BlackBasta Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
15
occurrences
First Seen
December 8, 2025
Last Seen
July 14, 2026

BlackBasta is a ransomware_group tracked across 9 threat clusters and 15 intelligence report mentions on ThreatCluster. First observed December 8, 2025; most recent activity July 14, 2026.

Related Threat Clusters

  • EU Sanctions Russia Over Ongoing Cyber Espionage Campaign

    The European Union has condemned and sanctioned Russia for a prolonged cyber espionage campaign targeting its member states. The campaign, orchestrated by the 16th Centre of the FSB, has involved infiltrating government…

    165 articles · Updated July 13, 2026
  • EU Sanctions Vitaly Kovalev, Ransomware Leader of Trickbot Group

    On July 14, 2026, the European Union, in coordination with the U.S. and U.K., sanctioned Vitaly Nikolayevich Kovalev, known as 'Stern,' a key figure in the Trickbot ransomware syndicate. Kovalev is linked to over $300…

    4 articles · Updated July 15, 2026
  • Critical RCE Vulnerability in Veeam Backup Exposes Organizations to Attacks

    Veeam has disclosed a critical vulnerability (CVE-2026-44963) affecting its Backup & Replication software, allowing authenticated domain users to execute remote code on domain-joined backup servers. This flaw impacts…

    11 articles · Updated June 9, 2026
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1553 articles · Updated February 12, 2026
  • Social Engineering Attack via Microsoft Teams Deploys A0Backdoor Malware

    Hackers are targeting employees in financial and healthcare sectors through Microsoft Teams, using social engineering tactics to gain remote access via Windows Quick Assist. The attackers deploy a new malware family…

    15 articles · Updated March 10, 2026
  • Veeam Backup & Replication Vulnerabilities Enable RCE Attacks

    Veeam has issued security updates to address multiple vulnerabilities in its Backup & Replication software, including a critical remote code execution (RCE) flaw tracked as CVE-2025-59470. This vulnerability affects…

    7 articles · Updated January 7, 2026
  • Makop Ransomware Enhancements Target Indian Organizations

    The Makop ransomware, a variant of the Phobos family, has been updated to include GuLoader malware for enhanced payload delivery. Recent attacks have primarily targeted Indian businesses, utilizing Remote Desktop…

    4 articles · Updated December 11, 2025
  • 389% Increase in Account Breaches Driven by Phishing Services in 2025

    eSentire reported a significant rise in account compromises in 2025, with email-led intrusions linked to credential theft. The research, based on data from over 2,000 customers, indicated that account compromise…

    4 articles · Updated January 16, 2026
  • Time to Exploit Vulnerabilities Drops 94% in Five Years

    A study by Flashpoint reveals that the time to exploit vulnerabilities has decreased from 745 days in 2020 to just 44 days in 2025. This significant reduction is attributed to the rise of n-day vulnerabilities, which…

    4 articles · Updated February 12, 2026

Recent Intelligence Reports

  • “Stern” Ransomware Operator Sanctioned by EU — Chainalysis · July 14, 2026
  • Police and Public Prosecution Service: New EU sanctions crucial step in international fight ... — Politie.Nl · July 13, 2026
  • New Veeam vulnerability exposes backup servers to RCE attacks — Bleepingcomputer · June 9, 2026
  • New Veeam vulnerability exposes backup servers to RCE attacks — Bleepingcomputer · June 9, 2026
  • Europol IOCTA 2026 report flags shift to industrialised cybercrime powered by AI ... — Industrialcyber.Co · April 29, 2026
  • Payouts King Rises as New Ransomware Threat Linked to Former BlackBasta Affiliates — Cybersecuritynews · April 17, 2026
  • Payouts King Emerges: New Ransomware Operation Tied to Ex — Gbhackers · April 17, 2026
  • Payouts King Emerges: New Ransomware Operation Tied to Ex — Gbhackers · April 17, 2026

CVSS v3.1 Breakdown