Malware.View on attack.mitre.org
Black Basta is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since at least April 2022; there are variants that target Windows and VMWare ESXi servers. Black Basta operations have included the double extortion technique where in addition to demanding ransom for decrypting the files of targeted organizations the cyber actors also threaten to post sensitive information to a leak site if the ransom is not paid. Black Basta affiliates have targeted multiple high-value organizations, with the largest number of victims based in the U.S. Based on similarities in TTPs, leak sites, payment sites, and negotiation tactics, security researchers assess the Black Basta RaaS operators could include current or former members of the Conti group.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
Black Basta can check whether the service name `FAX` is present. |
| T1018 Remote System Discovery |
Black Basta can use LDAP queries to connect to AD and iterate over connected workstations. |
| T1027.001 Binary Padding |
Black Basta had added data prior to the Portable Executable (PE) header to prevent automatic scanners from identifying the payload. |
| T1036.004 Masquerade Task or Service |
Black Basta has established persistence by creating a new service named `FAX` after deleting the legitimate service by the same name. |
| T1036.005 Match Legitimate Resource Name or Location |
The Black Basta dropper has mimicked an application for creating USB bootable drivers. |
| T1047 Windows Management Instrumentation |
Black Basta has used WMI to execute files over the network. |
| T1059.001 PowerShell |
Black Basta has used PowerShell scripts for discovery and to execute files over the network. |
| T1059.003 Windows Command Shell |
Black Basta can use `cmd.exe` to enable shadow copy deletion. |
| T1082 System Information Discovery |
Black Basta can collect system boot configuration and CPU information. |
| T1083 File and Directory Discovery |
Black Basta can enumerate specific files for encryption. |
| T1106 Native API |
Black Basta has the ability to use native APIs for numerous functions including discovery and defense evasion. |
| T1112 Modify Registry |
Black Basta has modified the Registry to enable itself to run in safe mode, to change the icons and file extensions for encrypted files, and to add the malware path for persistence. |
| T1204.002 Malicious File |
Black Basta has been downloaded and executed from malicious Excel files. |
| T1222.002 Linux and Mac Permissions |
The Black Basta binary can use `chmod` to gain full permissions to targeted files. |
| T1480.002 Mutual Exclusion |
Black Basta will check for the presence of a hard-coded mutex `dsajdhas.0` before executing. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.