Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Black Basta

🇷🇺Black Basta

🇷🇺 Black Basta is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 7 detection use cases to this actor across 12 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-07-30 to 2026-07-30.

crit 1
View full actor card → All threat actors
7Use cases
1Articles
12Techniques
5IOCs

Known aliases

Black BastaBlackBasta

Top techniques

All other tracked techniques

Detection use cases (7)

Microsoft Teams external-tenant chat from unverified IT-helpdesk impersonator Internal RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Internal PowerShell encoded / obfuscated command Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal Remote service execution — PsExec / SMB lateral movement Internal Network connections to article IPs / domains Internal

Threat-intel articles (1)

Tracked indicators

Domains (5)

corp-connect.top scan-security.top sequrityupdate.top supportsoft.top system-connect.top