Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Ransomware - Black Basta Collapses, But Its Tactics Live On 
Ransomware Attacks Latest News News & Analysis Phishing Social Engineering Study & Research

Black Basta Collapses, But Its Tactics Live On 

Kirsten DoyleBy Kirsten DoyleJune 12, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Black Basta Collapses
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The Black Basta ransomware group, once a dominant force in the cyber extortion landscape, disbanded in February 2025 following an unexpected leak of its internal chat logs. The leak, attributed to a disgruntled member known online as “ExploitWhispers,” surfaced shortly after the group breached an unspoken norm: targeting Russian financial institutions. 

ReliaQuest’s latest research details the group’s sudden downfall and the enduring influence of its tactics. At its peak, Black Basta named up to 50 victims a month on its data-leak site. But by the end of February, that site had disappeared. The group’s infrastructure followed suit. 

Despite this apparent collapse, the story doesn’t end there. 

A Ransomware Blueprint That Lives On 

Black Basta’s approach to ransomware-as-a-service (RaaS) was so successful that it’s become something of a model for the cybercrime ecosystem. Old members and unaffiliated malefactors continue to reuse and adapt the group’s techniques, particularly its early-stage intrusion strategies. 

Among these is mass email spam campaigns that lead to phishing lures delivered via Microsoft Teams. This method that proved successful even as defenses got better. More recently, attackers have begun layering in Python scripts triggered by cURL commands, which download and execute payloads after initial access is gained. 

These tactics illustrate the group’s lasting operational footprint, even as its formal structure dissolves. 

A Glimpse Into the Inner Workings 

The leaked chat logs reveal more than betrayal, they show a disciplined entity with defined roles. Black Basta ran like a business, albeit an illicit one. Intrusion specialists handled access. Developers built and maintained tooling. Managers coordinated ransom negotiations and victim communications. 

The group’s toolset was broad. It used credential stealers such as Lumma and StealC. For initial access and lateral movement, loaders like IcedID, Pikabot, and QakBot were employed. Data exfiltration relied on tools like Rclone, WinSCP, and FileZilla. 

Perhaps what made the group so successful was its agility and ability to pivot. As security teams adapted, so did Black Basta. It rotated payloads, changed delivery methods, and shifted infrastructure in response to defensive countermeasures. That adaptability made them incredibly hard to pin down. 

From Black Basta to New Fronts 

According to ReliaQuest, the end of Black Basta has done little to stem the tide of ransomware. Old affiliates have found new homes in groups like Cactus and Blacklock. Payment tracing and a noticeable surge in victim postings on these groups’ data-leak sites confirm this shift.  

The tactics have evolved, too. Teams phishing carries on, but is now enhanced by malefactors using  legitimate Microsoft domains to appear more credible. Bad actors are honing their tools to slip through multifactor authentication. Some have started using SEO poisoning to push malware through search engine results. 

New payloads are also appearing, many of them built in Python, reflecting the influence of Black Basta’s later-stage tool development. 

The Human Factor 

The most effective defense against these threats, ReliaQuest says, is unchanged: educated users. Technical controls matter, but security awareness often makes the difference between a successful breach and a foiled attempt. 

In several recent incidents, well-trained employees were able to spot phishing emails and report them before any damage occurred. Tools may shift, but social engineering is still the tip of the spear. Everyone is advised to remember that. 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

The Cyberattack That Exposed the Fragility of Digital Heritage

February 11, 20268 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}