Black Basta is a new ransomware campaign that has already hit at least a dozen companies. Some experts suspect this group has ties to the notorious Conti. Although Black Basta only became known in mid-April, researchers at MalwareHunterTeam discovered a sample of the malware that had been compiled back in February.
Black Basta attackers encrypt data on infected systems and add the .basta suffix to encrypted files. Like many other extortion groups, they also steal data from victims on a massive scale to increase pressure and the likelihood of receiving a ransom.
Minerva specialists conducted a technical analysis of Black Basta and found that the malware requires administrator credentials to run. In addition, it uses the Windows Fax service to ensure persistence on infected PCs.
Black Basta has already published a list of about ten organizations that refused to pay on its website. Among the victims are the American Dental Association and the German wind turbine manufacturer Deutsche Windtechnik, which confirmed the hack but stated that the turbines themselves were not compromised. The hackers have posted more than 100 GB of stolen company data.
According to MalwareHunterTeam, “the Black Basta gang is definitely related to Conti.” Their assumption is based on the similarity of the leak and ransom websites, as well as the nature of the attackers’ “support service” communications. Other researchers also note the similarity between Black Basta and Conti’s methods.
Meanwhile, Conti itself continues its attacks, including on government agencies in Peru and Costa Rica.
Moreover, Conti’s activity has increased significantly in recent weeks, despite the fact that their operations were partially exposed by a pro-Ukrainian hacktivist. Through the ContiLeaks Twitter account, he published correspondence, credentials, email addresses, C&C server data, and even the source code for Conti’s tools.
Although it was assumed that this would deal a serious blow to Conti’s activities, a recent Secureworks report showed the opposite: in March 2022 alone, more than 70 new victims appeared on their website, which is significantly higher than the average for 2021 (43 victims per month).