Black Basta Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
51
occurrences
First Seen
October 31, 2025
Last Seen
July 23, 2026

Black Basta is a ransomware_group tracked across 28 threat clusters and 51 intelligence report mentions on ThreatCluster. First observed October 31, 2025; most recent activity July 23, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • 002 — attack.mitre.org · July 23, 2026
  • A Huge Trove Of Leaked Black Basta Chat Logs Expose The Ransomware Gangs Key Members And Victims — techcrunch.com · July 5, 2026
  • US government body paid $1M in data-theft extortion — Thenextweb · July 4, 2026
  • Stealthy Mistic Backdoor Targets Enterprise Networks via KongTuke Ransomware Access Broker — Rescana · June 25, 2026
  • Be on the lookout for Mistic, a new backdoor used by ransomware broker — Csoonline · June 24, 2026
  • Symantec’s Threat Hunter Team observed ModeloRAT — www.security.com · June 24, 2026
  • Stealthy Mistic backdoor linked to ransomware access broker KongTuke — Ground.News · June 24, 2026
  • Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker — Security · June 24, 2026

CVSS v3.1 Breakdown