BlackBasta
From extortion.wiki, the ransomware negotiation research archive
Negotiation records classified under BlackBasta in the current Ransomchats snapshot. This page indexes the source label; it does not independently verify attribution.
Classification follows the source dataset. Metadata is useful. It is not testimony.
Actor lineage
Global lineage directoryOverview
Black Basta is documented as a RaaS variant first identified in April 2022. Reporting about possible Conti personnel overlap is retained as a suspected relationship, not a confirmed succession.
Documentary media

Known aliases
No source-supported alias is currently recorded. Malware names and actor-group names are not assumed to be equivalent.
Historical timeline
-
Black Basta first observed
Black Basta first identified
The joint advisory states that the Black Basta RaaS variant was first identified in April 2022.
Evidence status: officially confirmed Confirmed
Lineage and relationships
| Related actor or family | Relationship | Period | Confidence | Evidence summary | Sources |
|---|---|---|---|---|---|
| Contioperation | Shared operatorssuspected · undirected | From April 2022 | Moderate confidence | MITRE records researchers' assessment that Black Basta operators could include current or former Conti members. “Could include” is not treated as confirmed membership or succession.
| MITRE ATT&CK |
Predecessors
None established.
Successors
None established.
Splits and mergers
None established.
Suspected affiliate relationships
- Shared operators with Conti — Moderate confidence
MITRE ATT&CK integration
No explicit MITRE ATT&CK group mapping is published for this source label. Software entries and fuzzy name matches are not promoted to group mappings.
External intelligence references
- #StopRansomware: Black BastaFBI, CISA, HHS, and MS-ISAC · government advisory · primary authoritative
- Black Basta, Software S1070MITRE ATT&CK · MITRE ATTACK · authoritative secondary
Confidence and evidence notes
Confidence applies to each individual alias, event, or relationship—not to the actor page as a whole. “Confirmed” requires explicit authoritative attribution or multiple strong independent sources. Moderate, low, disputed, and unknown entries retain the source's uncertainty. A malware-family name is not automatically an actor identity, and shared code or affiliates do not prove shared leadership.
Ransomware notes
Browse Blackbasta notesThe explicit archive alias mapping connects this Ransomchats actor label to the ThreatLabz family Blackbasta. Its 5 archived notes are counted and searched separately from the negotiation records below.
Search within this collection
Negotiation records
| Participants | Source | Archive status | |||
|---|---|---|---|---|---|
| 20240814 | 50 | Black Basta, Victim | JSON | Indexed | |
| 20230501 | 50 | Black Basta, Victim | JSON | Indexed | |
| 20230410 | 57 | Black Basta, Victim | JSON | Indexed | |
| 20221229 | 50 | Black Basta, Victim | JSON | Indexed | |
| 20221011 | 50 | Black Basta, Victim | JSON | Indexed |
No matching records
No records match the current filters. Remove one before blaming the archive.