Late on the evening of February 11th, 2025, a brand‑new Telegram channel named shopotbasta (“Basta Whisper” in Russian) lit up with a link to a 1 GB MEGA archive. The channel’s creator, who went by ExploitWhispers, claimed the files were “the unfiltered Matrix history” of Black Basta and said they were acting in protest after the gang’s decision to raid several midsize Russian banks.
Over the next ten days researchers from BleepingComputer, The Register, and dozens of independent threat‑intel teams pulled the data apart and confirmed its authenticity: ≈196,000 messages, 800 distinct chat rooms, and a full year’s worth of timestamps and sender metadata.
By February 21st, mainstream tech outlets such as TechCrunch were already publishing rundowns of the gang’s hierarchy, tooling lists and victim negotiations, while CTI vendors hurried out scripts to parse the raw JSON logs.
Through March and April 2025, analysts noted that Black Basta’s public leak‑site went conspicuously quiet and affiliates complained—inside the very same leaked chat rooms!—about distrust and non‑payment. Dark Reading and Trellix both concluded that the leak had driven the crew into near‑total dormancy.
New TTPs and tooling. The logs reveal an automated brute‑force framework dubbed BRUTED used against VPNs, firewalls and edge appliances from Fortinet, Palo Alto, Citrix and Ivanti.
Infrastructure & IOCs. Analysts have extracted more than 300 cryptocurrency addresses, hundreds of C2 and staging domains, ZoomInfo reconnaissance links and bespoke phishing templates.
Org chart & workload. Chat fragments show project‑manager and HR‑style roles coordinating up to 25 simultaneous intrusions; one affiliate brags that he is only 17 years old.
Target‑selection logic. Contrary to prior belief, the gang actively debates the geopolitical risk of hitting critical infrastructure and health‑care providers—insightful context for threat‑modelling.
We created Bastachats to give analysts, researchers, and defenders a clean, powerful way to explore the leaked Black Basta communications.
To get there, we:
Parsed and normalized the chat logs – We took the multi-gigabyte JSON export of Matrix chats and converted it into structured messages with accurate timestamps and formatting.
Translated Russian to English – Using a hybrid of automated translation and manual review, we made each message readable in English.
Indexed everything – The platform supports full-text search, filters by whole word and regex with downloadable excerpts.
To help you get started, here are some example searches you might find useful:
bruted – See references to their custom brute-force tooling and how it’s deployed.
fortinet or palo alto – Reveals preferred perimeter device targets and known weaknesses.
rclone – Used for data exfiltration in several ransomware cases.
lolbas – Chat mentions of “living off the land” binaries (e.g., bitsadmin, wmic).
zoominfo or shodan – Conversations about using external services to identify targets.
stealer or logs – Affiliate discussions about buying initial access credentials from malware marketplaces.
mfa – Threads complaining about or working around multi-factor authentication.
pharma, hospital, manufacturing – Gang members talk about industry verticals and risk tolerance.
north america, usa, europe – Filters targeting campaigns by region.
Names of known victims (e.g., abbvie, baxter, caterpillar) – For threat intelligence correlation, though exact spelling may vary.
We built this site to turn a noisy, disorganized dump into something usable, actionable, and secure for defenders. We believe that curated access to threat actor operations helps level the playing field.
You can start your own exploration at bastachats.armada-ops.com.
Let us know what you find.