The Black Basta ransomware group and its affiliates compromised hundreds of organizations worldwide between April 2022 and May 2024, according to a new report from several US government agencies.
It claimed that Black Basta attacks have impacted more than 500 organizations in North America, Europe and Australia.
They led to the encryption and theft of data from at least 12 out of 16 critical infrastructure sectors, including the Healthcare and Public Health Sector.
It's unclear how much money the group has made over the period from its victims, but a November 2023 analysis of Bitcoin transactions estimated over $100m since April 2022.
The CSA includes TTPs and IOCs obtained from FBI investigations and third-party reporting, as well as a useful list of mitigations for network defenders designed to help them improve security posture.
It's long been suspected that Black Basta is an offshoot of Conti, a prolific ransomware group which ceased operating just before Black Basta appeared.
A November 2023 Bitcoin analysis from insurer Corvus highlighted significant crossover between the two groups - with both targeting manufacturing, construction/engineering, wholesale/retail, financial services, and transportation and logistics firms.
Black Basta prefers popular initial access techniques such as phishing and exploitation of known vulnerabilities, before deploying a double extortion model.
This Cyber News was published on www.infosecurity-magazine.com. Publication date: Mon, 13 May 2024 13:43:12 +0000