Closed ardroci closed 2 years ago
Thanks @ardroci for bringing this issue to our attention and providing lots of great details including sample hashes! We don't currently have coverage on the Black Basta family so we should try to change that 😃, our team will review the request and get back to you. Thanks again!
Hey @ardroci. I wanted to provide an update, we have written two new YARA rules around this family. They are currently going through a soak-testing period to verify if any potential issues arise, our plan will be to move these to production soon. I will provide another update to you when that happens, thanks!
Following up on this @ardroci, thanks for submitting this over. Below are the following new rules based on your request:
I will go ahead and close this out, feel free to ping us or let us know if you have any questions. Thanks again for bringing this to our attention!
Request for Coverage Details
Malware Family Name: Black Basta
Description
Black Basta is a new ransomware strain discovered during April 2022. Looks in development since, at least early February 2022, and due to their ability to quickly amass new victims and the style of their negotiations, this is likely not a new operation but rather a rebranding of a previous top-tier ransomware gang that brought along their affiliates.
Example Sample
https://malpedia.caad.fkie.fraunhofer.de/details/win.blackbasta https://www.virustotal.com/gui/file/96339a7e87ffce6ced247feb9b4cb7c05b83ca315976a9522155bad726b8e5be https://www.virustotal.com/gui/file/0d6c3de5aebbbe85939d7588150edf7b7bdc712fceb6a83d79e65b6f79bfc2ef https://www.virustotal.com/gui/file/0d6c3de5aebbbe85939d7588150edf7b7bdc712fceb6a83d79e65b6f79bfc2ef https://www.youtube.com/watch?v=Fezzdw6f7ls