ATT&CKReferencesTrend Micro Black Basta May 2022

Trend Micro Black Basta May 2022

Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1036.004
Masquerade Task or Service
MalwareBlack Basta

Black Basta has established persistence by creating a new service named `FAX` after deleting the legitimate service by the same name.

T1059.001
PowerShell
MalwareBlack Basta

Black Basta has used PowerShell scripts for discovery and to execute files over the network.

T1106
Native API
MalwareBlack Basta

Black Basta has the ability to use native APIs for numerous functions including discovery and defense evasion.

T1112
Modify Registry
MalwareBlack Basta

Black Basta has modified the Registry to enable itself to run in safe mode, to change the icons and file extensions for encrypted files, and to add the malware path for persistence.

T1204.002
Malicious File
MalwareBlack Basta

Black Basta has been downloaded and executed from malicious Excel files.

T1486
Data Encrypted for Impact
MalwareBlack Basta

Black Basta can encrypt files with the ChaCha20 cypher and using a multithreaded process to increase speed. Black Basta has also encrypted files while the victim system is in safe mode, appending `.basta` upon completion.

T1490
Inhibit System Recovery
MalwareBlack Basta

Black Basta can delete shadow copies using vssadmin.exe.

T1491.001
Internal Defacement
MalwareBlack Basta

Black Basta has set the desktop wallpaper on victims' machines to display a ransom note.

T1529
System Shutdown/Reboot
MalwareBlack Basta

Black Basta has used `ShellExecuteA` to shut down and restart the victim system.

T1688
Safe Mode Boot
MalwareBlack Basta

Black Basta can reboot victim machines in safe mode with networking via `bcdedit /set safeboot network`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.