Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
MalwareBlack Basta | Black Basta can enumerate specific files for encryption. |
| T1106 Native API |
MalwareBlack Basta | Black Basta has the ability to use native APIs for numerous functions including discovery and defense evasion. |
| T1490 Inhibit System Recovery |
MalwareBlack Basta | Black Basta can delete shadow copies using vssadmin.exe. Avertium Black Basta June 2022Check Point Black Basta October 2022Cyble Black Basta May 2022Deep Instinct Black Basta August 2022Minerva Labs Black Basta May 2022NCC Group Black Basta June 2022Palo Alto Networks Black Basta August 2022Trend Micro Black Basta May 2022Trend Micro Black Basta Spotlight September 2022 |
| T1491.001 Internal Defacement |
MalwareBlack Basta | Black Basta has set the desktop wallpaper on victims' machines to display a ransom note. |
| T1543.003 Windows Service |
MalwareBlack Basta | Black Basta can create a new service to establish persistence. |
| T1688 Safe Mode Boot |
MalwareBlack Basta | Black Basta can reboot victim machines in safe mode with networking via `bcdedit /set safeboot network`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.