Blackbasta Ransomware

Malware updated 5 months ago (2024-05-04T19:19:41.649Z)
Download STIX
Preview STIX
BlackBasta is a ransomware-type malware, designed to infiltrate systems undetected and hold data hostage in exchange for ransom. Originating from Russian-speaking regions, this malicious software has been linked to numerous high-profile cyber attacks. The group behind BlackBasta has demonstrated its capacity to breach even well-secured corporations, causing significant operational disruptions and stealing sensitive data. Recently, Viking Coca-Cola, one of the largest Coca-Cola bottlers in the U.S., fell victim to a BlackBasta attack. The company's name was added to the list of victims on the ransomware group's data leak website, indicating a successful data breach. In another incident, Dish Network experienced service disruptions due to a BlackBasta ransomware attack between February and March. The extent of these attacks showcases the potency and reach of the BlackBasta group. Over the past 22 months, it has been reported that the BlackBasta ransomware gang extracted over $107 million in payments from its victims, underlining the severity and financial impact of these attacks. There are indications that other groups may attempt to exploit the same vulnerabilities as BlackBasta, particularly a flaw in VMware systems. Italy's cybersecurity agency has suggested a possible link between BlackBasta and these anticipated attacks, although no concrete evidence has been published to support this claim.
Description last updated: 2024-05-04T18:55:08.373Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The QakBot Malware is associated with Blackbasta Ransomware. Qakbot is a potent piece of malware, or malicious software, that infiltrates computer systems through suspicious downloads, emails, or websites. Once installed, it can steal personal information, disrupt operations, or even hold data hostage for ransom. This malware, built by various groups includinUnspecified
2
The Blackbasta Malware is associated with Blackbasta Ransomware. BlackBasta is a notorious malware, particularly known for its ransomware attacks. The group behind it has been linked with other harmful software such as IcedID, NetSupport, Gozi, PikaBot, Pushdo, Quantum, Royal, and Nokoyawa. Artifacts and indicators of compromise (IoCs) suggest a possible relationUnspecified
2
Source Document References
Information about the Blackbasta Ransomware Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Securityaffairs
5 months ago
CERT-EU
a year ago
Malwarebytes
7 months ago
CERT-EU
9 months ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
9 months ago
InfoSecurity-magazine
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
2 years ago
CERT-EU
10 months ago