ATT&CKReferencesNCC Group Black Basta June 2022

NCC Group Black Basta June 2022

Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareBlack Basta

Black Basta has used WMI to execute files over the network.

T1059.001
PowerShell
MalwareBlack Basta

Black Basta has used PowerShell scripts for discovery and to execute files over the network.

T1083
File and Directory Discovery
MalwareBlack Basta

Black Basta can enumerate specific files for encryption.

T1112
Modify Registry
MalwareBlack Basta

Black Basta has modified the Registry to enable itself to run in safe mode, to change the icons and file extensions for encrypted files, and to add the malware path for persistence.

T1218.010
Regsvr32
MalwareQakBot

QakBot can use Regsvr32 to execute malicious DLLs.

T1486
Data Encrypted for Impact
MalwareBlack Basta

Black Basta can encrypt files with the ChaCha20 cypher and using a multithreaded process to increase speed. Black Basta has also encrypted files while the victim system is in safe mode, appending `.basta` upon completion.

T1490
Inhibit System Recovery
MalwareBlack Basta

Black Basta can delete shadow copies using vssadmin.exe.

T1491.001
Internal Defacement
MalwareBlack Basta

Black Basta has set the desktop wallpaper on victims' machines to display a ransom note.

T1543.003
Windows Service
MalwareQakBot

QakBot can remotely create a temporary service on a target host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.