By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Leaked Black Basta Chats Suggest Russian Officials Aided Leader’s Escape from Armenia
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Leaked Black Basta Chats Suggest Russian Officials Aided Leader’s Escape from Armenia
Tech News

Leaked Black Basta Chats Suggest Russian Officials Aided Leader’s Escape from Armenia

By Viral Trending Content 4 Min Read
Share
SHARE

Mar 19, 2025Ravie LakshmananCybercrime / Threat Intelligence

The recently leaked trove of internal chat logs among members of the Black Basta ransomware operation has revealed possible connections between the e-crime gang and Russian authorities.

The leak, containing over 200,000 messages from September 2023 to September 2024, was published by a Telegram user @ExploitWhispers last month.

According to an analysis of the messages by cybersecurity company Trellix, Black Basta’s alleged leader Oleg Nefedov (aka GG or AA) may have received help from Russian officials following his arrest in Yerevan, Armenia, in June 2024, allowing him to escape three days later.

Cybersecurity

In the messages, GG claimed that he contacted high-ranking officials to pass through a “green corridor” and facilitate the extraction.

“This knowledge from chat leaks makes it difficult for the Black Basta gang to completely abandon the way they operate and start a new RaaS from scratch without a reference to their previous activities,” Trellix researchers Jambul Tologonov and John Fokker said.

Among other notable findings include –

  • The group likely has two offices in Moscow
  • The group utilizes OpenAI ChatGPT for composing fraudulent formal letters in English, paraphrasing text, rewriting C#-based malware in Python, debugging code, and collecting victim data
  • Some members of the group overlap with other ransomware operations like Rhysida and CACTUS
  • The developer of PikaBot is a Ukrainian national who goes by the online alias mecor (aka n3auxaxl) and that it took Black Basta a year to develop the malware loader post QakBot’s disruption
  • The group rented DarkGate from Rastafareye and used Lumma Stealer to steal credentials as well as drop additional malware
  • The group developed a post-exploitation command-and-control (C2) framework called Breaker to establish persistence, evade detection, and maintain access across network systems
  • GG worked with mecor on new ransomware that’s derived from Conti’s source code, leading to the release of a prototype written in C, indicating a possible rebranding effort

The development comes as EclecticIQ revealed Black Basta’s work on a brute-forcing framework dubbed BRUTED that’s designed to perform automated internet scanning and credential stuffing against edge network devices, including widely used firewalls and VPN solutions in corporate networks.

Cybersecurity

There is evidence to suggest that the cybercrime crew has been using the PHP-based platform since 2023 to perform large-scale credential-stuffing and brute-force attacks on target devices, allowing the threat actors to gain visibility into victim networks.

“BRUTED framework enables Black Basta affiliates to automate and scale these attacks, expanding their victim pool and accelerating monetization to drive ransomware operations,” security researcher Arda Büyükkaya said.

“Internal communications reveal that Black Basta has heavily invested in the BRUTED framework, enabling rapid internet scans for edge network appliances and large-scale credential stuffing to target weak passwords.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Top 3 leadership myths debunked

Adds Device Fingerprinting, PNG Steganography Payloads

Your Delivery Robot Is Here

Samsung Galaxy Tab S11 Review: It’s Time For Something New

How the World’s Largest 3D Object Library By Microsoft & NVIDIA

TAGGED: #OpenAI, Credential stuffing, Cyber Security, Cybercrime, Cybersecurity, dark web, Internet, Malware, network security, Ransomware, Threat Intelligence
Share This Article
Facebook Twitter Copy Link
Previous Article Isaac GR00T N1: NVIDIA’s Humanoid Robot Foundation Model
Next Article Mastering Remote Work: Overcoming the Challenges for Productivity and Balance
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

The best guns in the Black Ops 7 beta in early access
Gaming News
6-story office building to be converted into housing in Denver’s Capitol Hill
Business
Could Trump’s $2,000 tariff rebates for Americans stimulate an altcoin surge?
Crypto
Hegseth announces latest strike on boat near Venezuela he says was trafficking drugs
World News
Top 3 leadership myths debunked
Tech News
Bitcoin Holders Locking In Gains As Profit-Taking Surges Amid Market Recovery, Rally To Extend?
Crypto
Adds Device Fingerprinting, PNG Steganography Payloads
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

The best guns in the Black Ops 7 beta in early access

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
The best guns in the Black Ops 7 beta in early access
October 3, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?