Internet

Russian Ransom Gang Black Basta Exposed

One of the most active Russian ransomware groups has been effectively exposed by security researchers in recent weeks. They gained access and insights into the systems and processes at the “Black Basta” gang.

There are currently only a few players in the ransomware scene who are responsible for the really big campaigns. Names like Hive or LockBit are known here, but Black Basta also belongs to this group. Hive recently suffered a major setback when FBI investigators severely curtailed the group’s ability to market its malware to the so-called ransomware-as-a-service (RaaS) industry.

Now it was also possible to step on Black Basta’s toes. The experts from the security company Quadrant Information Security had the main part in this. These caught the Black Basta people in the act of infiltrating a company’s network. The data that can be found is then copied and the servers in the company network are then encrypted in order to be able to enforce ransom payments.

More than just switching off

The point here is not just that the victims can get the decryption key by paying because companies in particular often have backups that can be used to fix the worst. The attackers are therefore also blackmailing the company with the threat of making the internal data public.

In the most recent case, the attack was not only prevented, but the security researchers also penetrated deep into Black Basta’s structures. This should lead to the group basically no longer being able to continue working on the basis it has built up for a long time. Because every new action that is carried out with the infrastructure last used can actually be observed live and stopped at the right moment. That should be as effective as a complete takeover of the servers used.

Furthermore, the issue of the security industry also offers the opportunity to delve into the inner structures and working methods of the ransomware scene in much more detail than before. Two reports published by Quadrant employees can serve as a starting point. The first report goes into the technical details of the malware and tactics used by Black Basta. The second report focuses on the backend servers and how they are managed.

Recent Posts

Android 17: Google finally lets users design the quick settings freely

Google has released the third beta version of Android 17 QPR2. The update brings users…

9 hours ago

Baby with iPhone: Apple has to remove advertising poster after heavy criticism

A huge Apple advertising poster in Milan has sparked heated debate. The motif showed a…

9 hours ago

After criticism of a lame player: VLC makers blame Windows

If the VLC player takes over 30 seconds to play a simple MP3 file, you're…

9 hours ago

Teams: Microsoft is discontinuing the chat function after 18 months

After only around 18 months, Microsoft is ending support for the live chat widget in…

9 hours ago

68 billion well spent: Blizzard becomes Microsoft’s Xbox savior

After the billion-dollar takeover by Microsoft, Blizzard Entertainment rescues the ailing Xbox division. The studio…

9 hours ago

Instagram or Instagzam? Users scoff at the new Insta logo

Meta is giving Instagram a new text logo for the first time in ten years.…

9 hours ago