ATT&CKSoftwareBlack Basta

Black Basta

S1070

Malware.View on attack.mitre.org

About this malware

Black Basta is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since at least April 2022; there are variants that target Windows and VMWare ESXi servers. Black Basta operations have included the double extortion technique where in addition to demanding ransom for decrypting the files of targeted organizations the cyber actors also threaten to post sensitive information to a leak site if the ransom is not paid. Black Basta affiliates have targeted multiple high-value organizations, with the largest number of victims based in the U.S. Based on similarities in TTPs, leak sites, payment sites, and negotiation tactics, security researchers assess the Black Basta RaaS operators could include current or former members of the Conti group.

Techniques used26

Procedure examples26

TechniqueProcedure example
T1007
System Service Discovery

Black Basta can check whether the service name `FAX` is present.

T1018
Remote System Discovery

Black Basta can use LDAP queries to connect to AD and iterate over connected workstations.

T1027.001
Binary Padding

Black Basta had added data prior to the Portable Executable (PE) header to prevent automatic scanners from identifying the payload.

T1036.004
Masquerade Task or Service

Black Basta has established persistence by creating a new service named `FAX` after deleting the legitimate service by the same name.

T1036.005
Match Legitimate Resource Name or Location

The Black Basta dropper has mimicked an application for creating USB bootable drivers.

T1047
Windows Management Instrumentation

Black Basta has used WMI to execute files over the network.

T1059.001
PowerShell

Black Basta has used PowerShell scripts for discovery and to execute files over the network.

T1059.003
Windows Command Shell

Black Basta can use `cmd.exe` to enable shadow copy deletion.

T1082
System Information Discovery

Black Basta can collect system boot configuration and CPU information.

T1083
File and Directory Discovery

Black Basta can enumerate specific files for encryption.

T1106
Native API

Black Basta has the ability to use native APIs for numerous functions including discovery and defense evasion.

T1112
Modify Registry

Black Basta has modified the Registry to enable itself to run in safe mode, to change the icons and file extensions for encrypted files, and to add the malware path for persistence.

T1204.002
Malicious File

Black Basta has been downloaded and executed from malicious Excel files.

T1222.002
Linux and Mac Permissions

The Black Basta binary can use `chmod` to gain full permissions to targeted files.

T1480.002
Mutual Exclusion

Black Basta will check for the presence of a hard-coded mutex `dsajdhas.0` before executing.

View all 26 procedure examples

Groups that use it1

Campaigns0

None recorded.

References6

  1. Avertium Black Basta June 2022 Open source
    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.
  2. Cyble Black Basta May 2022 Open source
    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.
  3. Deep Instinct Black Basta August 2022 Open source
    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.
  4. Minerva Labs Black Basta May 2022 Open source
    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.
  5. NCC Group Black Basta June 2022 Open source
    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.
  6. Palo Alto Networks Black Basta August 2022 Open source
    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.