EXPOSING YOUR RANSOMWARE adversaries

Threat Actor Index: Knowledge is Power

Welcome to the Halcyon Ransomware Threat Actor Index, a comprehensive catalog of the most prominent threat actors and ransomware families, to shed light on the ransomware ecosystem. Discover their techniques, tactics, procedures and targeted industries. Make informed decisions, and stay resilient in the face of ransomware.
THREAT ACTOR:

Black Basta

EMERGENCE DATE:
April 2022
2022-04-01
CATEGORiZATION:
Ransomware-as-a-Service
THREAT LEVEL:
5
OVERVIEW DESCRIPTION:

Black Basta emerged in April 2022 as an advanced Ransomware-as-a-Service (RaaS) operation employing double extortion tactics through file encryption and data exfiltration. Targeting healthcare, finance, and manufacturing sectors, the group executed numerous attacks across North America, Europe, and Australia using a closed affiliate model with stringent operational protocols. February 2025 leaked internal communications revealed the group's sophisticated operational structure, including call centers, victim research capabilities, and connections to disbanded Conti operations.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Explore Recent Threat Group Activity

View All
Top Ransomware Groups
Power Rankings: Ransomware Malicious Quartile
Ransomware attacks continue to be extremely lucrative, with ransom demands and recovery costs bleeding victim organizations for millions of dollars.
Cookie Consent

By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.