
CISA and FBI Issue Critical Advisory on Black Basta Ransomware Resurgence Following Major Healthcare Breach
A joint federal advisory (AA24-131A) details Black Basta's shift toward exploiting ConnectWise vulnerabilities and utilizing 'Backstab' to neutralize EDR, following the catastrophic Ascension Health breach.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- North America
- Confidence:
- Confirmed
- CVE:
- CVE-2024-1709
- Source:
- CISA/FBI Joint Advisory
- Read Time:
- 5 min
Executive Summary
Within the last 48 hours, the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have escalated their warnings regarding the Black Basta ransomware-as-a-service (RaaS) group. This follows the high-profile breach of Ascension Health, which forced 140 hospitals across 19 states to revert to manual paper-based workflows. Intelligence suggests that Black Basta has now successfully targeted over 500 organizations globally, focusing heavily on critical infrastructure. The group's recent shift in tactics, specifically the exploitation of public-facing application vulnerabilities and the use of specialized anti-EDR tools, represents a significant escalation in their operational capabilities.
Threat Analysis
Black Basta emerged in early 2022 and has quickly ascended to become one of the most prolific threat actors in the double-extortion landscape. Unlike more public RaaS groups, Black Basta is believed to be a 'closed' operation, selectively vetting its affiliates. The group typically targets medium-to-large enterprises, with a recent focus on the healthcare, manufacturing, and transportation sectors. Their extortion methodology involves both the encryption of critical assets and the exfiltration of sensitive data, with a standard 'pressure' window of 10-12 days before data publication on their TOR-based leak site. Analysis of recent campaigns indicates a high level of operational security and technical sophistication, likely drawing talent from the remnants of the Conti and FIN7 syndicates.
Technical Details
Initial access in recent campaigns has been achieved through a combination of sophisticated spear-phishing and the exploitation of CVE-2024-1709, a critical authentication bypass vulnerability in ConnectWise ScreenConnect. Once inside, the actors utilize 'Backstab,' a malicious utility designed to disable endpoint detection and response (EDR) solutions by leveraging a legitimate, but vulnerable, signed driver (often from Sysinternals Process Explorer) to terminate security processes.
Lateral movement is frequently conducted using PsExec and specialized network scanning tools like NetScan. Data exfiltration is streamlined through the use of RClone, configured to push sensitive directories to cloud storage services like Mega.nz. The final payload employs a hybrid encryption scheme: files are encrypted using the ChaCha20 algorithm with an RSA-4096 public key. The group has also been observed deleting Volume Shadow Copies and system backups to maximize the impact of the encryption phase.
Attribution Assessment
Evidence gathered from negotiation tactics and codebase analysis strongly suggests that Black Basta is a Russian-speaking threat group. Technical overlaps in malware loaders and financial laundering patterns show a 70% confidence link to the FIN7 threat group (also known as Sangria Tempest). The group's ability to maintain a 'premium' affiliate model while evading major law enforcement takedowns (such as Operation Cronos which targeted LockBit) indicates they possess robust backend infrastructure and highly disciplined operational leadership.
Implications
The targeted disruption of healthcare systems like Ascension demonstrates the 'life-safety' risks associated with modern ransomware. The financial implications extend beyond the ransom itself, encompassing massive operational losses, potential class-action litigation regarding patient data, and increased insurance premiums. For critical infrastructure providers, the use of EDR-killing tools like Backstab means that traditional signature-based and behavioral-based defenses are increasingly insufficient without hardware-rooted security measures.
Recommendations
Encrygma Intelligence recommends the following immediate mitigations:
- Patching: Prioritize updates for ConnectWise ScreenConnect (CVE-2024-1709) and all other public-facing management software.
- EDR Protection: Implement tamper protection for EDR agents and monitor for the unauthorized loading of the 'procexp' driver or the execution of 'Backstab.exe.'
- Network Segregation: Strictly isolate clinical and industrial control systems (ICS) from corporate IT networks.
- Credential Hardening: Enforce phishing-resistant multi-factor authentication (MFA) on all remote access portals and administrative accounts.
- Exfiltration Monitoring: Set alerts for high-volume outbound traffic to known cloud storage domains via RClone or similar command-line utilities.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Storm Ransomware Group Scales Healthcare Offensive; Phoenix Group Confirmed as Latest High-Profile Victim

Qilin Ransomware Intensifies Global Campaign with Multiple Strikes on Critical Infrastructure

