CVE-2024-26169
published 2024-03-12CVE-2024-26169: Windows Error Reporting Service Elevation of Privilege Vulnerability
PriorityP185high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2024-07-04
Exploited in the wild
EPSS
4.01%
89.4th percentile
Windows Error Reporting Service Elevation of Privilege Vulnerability
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20526 | 10.0.10240.20526 |
| microsoft | windows_10_1607 | < 10.0.14393.6796 | 10.0.14393.6796 |
| microsoft | windows_10_1809 | < 10.0.17763.5576 | 10.0.17763.5576 |
| microsoft | windows_10_21h2 | < 10.0.19044.4170 | 10.0.19044.4170 |
| microsoft | windows_10_22h2 | < 10.0.19045.4170 | 10.0.19045.4170 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20526 | 10.0.10240.20526 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.6796 | 10.0.14393.6796 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.5576 | 10.0.17763.5576 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.5576 | 10.0.17763.5576 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.4170 | 10.0.19044.4170 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.4170 | 10.0.19045.4170 |
| microsoft | windows_11_21h2 | < 10.0.22000.2836 | 10.0.22000.2836 |
| microsoft | windows_11_22h2 | < 10.0.22621.3296 | 10.0.22621.3296 |
| microsoft | windows_11_23h2 | < 10.0.22631.3296 | 10.0.22631.3296 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.2836 | 10.0.22000.2836 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.3296 | 10.0.22621.3296 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.3296 | 10.0.22631.3296 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.3296 | 10.0.22631.3296 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.21871 | 6.3.9600.21871 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.6796 | 10.0.14393.6796 |
| microsoft | windows_server_2019 | < 10.0.17763.5576 | 10.0.17763.5576 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.5576 | 10.0.17763.5576 |
| microsoft | windows_server_2022 | < 10.0.20348.2333 | 10.0.20348.2333 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2024-26169 exploit tool had a February 27 compilation timestamp in one variant, and December 18, 2023 in a second sample — suggesting potential zero-day use by Black Basta (Cardinal/UNC4394/Storm-1811) before the March 2024 patch ↗
- →CVE-2024-26169 is a local privilege escalation in Windows Error Reporting Service exploited by Black Basta ransomware operators to gain SYSTEM privileges from a standard user account ↗
- →Threat actor cluster tracking: Black Basta operators exploiting CVE-2024-26169 are also tracked as Cardinal, UNC4394, and Storm-1811 ↗
- ·Compilation timestamps on the exploit tool samples can be modified by attackers, making zero-day exploitation findings inconclusive ↗
- ·Microsoft's official exploit status lists the vulnerability as not publicly disclosed and not exploited at time of advisory publication, which conflicts with Symantec/Kaspersky field observations ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v6c8-v4w6-r8wx: Windows Error Reporting Service Elevation of Privilege Vulnerability
ghsa_unreviewed·2024-03-12
CVE-2024-26169 [HIGH] CWE-269 GHSA-v6c8-v4w6-r8wx: Windows Error Reporting Service Elevation of Privilege Vulnerability
Windows Error Reporting Service Elevation of Privilege Vulnerability
VulnCheck
Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
vulncheck·2024·CVSS 7.8
CVE-2024-26169 [HIGH] CWE-269 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://symantec-enterprise-blogs.security.com/threat-intelligence/black-basta-ransomware-zero-day; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://redalert.nshc.net/2024/07/30/monthly-threat-actor-group-intelligence-report-june-2024-kor/; https://www.tenable.com/blog/cybersecurit
CISA
Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
cisa·2024-06-13·CVSS 7.8
CVE-2024-26169 [HIGH] CWE-269 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
Vulnerability: Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
Affected: Microsoft Windows
Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
Required Action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26169; https://nvd.nist.gov/vuln/detail/CVE-2024-26169
Remediation Due Date: 2024-07-04
Microsoft
Windows Error Reporting Service Elevation of Privilege Vulnerability
vendor_msrc·2024-03-12·CVSS 7.8
CVE-2024-26169 [HIGH] CWE-269 Windows Error Reporting Service Elevation of Privilege Vulnerability
Windows Error Reporting Service Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Error Reporting: Windows Error Reporting
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5035849
Reference: https://support.microsoft.com/help/5035849
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5035857
Reference: https://support.microsoft.com/help/5035857
Reference: https://catalog
No detection rules found.
No public exploits indexed.
Greynoiseio
GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
blogs_greynoiseio·2025-02-26·CVSS 9.8
[CRITICAL] GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Qualys
Defense Lessons From the Black Basta Ransomware Playbook
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook
## Table of Contents
Know Your Enemys Playbook
Attackers Move Fast
How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against evolving
Qualys
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
#### Table of Contents
- Know Your Enemys Playbook
- Attackers Move Fast
- How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against ev
Qualys
What Is Black Basta Ransomware and How to Mitigate Attack
blogs_qualys·2024-09-19·CVSS 5.5
[MEDIUM] What Is Black Basta Ransomware and How to Mitigate Attack
## Table of Contents
Introduction
Tools, Techniques, and Vulnerabilities Exploited
Technical Analysis
Effective Hunting Queries
Mapping MITRE ATT&CK: Key Techniques
Indicators of Compromise (IoC)
Stay to the Left of Boom of Emerging Threats
## Introduction
Black Basta is a ransomware group operating as ransomware-as-a-service (RaaS), first spotted in April 2022. It is known to use double extortion techniques where the group demands payment for the decryption and non-release of stolen data. Earlier versions of Black Basta share many similarities with Conti Ransomware.
A wide range of industries and critical infrastructure in North America, Europe, and Australia have been impacted by Black Basta. To date, 500+ organizations have been affected globally by Black Basta affiliates gain
Securelist
IT threat evolution in Q2 2024. Non-mobile statistics
blogs_securelist·2024-09-03
IT threat evolution in Q2 2024. Non-mobile statistics
Table of Contents
Quarterly figures
Ransomware
Quarterly trends and highlights
Law enforcement successes
Attacks exploiting vulnerabilities
Most active groups
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
Top 10 countries and territories targeted by ransomware Trojans
Top 10 most common families of ransomware Trojans
Miners
Number of new modifications
Number of users attacked by miners
Geography of attacked users
Top 10 countries and territories targeted by miners
Attacks on macOS
Top 20 threats to macOS
Geography of threats for macOS
Top 10 countries and territories by share of attacked users
IoT threat statistics
Top 10 threats delivered to IoT devices
Attacks on IoT honeypots
Attacks via web resources
Coun
Securelist
Statistics on PC malware for Q2 2024
blogs_securelist·2024-09-03·CVSS 7.8
[HIGH] Statistics on PC malware for Q2 2024
Table of Contents
- Quarterly figures
- Ransomware
- Miners
- Attacks on macOS
- IoT threat statistics
- Attacks via web resources
- Local threats
Authors
- AMR
The statistics presented here are based on detection verdicts by Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
In Q2 2024:
- Kaspersky solutions blocked over 664 million attacks from various internet sources.
- The web antivirus reacted to 113.5 million unique URLs.
- The file antivirus blocked over 27 million malicious and unwanted objects.
- Almost 86,000 users encountered ransomware attacks.
- Nearly 12% of all ransomware victims whose data was published on DLSs (data leak sites) were affected by the Play ransomware group.
- Nearly 340,000 users faced
Securelist
Exploits and vulnerabilities in Q2 2024
blogs_securelist·2024-08-21·CVSS 7.8
CVE-2024-26169 [HIGH] Exploits and vulnerabilities in Q2 2024
Table of Contents
Statistics on registered vulnerabilities
Vulnerability exploitation statistics
Windows and Linux vulnerability exploitation
Most common exploits
Vulnerability exploitation in APT attacks
Exploiting vulnerable drivers to attack operating systems
BYOVD attack tools
Interesting vulnerabilities
CVE-2024-26169 (WerKernel.sys)
CVE-2024-26229 (csc.sys)
CVE-2024-4577 (PHP CGI)
Takeaways and recommendations
Authors
Vitaly Morgunov
Alexander Kolesnikov
Q2 2024 was eventful in terms of new interesting vulnerabilities and exploitation techniques for applications and operating systems. Attacks through vulnerable drivers have become prevalent as a general means of privilege escalation in the operating system. Such attacks are notable in that the vulnerability does not h
Securelist
Analyzing the vulnerability landscape in Q2 2024
blogs_securelist·2024-08-21·CVSS 7.8
CVE-2024-26169 [HIGH] Analyzing the vulnerability landscape in Q2 2024
Table of Contents
- Statistics on registered vulnerabilities
- Vulnerability exploitation statistics
- Vulnerability exploitation in APT attacks
- Exploiting vulnerable drivers to attack operating systems
- Interesting vulnerabilities
- CVE-2024-26169 (WerKernel.sys)
- CVE-2024-26229 (csc.sys)
- CVE-2024-4577 (PHP CGI)
- Takeaways and recommendations
Authors
- Vitaly Morgunov
- Alexander Kolesnikov
Q2 2024 was eventful in terms of new interesting vulnerabilities and exploitation techniques for applications and operating systems. Attacks through vulnerable drivers have become prevalent as a general means of privilege escalation in the operating system. Such attacks are notable in that the vulnerability does not have to be fresh, since attackers themselves deliver unpatched drivers to t
Unit42
Ransomware Review: First Half of 2024
blogs_unit42·2024-08-09·CVSS 9.1
CVE-2018-13379 [CRITICAL] Ransomware Review: First Half of 2024
Threat Research Center
Trend Reports
Ransomware
## Ransomware Review: First Half of 2024
Amanda Tanner
Kristopher Bleich
Published: August 9, 2024
Cybercrime
Ransomware
Trend Reports
Alpha
ALPHV
Ambitious Scorpius
Anemic Scorpius
AvosLocker
Bashful Scorpius
Black Basta
Blackcat
Blackout
BreachForums
Burning Scorpius
Buzzing Scorpius
Chubby Scorpius
CL0P
CVE-2018-13379
CVE-2020-1472
CVE-2024-1708
CVE-2024-1709
CVE-2024-26169
CVE-2024-27198
CVE-2024-4577
Dark Scorpius
DoNex
DragonForce
Drowsy Scorpius
Flighty Scorpius
GhostSec
Healthcare
Hive
Hunters International
Ignoble Scorpius
Karakurt
KelvinSecurity
Leak site
LockBit
Losttrust
LukaLocker
Manufacturing
Muddled Libra
Mushy Scorpius
MyData
NoEscape
Nokoyawa
Qilin
Quilong
Ragnar Locke
Unit42
Ransomware Review: First Half of 2024
blogs_unit42·2024-08-09
Ransomware Review: First Half of 2024
## Executive Summary
Unit 42 monitors ransomware and extortion leak sites closely to keep tabs on threat activity. We reviewed compromise announcements from 53 dedicated leak sites in the first half of 2024 and found 1,762 new posts. This averages to approximately 294 posts a month and almost 68 posts a week. Of the 53 ransomware groups whose leak sites we monitored, six of the groups accounted for more than half of the compromises observed.
In February, we reported a 49% increase year-over-year in alleged victims posted on ransomware leak sites. So far, in 2024, comparing the first half of 2023 to the first half of 2024, we see an even further increase of 4.3%. The higher level of activity observed in 2023 was no fluke.
Activity from groups like Ambitious Scorpius (distributors of Blac
Tenable
Cybersecurity Snapshot: Data Breach Costs Rise, as Ransomware Attacks Fall, Reports Find
blogs_tenable·2024-08-02
Cybersecurity Snapshot: Data Breach Costs Rise, as Ransomware Attacks Fall, Reports Find
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
CISA warns of Windows bug exploited in ransomware attacks
blogs_bleepingcomputer·2024-06-14·CVSS 7.8
CVE-2024-26169 [HIGH] CISA warns of Windows bug exploited in ransomware attacks
## CISA warns of Windows bug exploited in ransomware attacks
## Sergiu Gatlan
As revealed in a report published earlier this week, Symantec security researchers found evidence that the operators of the Black Basta ransomware gang (the Cardinal cybercrime group, also tracked as UNC4394 and Storm-1811) were likely behind attacks abusing the flaw as a zero-day.
They discovered that one variant of the CVE-2024-26169 exploit tool deployed in these attacks had a February 27 compilation timestamp, while a second sample was built even earlier, on December 18, 2023.
As Symantec admitted in their report, such timestamps can easily be modified, rendering their zero-day exploitation findings inconclusive. However, there is little to no motivation for the attackers to do so, making this scenario un
Bleepingcomputer
Microsoft March 2024 Patch Tuesday fixes 60 flaws, 18 RCE bugs
blogs_bleepingcomputer·2024-03-12·CVSS 5.5
[MEDIUM] Microsoft March 2024 Patch Tuesday fixes 60 flaws, 18 RCE bugs
## Microsoft March 2024 Patch Tuesday fixes 60 flaws, 18 RCE bugs
## Lawrence Abrams
24 Elevation of Privilege Vulnerabilities
3 Security Feature Bypass Vulnerabilities
18 Remote Code Execution Vulnerabilities
6 Information Disclosure Vulnerabilities
6 Denial of Service Vulnerabilities
2 Spoofing Vulnerabilities
The total count of 60 flaws does not include 4 Microsoft Edge flaws fixed on March 7th.
Furthermore, Microsoft did not disclose any zero-days as part of today's Patch Tuesday updates.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5035853 update and the Windows 10 KB5035845 update .
## Flaws of interest
This month's Patch Tuesday does not fix any zero-day vulnerabilities but does include some in
Trendmicro
The March 2024 Security Update Review
blogs_trendmicro·2024-03-12
The March 2024 Security Update Review
# The March 2024 Security Update Review
Get the March 2024 security update and review.
By: Dustin Childs
2024/03/12
Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for March 2024
For March, Adobe released six patches addressing 56 vulnerabilities in Adobe Experience Manager, Premiere Pro, ColdFusion, Adobe Bridge, Lightroom, and Adobe Animate. Two of these bugs were submitted through the ZDI Program. The largest is the update for Experience Manager, which addresses 44 CVEs.
Trendmicro
The March 2024 Security Update Review
blogs_trendmicro·2024-03-12
The March 2024 Security Update Review
## The March 2024 Security Update Review
Get the March 2024 security update and review.
By: Dustin Childs 2024/03/12 Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for March 2024
For March, Adobe released six patches addressing 56 vulnerabilities in Adobe Experience Manager, Premiere Pro, ColdFusion, Adobe Bridge, Lightroom, and Adobe Animate. Two of these bugs were submitted through the ZDI Program. The largest is the update for Experience Manager , which addresses 44 CVEs.
Trendmicro
The March 2024 Security Update Review
blogs_trendmicro·2024-03-12
The March 2024 Security Update Review
## The March 2024 Security Update Review
Get the March 2024 security update and review.
By: Dustin Childs Mar 12, 2024 Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for March 2024
For March, Adobe released six patches addressing 56 vulnerabilities in Adobe Experience Manager, Premiere Pro, ColdFusion, Adobe Bridge, Lightroom, and Adobe Animate. Two of these bugs were submitted through the ZDI Program. The largest is the update for Experience Manager , which addresses 44 CVE
Trendmicro
The March 2024 Security Update Review
blogs_trendmicro·2024-03-12
The March 2024 Security Update Review
## The March 2024 Security Update Review
Get the March 2024 security update and review.
By: Dustin Childs Mar 12, 2024 Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for March 2024
For March, Adobe released six patches addressing 56 vulnerabilities in Adobe Experience Manager, Premiere Pro, ColdFusion, Adobe Bridge, Lightroom, and Adobe Animate. Two of these bugs were submitted through the ZDI Programme. The largest is the update for Experience Manager , which addresses 44 C
Sentinelone
Black Basta
blogs_sentinelone·2022-11-30
Black Basta
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Sentinelone
Black Basta
blogs_sentinelone
Black Basta
# Black Basta Ransomware: In-Depth Analysis, Detection, and Mitigation
## Summary of Black Basta Ransomware
Black Basta first emerged in early 2022. The ransomware family is an evolution of the Hermes/Ryuk/Conti families. Black Basta was heavily advertised in underground cybercrime markets. Black Basta practices double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data. There are Windows and LInux variants of Black Basta ransomware. The group is responsible for hundreds of attacks against global targets of varying sectors.
February 2025 Update: Nearly a year’s worth of Black Basta chat logs have been released on Telegram, providing detailed insight into the groups operational workflow, reconnaissance activities, and specific userID and details o
2024-03-12
Published
2024-06-13
Added to CISA KEV
Exploited in the wild