« Todas las amenazas

Grupo de ransomware

Blackbasta

BlackBasta emerged in April 2022 and is widely assessed to be operated by former Conti group members. It functions as a Ransomware-as-a-Service (RaaS), leveraging a double-extortion model—encrypting data and threatening public leaks on its Tor-based site. The malware supports Windows and Linux/VMware ESXi environments, using ChaCha20 for encryption with RSA-4096 for key protection. Encrypted files are appended with the .basta extension, and a ransom note (readme.txt) provides negotiation instructions. BlackBasta has hit victims across manufacturing, construction, healthcare, government, and critical infrastructure sectors, with confirmed targets in the U.S., Canada, U.K., Australia, and New Zealand. Initial access vectors include exploitation of known vulnerabilities (e.g., QakBot infections, ZeroLogon, PrintNightmare), phishing, and purchasing credentials from Initial Access Brokers. By mid-2024, BlackBasta was among the top five most active ransomware groups worldwide.

Víctimas en los últimos 90 días0

Países más afectados

Sin datos todavía.

Sectores más afectados

Sin datos todavía.

Víctimas recientes

Sin datos todavía.

Las reivindicaciones las publican los propios grupos criminales y no están verificadas hasta que la organización o la prensa las confirman. Los nombres de personas físicas (autónomos, profesionales individuales) se anonimizan conforme al RGPD. Nunca enlazamos a sitios de filtración ni a datos robados. Para solicitar la retirada o anonimización de una entrada, contacte con el administrador del sitio.

Fuentes: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.