WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 Ransomware Awareness – Black Basta Borrowing from the Best
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Ransomware Awareness – Black Basta Borrowing from the Best

Author: Jennifer Walker

Created: Tuesday, June 28, 2022 - 19:09

Categories: Cybersecurity

A new ransomware group has targeted almost 50 victims within the two months of its emergence in the wild and it hasn’t even begun its marketing or affiliate campaign yet. The Black Basta ransomware first became operational in April 2022 and is the latest ransomware gang seeking to extort enterprises. Researchers believe Black Basta’s quick rise to prominence is due to its potential close ties with and copying the techniques of other successful ransomware groups such as Conti and REvil. Another factor of Black Basta’s early achievements is likely its partnership with Qakbot/QBot malware. Likewise, it didn’t take long for the ransomware to advance its capabilities by incorporating the encrypting of VMware ESXi virtual machines running on enterprise Linux servers into its arsenal. Despite its onset of aggressive activity, Black Basta seems to have at least one downfall. According to Trend Micro, it needs administrator rights to run. This “feature” alone makes a great case for maintaining separate user profiles and never staying perpetually logged in with an account profile that has administrator rights. For more information on how to defend against ransomware, visit CISA’s Stopransomware.gov. Read more at SecurityWeek or read the full report at Cybereason.

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar