[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/threat-assessment-black-basta-ransomware/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/ "High Profile Threats")
* [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/ "Ransomware")  
  [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)

# Threat Assessment: Black Basta Ransomware

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 12 min read  
Related Products  
[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Amer Elsad](https://unit42.paloaltonetworks.com/author/amer-elsad/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:August 25, 2022

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/)
  * [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Black Basta ransomware](https://unit42.paloaltonetworks.com/tag/black-basta-ransomware/)
  * [Dark Scorpius](https://unit42.paloaltonetworks.com/tag/dark-scorpius/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/?pdf=download&lg=en&_wpnonce=edee969a51 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/?pdf=print&lg=en&_wpnonce=edee969a51 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Threat%20Assessment:%20Black%20Basta%20Ransomware&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-black-basta-ransomware%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-black-basta-ransomware%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-black-basta-ransomware%2F&title=Threat%20Assessment:%20Black%20Basta%20Ransomware "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-black-basta-ransomware%2F&text=Threat%20Assessment:%20Black%20Basta%20Ransomware "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-black-basta-ransomware%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Threat%20Assessment:%20Black%20Basta%20Ransomware%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-black-basta-ransomware%2F "Share in Mastodon")

## Executive Summary

Black Basta is ransomware as a service (RaaS) that first emerged in April 2022. However, evidence suggests that it has been in development since February. The Black Basta operator(s) use the double extortion technique, meaning that in addition to encrypting files on the systems of targeted organizations and demanding ransom to make decryption possible, they also maintain a dark web leak site where they threaten to post sensitive information if an organization chooses not to pay ransom.

Black Basta affiliates have been very active deploying Black Basta and extorting organizations since the ransomware first emerged. Although the Black Basta affiliates have only been active for the past couple of months, based on the information posted on their leak site, they have compromised over 75 organizations at the time of this publication. Unit 42 has also worked on several Black Basta incident response cases.

The ransomware is written in C++ and impacts both Windows and Linux operating systems. It encrypts users' data using a combination of ChaCha20 and RSA-4096, and to speed up the encryption process, the ransomware encrypts in chunks of 64 bytes, with 128 bytes of data remaining unencrypted between the encrypted regions. The faster the ransomware encrypts, the more systems can potentially be compromised before defenses are triggered. It is a key factor affiliates look for when joining a Ransomware-as-a-Service group.

Palo Alto Networks customers receive help with detection and prevention of Black Basta ransomware through the following products and services: [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall) (including [cloud-delivered security services](https://www.paloaltonetworks.com/network-security/security-subscriptions) such as [WildFire)](https://www.paloaltonetworks.com/network-security/next-generation-firewall).

If you think you may have been impacted by a cyber incident, the [Unit 42 Incident Response team](https://www.paloaltonetworks.com/unit42/respond/incident-response) is available 24/7/365. You can also take preventative steps by requesting any of our [cyber risk management services](https://www.paloaltonetworks.com/unit42/assess).

|------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------|
| Related Unit 42 Topics | [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/), [Threat Assessments](https://unit42.paloaltonetworks.com/tag/threat-assessment/) |

## Black Basta Overview

Black Basta is ransomware as a service (RaaS) that leverages [double extortion](https://www.paloaltonetworks.com/blog/2022/03/ransomware-trends-demands-dark-web-leak-sites/) as part of its attacks. The attackers not only execute ransomware but also exfiltrate sensitive data and threaten to release it publicly if the ransom demands are not met. The threat actors behind the ransomware deploy a name-and-shame approach to their victim, where they use a Tor site, Basta News, to list all of the victims who have not paid the ransom.

Although the Black Basta RaaS has only been active for a couple of months, according to its leak site, it had compromised over 75 organizations at the time of this publication. At least 20 victims were posted to its leak site in the first two weeks of the ransomware's operation, which indicates the group likely is experienced in the ransomware business and has a steady source of initial access.

It is also possible that this is not a new operation but rather a rebrand of a previous ransomware group that brought along their affiliates. Based on multiple similarities in tactics, techniques and procedures (TTPs) - victim-shaming blogs, recovery portals, negotiation tactics, and how quickly Black Basta amassed its victims - that the Black Basta group could include current or former members of the Conti group.

Unit 42 has observed ​​the Black Basta ransomware group using QBot as an initial point of entry and to move laterally in compromised networks. QBot, also known as [Qakbot](https://unit42.paloaltonetworks.com/tutorial-qakbot-infection/), is a Windows malware strain that started as a banking trojan and evolved into a malware dropper. It has been used by other ransomware groups, including MegaCortex, ProLock, [DoppelPaymer](https://unit42.paloaltonetworks.com/ransomware-threat-assessments/4/) and [Egregor](https://unit42.paloaltonetworks.com/egregor-ransomware-courses-of-action/). While these ransomware groups used QBot for initial access, the Black Basta group was observed using it for both initial access and to spread laterally throughout the network.

Figure 1 below shows the standard attack lifecycle observed with Black Basta ransomware.
![Figure 1 shows the Black Basta attack lifecycle based on Unit 42 incident response cases. A phishing email contains either a URL for a ZIP file. The ZIP file downloads and extracts and XLS file. Macros enabled HTTP traffic for QAKBOT DLL files. QAKBOT C2 activity deploys Cobalt strike, which allows for system discovery and lateral movement using RDP/Psexec. And finally the Black Basta Ransomware deployment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-84.png) Figure 1. Black Basta attack lifecycle based on Unit 42 incident response cases.

## Technical Details

Black Basta is written in C++ and is cross-platform ransomware that impacts both Windows and Linux systems. In June 2022, a VMware ESXi variant of Black Basta was observed targeting virtual machines running on enterprise Linux servers.

The ransomware includes anti-analysis techniques that attempt to detect code emulation or sandboxing to avoid virtual/analysis machine environments. It also supports the command line argument -forcepath that is used to encrypt files in a specified directory. Otherwise, the entire system, except for certain critical directories, is encrypted.

The ransomware spawns a mutex with a string of dsajdhas.0 to ensure a single instance of the malware is running at a time. Then it will iterate through the entire file system, encrypting files with a file extension of .basta.

Black Basta ransomware encrypts users' data through a combination of ChaCha20 and RSA-4096. To speed up the encryption process, the ransomware encrypts in chunks of 64 bytes, with 128 bytes of data remaining unencrypted between the encrypted regions. The ransomware also attempts to delete shadow copies and other backups of files using [vssadmin.exe](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/vssadmin), a command-line tool that manages Volume Shadow Copy Service (VSS), which captures and copies stable images for backups on running systems.

It writes the Random-letters.ico and Random-letters.jpg files to the %TEMP% directory. The .jpg file is leveraged to overwrite the desktop background and appears as follows:
![Figure 2 shows the Black Basta Wallpaper, which reads "Your network is encrypted by the Black Basta group. Instructions in the file readme.txt.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-85.png) Figure 2. Black Basta desktop wallpaper.

It adds a custom icon to the registry, corresponding to the .basta icon, which is shown in Figure 3.
![Figure 3 shows the black and white cube Black Basta icon.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-86.png) Figure 3. Black Basta icon.

It will then boot the system in safe mode and proceed to encrypt files. Following successful encryption, the file's extension is changed to .basta and the ransomware will write numerous instances of readme.txt, which contains the following ransom note:
![Figure 4 shows Black Basta ransom note in the readme.txt file. It reads: Your data are stolen and encrypted. The data will be published on TOR website if you do not pay the ransom. You can contact us and decrypt one file for free on this TOR site. Onion address listed.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-87.png) Figure 4. Black Basta ransom note.

## Tactics, Techniques and Procedures

We have observed Black Basta affiliates leveraging the following TTPs:

|------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Tactic / Technique**                                           | **Notes**                                                                                                                                                                                                                                                                                                                                       |
| **TA0001 Initial Access**                                                                                                                                                                                                                                                                                                                                                                                         ||
| T1566.001. Phishing: Spear phishing Attachment                   | Victims receive spear phishing emails with attached malicious zip files - typically password protected. That contains malicious doc including .doc, .pdf, .xls                                                                                                                                                                                  |
| **TA0002 Execution**                                                                                                                                                                                                                                                                                                                                                                                              ||
| T1569.002. System Services: Service Execution                    | Black Basta has installed and used PsExec to execute payloads on remote hosts.                                                                                                                                                                                                                                                                  |
| T1047. Windows Management Instrumentation                        | Utilizes Invoke-TotalExec to push out the ransomware binary.                                                                                                                                                                                                                                                                                    |
| T1059.001. Command and Scripting Interpreter: PowerShell         | Black Basta has encoded PowerShell scripts to download additional scripts.                                                                                                                                                                                                                                                                      |
| **TA0003 Persistence**                                                                                                                                                                                                                                                                                                                                                                                            ||
| T1136. Create Account                                            | Black Basta threat actors created accounts with names such as temp, r, or admin.                                                                                                                                                                                                                                                                |
| T1098. Account Manipulation                                      | Added newly created accounts to the administrators' group to maintain elevated access.                                                                                                                                                                                                                                                          |
| T1543.003. Create or Modify System Process: Windows Service      | Creates benign-looking services for the ransomware binary.                                                                                                                                                                                                                                                                                      |
| T1574.001. Hijack Execution Flow: DLL Search Order Hijacking     | Black Basta used Qakbot, which has the ability to exploit Windows 7 Calculator to execute malicious payloads.                                                                                                                                                                                                                                   |
| **TA0004 Privilege Escalation**                                                                                                                                                                                                                                                                                                                                                                                   ||
| T1484.001. Domain Policy Modification: Group Policy Modification | Black Basta can modify group policy for privilege escalation and defense evasion.                                                                                                                                                                                                                                                               |
| T1574.001. Hijack Execution Flow: DLL Search Order Hijacking     | Black Basta used Qakbot, which has the ability to exploit Windows 7 Calculator to execute malicious payloads.                                                                                                                                                                                                                                   |
| T1543.003. Create or Modify System Process: Windows Service      | Creates benign-looking services for the ransomware binary.                                                                                                                                                                                                                                                                                      |
| **TA0005 Defense Evasion**                                                                                                                                                                                                                                                                                                                                                                                        ||
| T1484.001. Domain Policy Modification: Group Policy Modification | Black Basta can modify group policy for privilege escalation and defense evasion.                                                                                                                                                                                                                                                               |
| T1218.010. System Binary Proxy Execution: Regsvr32               | Black Basta has used regsvr32.exe to execute a malicious DLL.                                                                                                                                                                                                                                                                                   |
| T1070.004. Indicator Removal on Host: File Deletion              | Attempts to delete malicious batch files.                                                                                                                                                                                                                                                                                                       |
| T1112. Modify Registry                                           | Black Basta makes modifications to the Registry.                                                                                                                                                                                                                                                                                                |
| T1140. Deobfuscate/Decode Files or Information                   | Initial malicious .zip file bypasses some antivirus detection due to password protection.                                                                                                                                                                                                                                                       |
| T1562.001. Impair Defenses: Disable or Modify Tools              | Disables Windows Defender with batch scripts, such as d.bat or defof.bat.                                                                                                                                                                                                                                                                       |
| T1562.004. Impair Defenses: Disable or Modify System Firewall    | Uses batch scripts, such as rdp.bat or SERVI.bat, to modify the firewall to allow remote administration and RDP.                                                                                                                                                                                                                                |
| T1562.009. Impair Defenses: Safe Boot Mode                       | Uses bcdedit to boot the device in safe mode.                                                                                                                                                                                                                                                                                                   |
| T1574.001. Hijack Execution Flow: DLL Search Order Hijacking     | Black Basta used Qakbot, which has the ability to exploit Windows 7 Calculator to execute malicious payloads.                                                                                                                                                                                                                                   |
| T1622. Debugger Evasion                                          | Uses IsDebuggerPresent to check if processes are being debugged.                                                                                                                                                                                                                                                                                |
| **TA0006 Credential Access**                                                                                                                                                                                                                                                                                                                                                                                      ||
| T1555. Credentials from Password Stores                          | Black Basta uses Mimikatz to dump passwords.                                                                                                                                                                                                                                                                                                    |
| **TA0007 Discovery**                                                                                                                                                                                                                                                                                                                                                                                              ||
| T1087.002. Account Discovery: Domain Account                     | Used commands such as net user /domain and net group /domain.                                                                                                                                                                                                                                                                                   |
| T1016. System Network Configuration Discovery                    | Lists internal IP addresses to target in C:\\Windows\\pc\_list.txt -- typically found on the Domain Controller.                                                                                                                                                                                                                                  |
| T1082. System Information Discovery                              | Uses GetComputerName to query the computer name.                                                                                                                                                                                                                                                                                                |
| T1622. Debugger Evasion                                          | Uses IsDebuggerPresent to check if processes are being debugged.                                                                                                                                                                                                                                                                                |
| **TA0008 Lateral Movement**                                                                                                                                                                                                                                                                                                                                                                                       ||
| T1021.001. Remote Services: Remote Desktop Protocol              | Black Basta has used RDP for lateral movement.                                                                                                                                                                                                                                                                                                  |
| **TA0009 Collection**                                                                                                                                                                                                                                                                                                                                                                                             ||
| T1560.001. Archive Collected Data: Archive via Utility           |                                                                                                                                                                                                                                                                                                                                                 |
| **TA0010 Exfiltration**                                                                                                                                                                                                                                                                                                                                                                                           ||
| T1567. Exfiltration over Web Service                             |                                                                                                                                                                                                                                                                                                                                                 |
| **TA0011 Command and Control**                                                                                                                                                                                                                                                                                                                                                                                    ||
| T1219. Remote Access Software                                    | Black Basta has installed and used legitimate tools such as TeamViewer and AnyConnect on targeted systems.                                                                                                                                                                                                                                      |
| T1573. Encrypted Channel                                         | Uses Qakbot primarily and Cobalt Strike.                                                                                                                                                                                                                                                                                                        |
| **TA0040 Impact**                                                                                                                                                                                                                                                                                                                                                                                                 ||
| T1486. Data Encrypted for Impact                                 | Black Basta modifies the Desktop background by adding a .jpg in C:\\Temp and creating a registry key HKCU\\Control Panel\\Desktop. Additionally modifies the registry to change the icon of encrypted files.  It encrypts files excluding those with a .exe, .cmd, .bat and .com extension. Uses ChaCha20 or RSA-4096 to encrypt victims. |
| T1489. Service Stop                                              | Uses sc stop and taskkill to stop services.                                                                                                                                                                                                                                                                                                     |
| T1490. Inhibit System Recovery                                   | Black Basta deletes Volume Shadow Copies using vssadmin.                                                                                                                                                                                                                                                                                        |

*Table 1. Tactics, techniques and procedures for Black Basta activity.*

## Victimology

The ransomware group and its affiliate program reportedly compromised multiple large organizations, in sectors including consumer and industrial products; energy, resources and agriculture; manufacturing; utilities; transportation; government agencies; professional services and consulting; and real estate.

Black Basta operators also posted on dark web forums expressing interest in attacking organizations based in Australia, Canada, New Zealand, the U.K. and the U.S. Threat actors using the ransomware impacted organizations based in the U.S., Germany, Switzerland, Italy, France and the Netherlands (listed in descending order by numbers of allegedly breached organizations).
![Figure 5 shows the Black Basta post on dark web forums. It reads "We buy and monetize for a share of profits corporate network access credential from the following countries: the USA, Canada, the UK, Australia, and New Zealand."](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-88.png) Figure 5. Black Basta post on dark web forums.

The threat actor(s) responsible for Black Basta operate a cybercrime marketplace and victim name-and-shame blog. This site is hosted as a Tor hidden service, where the Black Basta ransomware group lists their victims' names, descriptions, percentage of stolen data which has been published, number of visits and any data exfiltrated. There were 75 victims listed on the leak site at the time of writing.
![Figure 6 shows the Black Basta News site where the threat actors post allegedly breached organizations (details redacted) and number of visits.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-89.png) Figure 6. Black Basta News site where the threat actors post allegedly breached organizations (details redacted) and number of visits.

## Courses of Action

Several adversarial techniques were observed in activity associated with Black Basta, and the following measures are suggested within Palo Alto Networks products and services to mitigate threats related to Black Basta ransomware, as well as other malware using similar techniques:

|---------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------|
| **Product / Service**     | **Course of Action**                                                                                                                          |
| **Initial Access**                                                                                                                                                       ||
| The below courses of action mitigate the following techniques:  Spear Phishing Attachment \[[T1566.001](https://attack.mitre.org/techniques/T1566/001)\]           ||
| THREAT PREVENTION         | Ensure that antivirus profiles are set to block on all decoders except 'imap' and 'pop3'                                                      |
| THREAT PREVENTION         | Ensure a secure antivirus profile is applied to all relevant security policies                                                                |
| NEXT-GENERATION FIREWALLS | Set up File Blocking                                                                                                                          |
| CORTEX XDR PREVENT        | Configure Malware Security Profile                                                                                                            |
| CORTEX XSOAR              | Deploy XSOAR Playbook -- Endpoint Malware Investigation                                                                                       |
| CORTEX XSOAR              | Deploy XSOAR Playbook -- Phishing Investigation -- Generic V2                                                                                 |
| **Execution**                                                                                                                                                            ||
| The below courses of action mitigate the following techniques:  Service Execution \[[T1569.002](https://attack.mitre.org/techniques/T1569/002)\], Windows Management Instrumentation \[[T1047](https://attack.mitre.org/techniques/T1047)\], PowerShell \[[T1059.001](https://attack.mitre.org/techniques/T1059/001)\] ||
| NEXT-GENERATION FIREWALLS | Ensure remote access capabilities for the User-ID service account are forbidden.                                                              |
| NEXT-GENERATION FIREWALLS | Ensure that User-ID is only enabled for internal trusted interfaces                                                                           |
| NEXT-GENERATION FIREWALLS | Ensure 'Service setting of ANY' in a security policy allowing traffic does not exist                                                          |
| NEXT-GENERATION FIREWALLS | Ensure that security policies restrict User-ID Agent traffic from crossing into untrusted zones                                               |
| NEXT-GENERATION FIREWALLS | Ensure that the User-ID service account does not have interactive logon rights                                                                |
| NEXT-GENERATION FIREWALLS | Ensure that 'Include/Exclude Networks' is used if User-ID is enabled                                                                          |
| NEXT-GENERATION FIREWALLS | Ensure 'Security Policy' denying any/all traffic to/from IP addresses on Trusted Threat Intelligence Sources exists                           |
| NEXT-GENERATION FIREWALLS | Ensure that the User-ID Agent has minimal permissions if User-ID is enabled                                                                   |
| NEXT-GENERATION FIREWALLS | Ensure application security policies exist when allowing traffic from an untrusted zone to a more trusted zone                                |
| CORTEX XDR PREVENT        | Configure Restrictions Security Profile                                                                                                       |
| **Persistence, Privilege Escalation, Defense Evasion**                                                                                                                   ||
| The below courses of action mitigate the following techniques:  Create Account \[[T1136](https://attack.mitre.org/techniques/T1136)\], Account Manipulation \[[T1098](https://attack.mitre.org/techniques/T1098)\], Regsvr32 \[[T1218.010](https://attack.mitre.org/techniques/T1218/010)\], File Deletion \[[T1070.004](https://attack.mitre.org/techniques/T1070/004)\], Disable or Modify Tools \[[T1562.001](https://attack.mitre.org/techniques/T1562/001)\], Modify Registry \[[T1112](https://attack.mitre.org/techniques/T1112)\], Deobfuscate/Decode Files or Information \[[T1140](https://attack.mitre.org/techniques/T1140)\], Disable or Modify System Firewall \[[T1562.004](https://attack.mitre.org/techniques/T1562/004)\], Windows Service \[[T1543.003](https://attack.mitre.org/techniques/T1543/003)\], DLL Search Order Hijacking \[[T1574.001](https://attack.mitre.org/techniques/T1574/001)\], Group Policy Modification \[[T1484.001](https://attack.mitre.org/techniques/T1484/001)\] ||
| NEXT-GENERATION FIREWALLS | Ensure that the User-ID Agent has minimal permissions if User-ID is enabled                                                                   |
| NEXT-GENERATION FIREWALLS | Ensure that security policies restrict User-ID Agent traffic from crossing into untrusted zones                                               |
| NEXT-GENERATION FIREWALLS | Ensure that the User-ID service account does not have interactive logon rights                                                                |
| NEXT-GENERATION FIREWALLS | Ensure that 'Include/Exclude Networks' is used if User-ID is enabled                                                                          |
| NEXT-GENERATION FIREWALLS | Ensure remote access capabilities for the User-ID service account are forbidden.                                                              |
| NEXT-GENERATION FIREWALLS | Ensure that User-ID is only enabled for internal trusted interfaces                                                                           |
| CORTEX XSOAR              | Deploy XSOAR Playbook -- Access Investigation Playbook                                                                                        |
| CORTEX XSOAR              | Deploy XSOAR Playbook -- Block Account Generic                                                                                                |
| CORTEX XSOAR              | Deploy XSOAR Playbook -- Impossible Traveler                                                                                                  |
| CORTEX XDR PREVENT        | Configure Host Firewall Profile                                                                                                               |
| CORTEX XDR PREVENT        | Enable Anti-Exploit Protection                                                                                                                |
| CORTEX XDR PREVENT        | Configure Restrictions Security Profile                                                                                                       |
| CORTEX XDR PREVENT        | Configure Behavioral Threat Protection under the Malware Security Profile                                                                     |
| CORTEX XDR PREVENT        | Enable Anti-Malware Protection                                                                                                                |
| **Credential Access**                                                                                                                                                    ||
| The below courses of action mitigate the following techniques:  Credentials from Password Stores \[[T1555](https://attack.mitre.org/techniques/T1555)\]            ||
| CORTEX XDR                | Cortex XDR monitors for behavioral events and files associated with credential access and exfiltration                                        |
| **Discovery**                                                                                                                                                            ||
| The below courses of action mitigate the following techniques:  System Network Configuration Discovery \[[T1016](https://attack.mitre.org/techniques/T1016)\], System Information Discovery \[[T1082](https://attack.mitre.org/techniques/T1082)\], Domain Account \[[T1087.002](https://attack.mitre.org/techniques/T1087/002)\] ||
| CORTEX XDR                | Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors                                             |
| **Lateral Movement**                                                                                                                                                     ||
| The below courses of action mitigate the following techniques:  Remote Desktop Protocol \[[T1021.001](https://attack.mitre.org/techniques/T1021/001)\]             ||
| NEXT-GENERATION FIREWALLS | Ensure 'Service setting of ANY' in a security policy allowing traffic does not exist                                                          |
| NEXT-GENERATION FIREWALLS | Ensure remote access capabilities for the User-ID service account are forbidden                                                               |
| NEXT-GENERATION FIREWALLS | Ensure that the User-ID Agent has minimal permissions if User-ID is enabled                                                                   |
| NEXT-GENERATION FIREWALLS | Ensure that User-ID is only enabled for internal trusted interfaces                                                                           |
| NEXT-GENERATION FIREWALLS | Ensure application security policies exist when allowing traffic from an untrusted zone to a more trusted zone                                |
| NEXT-GENERATION FIREWALLS | Ensure that the User-ID service account does not have interactive logon rights                                                                |
| NEXT-GENERATION FIREWALLS | Ensure that all zones have Zone Protection Profiles with all Reconnaissance Protection settings enabled, tuned and set to appropriate actions |
| NEXT-GENERATION FIREWALLS | Ensure that 'Include/Exclude Networks' is used if User-ID is enabled                                                                          |
| NEXT-GENERATION FIREWALLS | Ensure that security policies restrict User-ID Agent traffic from crossing into untrusted zones                                               |
| NEXT-GENERATION FIREWALLS | Ensure 'Security Policy' denying any/all traffic to/from IP addresses on Trusted Threat Intelligence Sources exists                           |
| CORTEX XDR PREVENT        | Configure Host Firewall Profile                                                                                                               |
| CORTEX XSOAR              | Deploy XSOAR Playbook -- Access Investigation Playbook                                                                                        |
| CORTEX XSOAR              | Deploy XSOAR Playbook -- Block Account Generic                                                                                                |
| **Collection**                                                                                                                                                           ||
| The below courses of action mitigate the following techniques:  Archive via Utility \[[T1560.001](https://attack.mitre.org/techniques/T1560/001)\]                 ||
| CORTEX XDR                | Monitors for behavioral events via BIOCs including the creation of zip archives                                                               |
| **Command and Control**                                                                                                                                                  ||
| The below courses of action mitigate the following techniques:  Remote Access Software \[[T1219](https://attack.mitre.org/techniques/T1219)\], Encrypted Channel \[[T1573](https://attack.mitre.org/techniques/T1573)\] ||
| CORTEX XSOAR              | Deploy XSOAR Playbook -- PAN-OS Query Logs for Indicators                                                                                     |
| CORTEX XSOAR              | Deploy XSOAR Playbook -- Block URL                                                                                                            |
| CORTEX XSOAR              | Deploy XSOAR Playbook -- Block IP                                                                                                             |
| NEXT-GENERATION FIREWALLS | Ensure that the Certificate used for Decryption is Trusted                                                                                    |
| NEXT-GENERATION FIREWALLS | Ensure application security policies exist when allowing traffic from an untrusted zone to a more trusted zone                                |
| NEXT-GENERATION FIREWALLS | Ensure 'Security Policy' denying any/all traffic to/from IP addresses on Trusted Threat Intelligence Sources Exists                           |
| NEXT-GENERATION FIREWALLS | Ensure 'SSL Forward Proxy Policy' for traffic destined to the Internet is configured                                                          |
| NEXT-GENERATION FIREWALLS | Ensure 'SSL Inbound Inspection' is required for all untrusted traffic destined for servers using SSL or TLS                                   |
| NEXT-GENERATION FIREWALLS | Ensure 'Service setting of ANY' in a security policy allowing traffic does not exist                                                          |
| THREAT PREVENTION         | Ensure DNS sinkholing is configured on all anti-spyware profiles in use                                                                       |
| THREAT PREVENTION         | Ensure passive DNS monitoring is set to enabled on all anti-spyware profiles in use                                                           |
| THREAT PREVENTION         | Ensure a secure anti-spyware profile is applied to all security policies permitting traffic to the Internet                                   |
| THREAT PREVENTION         | Ensure that antivirus profiles are set to block on all decoders except 'imap' and 'pop3'                                                      |
| THREAT PREVENTION         | Ensure an anti-spyware profile is configured to block on all spyware severity levels, categories, and threats                                 |
| THREAT PREVENTION         | Ensure a secure antivirus profile is applied to all relevant security policies                                                                |
| URL FILTERING             | Ensure secure URL filtering is enabled for all security policies allowing traffic to the Internet                                             |
| URL FILTERING             | Ensure all HTTP Header Logging options are enabled                                                                                            |
| URL FILTERING             | Ensure that PAN-DB URL Filtering is used                                                                                                      |
| URL FILTERING             | Ensure that URL Filtering uses the action of 'block' or 'override' on the URL categories                                                      |
| URL FILTERING             | Ensure that access to every URL is logged                                                                                                     |
| **Impact**                                                                                                                                                               ||
| The below courses of action mitigate the following techniques:  Data Encrypted for Impact \[[T1486](https://attack.mitre.org/techniques/T1486)\], Service Stop \[[T1489](https://attack.mitre.org/techniques/T1489)\], Inhibit System Recovery \[[T1490](https://attack.mitre.org/techniques/T1490)\] ||
| CORTEX XSOAR              | Deploy XSOAR Playbook -- Ransomware Manual for incident response.                                                                             |
| CORTEX XSOAR              | Deploy XSOAR Playbook -- Palo Alto Networks Endpoint Malware Investigation                                                                    |

## Conclusion

Black Basta ransomware operators have been active since at least April 2022. Although their RaaS has only been active for the past couple of months it had compromised at least 75 organizations at the time of this publication. Due to the high-profile nature and steady stream of Black Basta attacks identified globally in 2022, the operators and/or affiliates behind the service likely will continue to attack and extort organizations.

Palo Alto Networks helps detect and prevent Black Basta ransomware in the following ways:

* [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire): All known samples are identified as malware.
* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr):
  * Identifies indicators associated with Black Basta.
  * Anti-Ransomware Module blocks Black Basta encryption behaviors on Windows.
  * Local Analysis detection for Black Basta binaries on Windows and Linux.
  * Behavioral Threat Prevention prevents Black Basta behaviors.
* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall): DNS Signatures detect the known C2 domains, which are also categorized as malware in [Advanced](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)[URL Filtering](https://www.paloaltonetworks.com/products/threat-detection-and-prevention/web-security).

If you think you may have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call North America Toll-Free: 866.486.4842 (866.4.UNIT42), EMEA: +31.20.299.3130, APAC: +65.6983.8730, or Japan: +81.50.1790.0200.

Indicators of compromise and Black Basta-associated TTPs can be found in the Black Basta [ATOM](https://unit42.paloaltonetworks.com/atoms/blackbasta-ransomware/).

Palo Alto Networks has shared these findings, including file samples and indicators of compromise, with our fellow Cyber Threat Alliance members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Additional Resources

* [2022 Unit 42 Ransomware Threat Report](https://start.paloaltonetworks.com/unit-42-ransomware-threat-report.html)
* [2022 Unit 42 Incident Response Report](https://start.paloaltonetworks.com/2022-unit42-incident-response-report)

Back to top

### Tags

* [Black Basta ransomware](https://unit42.paloaltonetworks.com/tag/black-basta-ransomware/ "Black Basta ransomware")
* [Dark Scorpius](https://unit42.paloaltonetworks.com/tag/dark-scorpius/ "Dark Scorpius")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Legitimate SaaS Platforms Being Used to Host Phishing Attacks](https://unit42.paloaltonetworks.com/platform-abuse-phishing/ "Legitimate SaaS Platforms Being Used to Host Phishing Attacks")

### Table of Contents

* 

### Related Articles

* [Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/ "article - table of contents")
* [Ransomware Review: First Half of 2024](https://unit42.paloaltonetworks.com/unit-42-ransomware-leak-site-data-analysis/ "article - table of contents")
* [Chinese PlugX Malware Hidden in Your USB Devices?](https://unit42.paloaltonetworks.com/plugx-variants-in-usbs/ "article - table of contents")

## Related Ransomware Resources

![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) April 17, 2026 [#### Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/tag/apk/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/tag/ddos-attacks/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/ "Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)")  
  ![Pictorial representation of RaaS RansomHouse. Digital representation of cybersecurity concept with a padlock superimposed over computer circuit boards, symbolizing data protection and encryption technologies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/06_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 17, 2025 [#### From Linear to Complex: An Upgrade in RansomHouse Encryption](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/)

* [ESXi](https://unit42.paloaltonetworks.com/tag/esxi/ "ESXi")

* [Jolly Scorpius](https://unit42.paloaltonetworks.com/tag/jolly-scorpius/ "Jolly Scorpius")

* [RansomHouse](https://unit42.paloaltonetworks.com/tag/ransomhouse/ "RansomHouse")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/ "From Linear to Complex: An Upgrade in RansomHouse Encryption")  
  ![Pictorial representation of 01flip ransomware written in Rust. Digital artwork of a pixelated U.S. dollar bill disintegrating into small blocks against a blue data matrix background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 10, 2025 [#### 01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/)

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [CL-CRI-103](https://unit42.paloaltonetworks.com/tag/cl-cri-103/ "CL-CRI-103")

* [Cryptocurrency](https://unit42.paloaltonetworks.com/tag/cryptocurrency/ "Cryptocurrency")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "01flip: Multi-Platform Ransomware Written in Rust")  
  ![Pictorial representation of malicious LLMs. Close-up view of a digital wall displaying various glowing icons, representing a high-tech network interface.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/AdobeStock_1270203474-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 25, 2025 [#### The Dual-Use Dilemma of AI: Malicious LLMs](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/tag/credential-harvesting/ "Credential Harvesting")

* [Data exfiltration](https://unit42.paloaltonetworks.com/tag/data-exfiltration/ "data exfiltration")

* [LLM](https://unit42.paloaltonetworks.com/tag/llm/ "LLM")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/ "The Dual-Use Dilemma of AI: Malicious LLMs")  
  ![Constellation image representing the constellation schema used by Palo Alto Networks Unit 42 to track nation-state and cybercrime threat actor groups](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/Generic-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) August 1, 2025 [#### Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/)

* [Academic Serpens](https://unit42.paloaltonetworks.com/tag/academic-serpens/ "Academic Serpens")

* [Agent Serpens](https://unit42.paloaltonetworks.com/tag/agent-serpens/ "Agent Serpens")

* [Agonizing Serpens](https://unit42.paloaltonetworks.com/tag/agonizing-serpens/ "Agonizing Serpens")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/ "Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)")  
  ![Pictorial representation of Unit 42 threat attribution system. Illustration featuring a white triangle centered within an abstract cosmic background of purple and blue swirls and stars.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/Generic-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) July 31, 2025 [#### Introducing Unit 42's Attribution Framework](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Bookworm](https://unit42.paloaltonetworks.com/tag/bookworm/ "Bookworm")

* [Nomenclature](https://unit42.paloaltonetworks.com/tag/nomenclature/ "nomenclature")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/ "Introducing Unit 42’s Attribution Framework")  
  ![Pictorial representation of the ransomware landscape. Digital artwork of a disintegrating U.S. dollar bill with pixelated effects on a cyber-inspired background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-report-white-1.svg)Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/) April 23, 2025 [#### Extortion and Ransomware Trends January-March 2025](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/)

* [BianLian](https://unit42.paloaltonetworks.com/tag/bianlian/ "BianLian")

* [Akira ransomware](https://unit42.paloaltonetworks.com/tag/akira-ransomware/ "Akira ransomware")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/ "Extortion and Ransomware Trends January-March 2025")  
  ![A pictorial representation of Akira ransomware, distributed by Howling Scorpius. A person's hand typing on a keyboard with a digital screen displaying the word "password" highlighted in blue, set against a backdrop of various cybersecurity interface graphics.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/09_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) December 2, 2024 [#### Threat Assessment: Howling Scorpius (Akira Ransomware)](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/)

* [Howling Scorpius](https://unit42.paloaltonetworks.com/tag/howling-scorpius/ "Howling Scorpius")

* [Leak site](https://unit42.paloaltonetworks.com/tag/leak-site/ "Leak site")

* [Torrenting](https://unit42.paloaltonetworks.com/tag/torrenting/ "torrenting")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/ "Threat Assessment: Howling Scorpius (Akira Ransomware)")  
  ![Pictorial representation of a threat like BlackSuit ransomware. An illustration of a modern workspace with a laptop displaying cybersecurity icons, surrounded by stacks of coins and a credit card, all depicted in a neon, digital art style.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/04_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) November 20, 2024 [#### Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware](https://unit42.paloaltonetworks.com/threat-assessment-blacksuit-ransomware-ignoble-scorpius/)

* [BlackSuit ransomware](https://unit42.paloaltonetworks.com/tag/blacksuit-ransomware/ "BlackSuit ransomware")

* [Construction](https://unit42.paloaltonetworks.com/tag/construction/ "construction")

* [Education](https://unit42.paloaltonetworks.com/tag/education/ "Education")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-assessment-blacksuit-ransomware-ignoble-scorpius/ "Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware")  
  ![A representation of a threat group like Jumpy Pisces. Illustrative image featuring two fish and the Pisces constellation superimposed on a stylized, abstract background with flowing purple waves and a starry night sky.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/10/Pisces-NK-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) October 30, 2024 [#### Jumpy Pisces Engages in Play Ransomware](https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/)

* [North Korea](https://unit42.paloaltonetworks.com/tag/north-korea/ "North Korea")

* [Jumpy Pisces](https://unit42.paloaltonetworks.com/tag/jumpy-pisces/ "Jumpy Pisces")

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/ "Jumpy Pisces Engages in Play Ransomware")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
