Black Basta internal chat logs leak online
by lulagain - Thursday February 20, 2025 at 10:07 PM
#1
[Image: Black-Basta-chat-leak.png]
An unknown leaker has released what they claim to be an archive of internal Matrix chat logs belonging to the Black Basta ransomware operation.
ExploitWhispers, the individual who uploaded the stolen messages on the MEGA file-sharing platform, has since removed it and uploaded it to a dedicated Telegram channel.
It's not yet clear if ExploitWhispers is a security researcher who gained access to the gang's internal chat server or a disgruntled member.
While they never shared the reason behind this move, cyber threat intelligence company PRODAFT said today that the leak could directly result from the ransomware gang's alleged attacks targeting Russian banks.
"As part of our continuous monitoring, we've observed that BLACKBASTA (Vengeful Mantis) has been mostly inactive since the start of the year due to internal conflicts. Some of its operators scammed victims by collecting ransom payments without providing functional decryptors," PRODAFT said.
"On February 11, 2025, a major leak exposed BLACKBASTA's internal Matrix chat logs. The leaker claimed they released the data because the group was targeting Russian banks. This leak closely resembles the previous Conti leaks."
The leaked archive contains messages exchanged in Black Basta's internal chat rooms between September 18, 2023, and September 28, 2024.
BleepingComputer's analysis of the messages shows they contain a wide range of information, including phishing templates and emails to send them to, cryptocurrency addresses, data drops, victim's credentials, and confirmation of tactics we previously reported on.
The leaked chats also contain 367 unique ZoomInfo links, which indicate the likely number of companies targeted during this period. Ransomware gangs commonly use the ZoomInfo site to share information about a targeted company, internally or with victims during negotiations.
ExploitWhispers also shared information about some Black Basta ransomware gang members, including Lapa (one of the operation's admins), Cortes (a threat actor linked to the Qakbot group), YY (Black Basta's main administrator), and Trump (aka GG and AA), the group's boss (Oleg Nefedov).
CHATS UPLOADED HERE :https://breachforums.hn/Thread-Black-Bas...s-Download 
[Image: 128.gif]
@Ater  @antisocial My Nigga's
Reply
#2
Really intressting news. Somebody already found it to download directly?

Thanks for sharing.
Reply
#3
Thanks for sharing
Reply
#4
Is anywhere option to download? please
Reply
#5
Interesting a Russian guy behind this !
[Image: I-FEAR-NO.gif]
Reply
#6
CHATS UPLOADED HERE :-  https://breachforums.hn/Thread-Black-Bas...s-Download
[Image: 128.gif]
@Ater  @antisocial My Nigga's
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  SafePay ransomware threatens to leak 3.5TB of Ingram Micro data lulagain 2 200 Yesterday, 04:00 AM
Last Post: xhuimix
  epsilon hacker "Chat Noir" arrested for FREE SAS breach Angel_Batista 17 1,960 04-15-2025, 01:34 AM
Last Post: Mamadou123
  Meet Lek Do BlacK – The Most Unfiltered, No-Bullshit AI Ever bishopnicco 5 387 04-14-2025, 11:22 AM
Last Post: SilverX
  Cyberattack takes down Ukrainian state railway’s online services lulagain 1 262 04-14-2025, 07:31 AM
Last Post: RedMedved
  Dxbin Got a public chat system on their site lulagain 2 320 04-13-2025, 05:43 PM
Last Post: antisocial

Forum Jump:


 Users browsing this thread: 1 Guest(s)