Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Leaked Black Basta Chats Suggest Russian Officials Aided Leader’s Escape from Armenia

The Hacker News by The Hacker News
March 19, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Mar 19, 2025Ravie LakshmananCybercrime / Threat Intelligence

The recently leaked trove of internal chat logs among members of the Black Basta ransomware operation has revealed possible connections between the e-crime gang and Russian authorities.

The leak, containing over 200,000 messages from September 2023 to September 2024, was published by a Telegram user @ExploitWhispers last month.

According to an analysis of the messages by cybersecurity company Trellix, Black Basta’s alleged leader Oleg Nefedov (aka GG or AA) may have received help from Russian officials following his arrest in Yerevan, Armenia, in June 2024, allowing him to escape three days later.

Cybersecurity

In the messages, GG claimed that he contacted high-ranking officials to pass through a “green corridor” and facilitate the extraction.

“This knowledge from chat leaks makes it difficult for the Black Basta gang to completely abandon the way they operate and start a new RaaS from scratch without a reference to their previous activities,” Trellix researchers Jambul Tologonov and John Fokker said.

Among other notable findings include –

  • The group likely has two offices in Moscow
  • The group utilizes OpenAI ChatGPT for composing fraudulent formal letters in English, paraphrasing text, rewriting C#-based malware in Python, debugging code, and collecting victim data
  • Some members of the group overlap with other ransomware operations like Rhysida and CACTUS
  • The developer of PikaBot is a Ukrainian national who goes by the online alias mecor (aka n3auxaxl) and that it took Black Basta a year to develop the malware loader post QakBot‘s disruption
  • The group rented DarkGate from Rastafareye and used Lumma Stealer to steal credentials as well as additional malware
  • The group developed a post-exploitation command-and-control (C2) framework called Breaker to establish persistence, evade detection, and maintain access across network systems
  • GG worked with mecor on new ransomware that’s derived from Conti’s source code, leading to the release of a prototype written in C, indicating a possible rebranding effort

The development comes as EclecticIQ revealed Black Basta’s work on a brute-forcing framework dubbed BRUTED that’s designed to perform automated internet scanning and credential stuffing against edge network devices, including widely used firewalls and VPN solutions in corporate networks.

Cybersecurity

There is evidence to suggest that the cybercrime crew has been using the PHP-based platform since 2023 to perform large-scale credential-stuffing and brute-force attacks on target devices, allowing the threat actors to gain visibility into victim networks.

“BRUTED framework enables Black Basta affiliates to automate and scale these attacks, expanding their victim pool and accelerating monetization to drive ransomware operations,” security researcher Arda Büyükkaya said.

“Internal communications reveal that Black Basta has heavily invested in the BRUTED framework, enabling rapid internet scans for edge network appliances and large-scale credential stuffing to target weak passwords.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
Enterprise Connect 2025: AI-Powered Products From Cisco, RingCentral, Zoom And More

Enterprise Connect 2025: AI-Powered Products From Cisco, RingCentral, Zoom And More

Recommended.

HPE ‘Laps’ Networking Rivals With Distributed Services Switch Portfolio Update; New Wi-Fi 7 APs

HPE ‘Laps’ Networking Rivals With Distributed Services Switch Portfolio Update; New Wi-Fi 7 APs

May 28, 2025
GDT enhances client-first managed services platform powered by Webex to redefine the future of customer experience

GDT enhances client-first managed services platform powered by Webex to redefine the future of customer experience

October 28, 2025

Trending.

Spirit of openness helps banks get serious about stopping scams | Computer Weekly

Spirit of openness helps banks get serious about stopping scams | Computer Weekly

April 10, 2025
Weibo Publishes 2025 Environmental, Social and Governance Report

Weibo Publishes 2025 Environmental, Social and Governance Report

April 28, 2026
It Takes 2 Minutes to Hack the EU’s New Age-Verification App

It Takes 2 Minutes to Hack the EU’s New Age-Verification App

April 18, 2026
Chunghwa Telecom 2025 Form 20-F filed with the U.S. SEC

Chunghwa Telecom 2025 Form 20-F filed with the U.S. SEC

April 15, 2026
2025 Wired, WLAN Gartner Magic Quadrant: Cisco Drops To Challenger, NaaS Specialists Join

2025 Wired, WLAN Gartner Magic Quadrant: Cisco Drops To Challenger, NaaS Specialists Join

July 14, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio