Late on the evening of February 11th, 2025, a brand‑new Telegram channel named shopotbasta (“Basta Whisper” in Russian) lit up with a link to a 1 GB MEGA archive. The channel’s creator, who went by ExploitWhispers, claimed the files were “the unfiltered Matrix history” of Black Basta and said they were acting in protest after the gang’s decision to raid several midsize Russian banks.
Over the next ten days researchers from BleepingComputer, The Register, and dozens of independent threat‑intel teams pulled the data apart and confirmed its authenticity: ≈196,000 messages, 800 distinct chat rooms, and a full year’s worth of timestamps and sender metadata.
By February 21st, mainstream tech outlets such as TechCrunch were already publishing rundowns of the gang’s hierarchy, tooling lists and victim negotiations, while CTI vendors hurried out scripts to parse the raw JSON logs.
Through March and April 2025, analysts noted that Black Basta’s public leak‑site went conspicuously quiet and affiliates complained—inside the very same leaked chat rooms!—about distrust and non‑payment. Dark Reading and Trellix both concluded that the leak had driven the crew into near‑total dormancy.
Why the leak is a goldmine for defenders
New TTPs and tooling. The logs reveal an automated brute‑force framework dubbed BRUTED used against VPNs, firewalls and edge appliances from Fortinet, Palo Alto, Citrix and Ivanti.
Infrastructure & IOCs. Analysts have extracted more than 300 cryptocurrency addresses, hundreds of C2 and staging domains, ZoomInfo reconnaissance links and bespoke phishing templates.
Org chart & workload. Chat fragments show project‑manager and HR‑style roles coordinating up to 25 simultaneous intrusions; one affiliate brags that he is only 17 years old.
Target‑selection logic. Contrary to prior belief, the gang actively debates the geopolitical risk of hitting critical infrastructure and health‑care providers—insightful context for threat‑modelling.
What we built
We created Bastachats to give analysts, researchers, and defenders a clean, powerful way to explore the leaked Black Basta communications.
To get there, we:
Parsed and normalized the chat logs – We took the multi-gigabyte JSON export of Matrix chats and converted it into structured messages with accurate timestamps and formatting.
Translated Russian to English – Using a hybrid of automated translation and manual review, we made each message readable in English.
Indexed everything – The platform supports full-text search, filters by whole word and regex with downloadable excerpts.
Ideas for your own searches
To help you get started, here are some example searches you might find useful:
ttp focused searches
bruted– See references to their custom brute-force tooling and how it’s deployed.fortinetorpalo alto– Reveals preferred perimeter device targets and known weaknesses.rclone– Used for data exfiltration in several ransomware cases.lolbas– Chat mentions of “living off the land” binaries (e.g.,bitsadmin,wmic).
Reconnaissance and access
zoominfoorshodan– Conversations about using external services to identify targets.stealerorlogs– Affiliate discussions about buying initial access credentials from malware marketplaces.mfa– Threads complaining about or working around multi-factor authentication.
victim or industry references
pharma,hospital,manufacturing– Gang members talk about industry verticals and risk tolerance.north america,usa,europe– Filters targeting campaigns by region.Names of known victims (e.g.,
abbvie,baxter,caterpillar) – For threat intelligence correlation, though exact spelling may vary.
OUR GOAL
We built this site to turn a noisy, disorganized dump into something usable, actionable, and secure for defenders. We believe that curated access to threat actor operations helps level the playing field.
You can start your own exploration at bastachats.armada-ops.com.
Let us know what you find.
Cory Wolff
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)