Black Basta ransomware switches to more evasive custom malware

Share:

The Black Basta ransomware gang has shown resilience and an ability to adapt to a constantly shifting space, using new custom tools and tactics to evade detection and spread throughout a network.

Black Basta is a ransomware operator who has been active since April 2022 and is responsible for over 500 successful attacks on companies worldwide.

The ransomware group follows a double-extortion strategy, combining data theft and encryption, and demands large ransom payments in the millions. The ransomware gang previously partnered with the QBot botnet to gain initial access to corporate networks.

However, after the QBot botnet was disrupted by law enforcement, Mandiant reports that the ransomware gang had to create new partnerships to breach corporate networks.

Moreover, Mandiant, who tracks the threat actors as UNC4393, has identified new malware and tools used in Black Basta intrusions, demonstrating evolution and resilience.

The Black Basta ransomware gang has had an active year thus far, compromising notable entities such as Veolia North America, Hyundai Motor Europe, and Keytronic.

The threat group’s sophistication is reflected in the fact that it often has access to zero-day vulnerability exploits, including Windows privilege elevation (2024-26169) and VMware ESXi authentication bypass flaws (CVE-2024-37085).

New Black Basta tactics and tools

After the FBI and DOJ took down the QBot infrastructure in late 2023, Black Basta turned to other initial access distribution clusters, most notably those delivering DarkGate malware.

Later, Black Basta switched to using SilentNight, a versatile backdoor malware delivered through malvertising, marking a departure from phishing as their primary method for initial access.

Mandiant reports that Black Basta has gradually switched from using publicly available tools to internally developed custom malware.

In early 2024, UNC4393 was observed deploying a custom memory-only dropper named DawnCry. This dropper initiated a multi-stage infection, followed by DaveShell, which ultimately led to the PortYard tunneler.

PortYard, also a custom tool, establishes connections to Black Basta’s command and control (C2) infrastructure and proxies traffic.

Other noteworthy custom tools used by Black Basta in recent operations are:

  • CogScan: A .NET reconnaissance tool used to gather a list of hosts available on the network and collect system information.
  • SystemBC: A tunneler that retrieves proxy-related commands from a C2 server using a custom binary protocol over TCP.
  • KnockTrock: A .NET-based utility that creates symbolic links on network shares and executes the BASTA ransomware executable, providing it with the path to the newly created symbolic link.
  • KnowTrap:  A memory-only dropper written in C/C++ that can execute an additional payload in memory.

Combined with the above, Black Basta continues using “living off the land” binaries and readily available tools in its latest attacks, including the Windows certutil command-line utility to download SilentNight and the Rclone tool to exfiltrate data.

All in all, Black Basta remains a significant global threat and one of the top players in the ransomware space.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:01 pm, Jun 12, 2025
weather icon 24°C
L: 23° | H: 26°
broken clouds
Humidity: 63 %
Pressure: 1012 mb
Wind: 11 mph S
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:17 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
23° | 26°°C 0 mm 0% 9 mph 71 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 27°°C 1 mm 100% 7 mph 94 % 1019 mb 0 mm/h
Sat Jun 14 10:00 pm
weather icon
17° | 23°°C 1 mm 100% 13 mph 96 % 1019 mb 0 mm/h
Sun Jun 15 10:00 pm
weather icon
13° | 22°°C 0.46 mm 46% 10 mph 84 % 1025 mb 0 mm/h
Mon Jun 16 10:00 pm
weather icon
14° | 25°°C 0 mm 0% 7 mph 86 % 1027 mb 0 mm/h
Today 7:00 pm
weather icon
24° | 25°°C 0 mm 0% 9 mph 62 % 1012 mb 0 mm/h
Today 10:00 pm
weather icon
19° | 21°°C 0 mm 0% 4 mph 71 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
17° | 17°°C 0 mm 0% 3 mph 80 % 1016 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0 mm 0% 3 mph 84 % 1017 mb 0 mm/h
Tomorrow 7:00 am
weather icon
18° | 18°°C 0 mm 0% 7 mph 79 % 1018 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 7 mph 60 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 6 mph 41 % 1019 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
27° | 27°°C 0 mm 0% 7 mph 40 % 1019 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,353.19
-2.47%
Ethereum(ETH)
€2,351.68
-4.79%
Tether(USDT)
€0.86
0.00%
XRP(XRP)
€1.92
-4.08%
Solana(SOL)
€135.53
-5.94%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.160775
-8.31%
Shiba Inu(SHIB)
€0.000011
-7.71%
Pepe(PEPE)
€0.000010
-11.12%
Peanut the Squirrel(PNUT)
€0.236997
-5.02%
Scroll to Top