators.
Black Basta emerges
April 2022
Operational activity
Black Basta began operating as a ransomware-as-a-service operation targeting Windows and VMware ESXi environments.

TTPs

ATT&CK coverage: 9 techniques · 7 tactics
T1667 Email Bombing
VERIFIED
Initial Access
Storm-1811 has flooded victim inboxes with large volumes of non-malicious spam to trigger follow-up social engineering.
T1585.003 Establish Accounts: Cloud Accounts
VERIFIED
Resource Development
Storm-1811 has created cloud accounts used to impersonate IT support in Microsoft Teams.
T1059.001 PowerShell
VERIFIED
Execution
PowerShell has been used for discovery, payload execution and persistent SSH-related activity.
Show more TTPs (6)
T1059.003 Windows Command Shell
VERIFIED
Execution
Black Basta can use cmd.exe and batch scripts for execution and system modification.
T1074.001 Local Data Staging
VERIFIED
Collection
Storm-1811 has staged captured credentials locally prior to exfiltration.
T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
VERIFIED
Exfiltration
Storm-1811 has exfiltrated captured credentials using SCP.
T1490 Inhibit System Recovery
VERIFIED
Impact
Black Basta can delete shadow copies and interfere with system recovery.
T1688 Safe Mode Boot
VERIFIED
Defense Impairment
Black Basta can reboot compromised Windows systems into Safe Mode with networking.
T1486 Data Encrypted for Impact
VERIFIED
Impact
Black Basta encrypts Windows and VMware ESXi systems as part of its extortion activity.

Victims

CVEs

ConnectWise — ScreenConnect
The joint CISA/FBI/HHS/MS-ISAC advisory documents exploitation of this ScreenConnect authentication-bypass vulnerability by Black Basta affiliates for initial access.
Associated since: February 2024

Infrastructure

Black Basta leak site
Black Basta operated Tor-hosted leak infrastructure used to publish victim claims and stolen information as part of its double-extortion model.
Black Basta affiliate panel
Black Basta operated through a ransomware-as-a-service model in which affiliates gained access to victim environments and deployed the ransomware.

Timeline

2025-01
Last sustained leak-site activity
The currently indexed leak-site dataset shows Black Basta's last sustained victim publication in January 2025.
2024-05
Joint government advisory
FBI, CISA, HHS and MS-ISAC published a joint advisory documenting Black Basta tradecraft and indicators.
2023-01
Expanded global activity
Black Basta continued targeting high-value organisations across multiple countries and sectors.
Show more events (1)
2022-04
Black Basta emerges
Black Basta appeared publicly as a ransomware-as-a-service operation targeting Windows and VMware ESXi environments.

Sources

Black Basta — Software S1070
MITRE ATT&CK
Framework
Storm-1811 — Group G1046
MITRE ATT&CK
Framework
#StopRansomware: Black Basta
FBI / CISA / HHS / MS-ISAC
Government advisory
Show more sources (4)