From the Labs: YARA Rule for Detecting Black Basta
ReversingLabs’ YARA detection rule for Black Basta can help you find this ransomware in your environment.
ReversingLabs threat analysts are constantly working to respond to new threats and provide our customers with information and tools to defend their systems from attacks. Written by our threat analysts, our high-quality, open source YARA rules help threat hunters, incident responders, security analysts, and other defenders detect malicious behavior in their environment.
In this series, we break down some of the threats behind our YARA detection rules that can help your organization to detect threats within your environment.
Black Basta: A Prolific Operation
The Black Basta ransomware group was first discovered in April 2022, but evidence suggests that the group has been in development since February 2022. Since the group’s first string of attacks in April, Black Basta has been highly active and has successfully attacked an estimated 100 organizations, based on public reports. Researchers suspect that the group’s quick rise to success reflects an operation that has recycled its parts from another, now defunct ransomware group.
Black Basta functions similarly to other ransomware gangs. It is a ransomware-as-a-service (RaaS) that uses the double extortion technique, in which they not only encrypt files and demand ransoms from victims, but also steal data from victims which they threaten to sell or publish via a dark web leak site, “Basta News.”
A Laundry List of Victims
Since its inception, Black Basta has been active and successful in targeting a large number of organizations across industries. In late April of last year, Black Basta managed to breach at least 12 organizations across the globe within the span of a few weeks, ranging from systems belonging to the American Dental Association to Deutsche Windtechnik, a company in the renewable energy sector. One of the group’s early victims was asked to pay a $2 million ransom in order to get their files decrypted and prevent their data from being released, reports BleepingComputer.
Months later, researchers at Malwarebytes found that Black Basta successfully targeted 25 companies in October 2022, making it one of the most successful ransomware groups in 2022.
In attacks in late 2022, Black Basta was found using Qakbot, a type of malware, to target U.S.-based companies. Using Qakbot allowed the attackers to create an initial point of entry and move laterally within an organization’s network, according to . More than by this campaign in just two weeks.



