- Chatlogfiles from Black Basta Ransomware Group were leaked on Telegram
- The leaks claim that this is a response to the group that attacks Russian banks
- The data contains valuable information about how the group works
Internal chatlog files describing the internal feature of the Black Basta Ransomware Group were just leaked online.
An individual (or a group) with the alias utilization has apparently drawn the information from Matrix, an open source, decentralized communication protocol used for safe and real -time messages. Matrix is often used for encrypted chats, making it popular with cybersecurity -subject people, advocates of privacy, but also, unfortunately cyber criminals.
ExploitWhispers first uploaded the archive to MEGA, but after it was pulled down, they created a dedicated telegram channel and leaked it there.
Targeting of domestic banks
“A place to discuss the most important news about Black Basta, one of the largest groups of health workers in Russia, who recently hacked domestic banks,” said Delicious on Telegram. “With such questions, we can say that they crossed the border so that we are dedicated to revealing the truth and exploring the next steps in Black Basta. Here you can find information that you can trust and read everything the most important thing in a channel. “
The one who exploits who is, they were not happy with what Black Basta did in recent times. They can either be an unhappy member or a security researcher.
In any case, Black Basta was allegedly targeted at Russian banks, which did not sit well with them.
Leakage covers chats between September 2023 and September 2024 and contains valuable information about the group’s internal structure.
A person named Lapa is one of the administrators. Cortes is a threat actor with links to the Qakbot group, yy is the principal administrator and Trump is the key figure. There are some indications that Trump’s real name may be Oleg Nefedov.
It also shows the group’s phishing templates, e emails, cryptocurrency addresses, data trants, victim information and more.
Analysis of Data Dump said Bleeping computer that the archive also contains 367 unique Zoominfo links, which may indicate the number of companies that are targeted during this period.
Via Bleeping computer