Inside Ransomware: Facts and Findings from the Blackbasta and Lockbit Leaks

Cory Wolff (Director of Offensive Security · Risk 360)

BSides NYC 2025 (0x05) · Day 1 · Tech - Red

Overview

In "Inside Ransomware: Facts and Findings from the Blackbasta and Lockbit Leaks," Cory Wolff, Director of Offensive Security at Risk 360, provides an unprecedented look into the internal operations of two of the most prolific ransomware groups: Black Basta and LockBit. Drawing from recently leaked internal chat messages and database dumps, Wolff offers a rare glimpse beyond typical government intelligence reports and public bragging, revealing the sophisticated, business-like nature of these criminal enterprises. The talk dissects the methodologies, tools, and internal dynamics of these groups, shedding light on how they conduct reconnaissance, manage affiliates, and even handle internal missteps.

Watch on YouTube

Visual summary for Inside Ransomware: Facts and Findings from the Blackbasta and Lockbit Leaks by Cory Wolff
Visual summary for Inside Ransomware: Facts and Findings from the Blackbasta and Lockbit Leaks by Cory Wolff

Key moments

  1. 2:00 Overview of talk: Blackbasta and Lockbit leaks
  2. 2:40 Why these ransomware leaks are rare and valuable
  3. 3:40 Conti leak context and Black Basta's origin
  4. 4:20 Black Basta Matrix chat leak details and impact
  5. 6:00 Black Basta's self-disbanding after attacking Russian banks
  6. 7:00 Explanation of Ransomware as a Service (RaaS) model
  7. 8:00 Lockbit affiliate site defacement and SQL database leak

Inside Ransomware: Facts and Findings from the Blackbasta and Lockbit Leaks

Speakers: Cory Wolff, Director of Offensive Security, Risk 360

Conference: BSides NYC

YouTube: https://www.youtube.com/watch?v=2u3bcZxdoaI

Overview

In "Inside Ransomware: Facts and Findings from the Blackbasta and Lockbit Leaks," Cory Wolff, Director of Offensive Security at Risk 360, provides an unprecedented look into the internal operations of two of the most prolific ransomware groups: Black Basta and LockBit. Drawing from recently leaked internal chat messages and database dumps, Wolff offers a rare glimpse beyond typical government intelligence reports and public bragging, revealing the sophisticated, business-like nature of these criminal enterprises. The talk dissects the methodologies, tools, and internal dynamics of these groups, shedding light on how they conduct reconnaissance, manage affiliates, and even handle internal missteps.

This presentation is particularly significant because it leverages publicly released, raw intelligence that allows researchers and defenders to directly observe threat actor communications and operational data. Such leaks are exceedingly rare, providing a unique opportunity to understand the adversary from the inside. Wolff's analysis highlights critical insights into the ransomware-as-a-service (RaaS) model, the efficacy of open-source intelligence for targeting, and the rapid adoption of legitimate penetration testing tools by malicious actors.

For cybersecurity professionals, this talk is crucial. It demystifies the inner workings of ransomware gangs, offering actionable intelligence that can inform defensive strategies. By understanding the adversary's research methods, operational security failures, and preferred toolsets, organizations can better anticipate attacks, fortify their defenses, and develop more effective incident response plans against the persistent and evolving threat of ransomware.

Background

▶ Watch: Overview of talk: Blackbasta and Lockbit leaks (2:00)

The landscape of ransomware operations is typically shrouded in secrecy, with insights often limited to post-incident analysis, government indictments, or the public boasts of threat actors on dark web forums and encrypted channels. However, 2023 and early 2024 brought two significant, rare breaches that exposed the internal communications and operational data of two major ransomware groups: Black Basta and LockBit. These leaks offered an invaluable, unvarnished look into the daily activities, strategic decisions, and even the mistakes of these highly organized cybercriminal syndicates.

The first major precursor to these events was the Conti ransomware group leak in 2023. Conti, which reportedly generated approximately $200 million in revenue in 2022, saw its internal chat messages leaked, leading to its eventual disbandment. A significant portion of Conti's members subsequently regrouped to form Black Basta, a new ransomware operation that quickly rose to prominence. This pattern of a group's demise leading to the emergence of a new, related entity highlights the fluid and resilient nature of the ransomware ecosystem.

In February 2024, the internal communications of Black Basta were exposed. A Telegram user operating under the handle "Exploit Whispers" released over 200,000 Matrix chat messages from Black Basta's internal server. Matrix, a decentralized communication protocol similar to Mastodon, had become a popular choice for threat actors seeking more secure and private communication channels. Exploit Whispers claimed the leak was "payback" for Black Basta's violation of a tacit rule within the Russian-based cybercriminal community: do not target Russian entities, especially financial institutions. Black Basta had reportedly attacked Russian banks, prompting this retaliatory data dump. The leak effectively led to Black Basta's disbandment, with the group showing no activity since May 2024, although its members are presumed to have moved on to other operations.

Just a few months later, in May 2024, LockBit, one of the most dominant ransomware-as-a-service (RaaS) providers, suffered a significant breach. Following months of escalating tensions and public exchanges with law enforcement agencies, particularly the FBI (which had doxed LockBit's leader, "LockBitSupp," and taken down much of their infrastructure), LockBit's affiliate site was defaced. The defacement included a message – "don't do crime crime is bad. XOXO from Prague" – and, crucially, a link to an SQL dump of the affiliate site's database. This database contained a wealth of operational data, including Bitcoin addresses, negotiation messages, and affiliate build configurations. This was not the first time a ransomware group's site had been defaced with this message, but it was the first time it was accompanied by a data leak of such magnitude.

These leaks are more than just isolated incidents; they represent a rare opportunity for the cybersecurity community to gain direct, unfiltered insights into the tactics, techniques, and procedures (TTPs) of major ransomware groups. The data provides a ground-truth perspective that complements traditional intelligence gathering, enabling a deeper understanding of how these sophisticated criminal enterprises function, from recruitment and reconnaissance to negotiation and payout.

Key Findings

▶ Watch: Conti leak context and Black Basta's origin (3:40)

The analysis of the Black Basta and LockBit leaks by Cory Wolff revealed several critical findings that challenge common assumptions about ransomware operations and provide invaluable intelligence for defenders.

Firstly, the ease of entry into the ransomware ecosystem is remarkably low. LockBit, for instance, openly advertised its ransomware-as-a-service (RaaS) offering on its dark web sites. As demonstrated in a screenshot from their LockBit 5.0 campaign, aspiring cybercriminals could become an affiliate by simply sending $777 in cryptocurrency. Upon payment, they would receive an account and access to LockBit's infrastructure, encryptors, and support system. This low barrier to entry means that anyone with a basic understanding of cybercrime and a small investment can participate in ransomware attacks, significantly broadening the threat landscape and making the overall threat more diffuse and challenging to track.

Secondly, ransomware groups conduct extensive and sophisticated reconnaissance. The Black Basta chats, for example, contained 776 results related to "ZoomInfo." ZoomInfo is a legitimate business intelligence platform that provides detailed information on companies, including revenue, employee count, organizational structures, and contact details. This indicates that ransomware actors are not randomly selecting targets or making arbitrary ransom demands. Instead, they leverage tools like ZoomInfo to thoroughly research potential victims, understand their financial health, and tailor ransom demands based on a company's ability to pay, often knowing their annual revenue and even the potential payout from their cyber insurance policies. By exfiltrating financial data before deploying ransomware, they ensure their demands are well-informed and maximized.

Thirdly, these threat actors are avid consumers of legitimate security research and penetration testing tools. They actively read cybersecurity blogs, engage with platforms like Hack The Box and TryHackMe, and pursue certifications like the Offensive Security Certified Professional (OSCP). Wolff presented screenshots from internal chats showing discussions about tools such as Sharpshares.exe, a .NET assembly designed for enumerating network SMB shares, and Roadtools, a comprehensive toolset for performing device code phishing attacks against Azure and Entra ID environments. The rapid adoption of these tools and techniques by ransomware groups underscores the need for defenders to stay current with offensive security trends, as new exploits and tools quickly transition from the legitimate pentesting community to malicious actors.

Fourthly, the leaks exposed a fascinating instance of LockBit accidentally ransoming a Russian government entity. Among the 4,000 negotiation messages found in the LockBit database, one particular exchange stood out. A victim, communicating in Russian, adopted an unusually stern and demanding tone, stating, "more than an hour has passed without a response. What's the status of the issue? We need the decryption tool to proceed." The victim also emphasized the importance of LockBit's reputation and its commitment to upholding it. This was highly uncharacteristic of typical victim communications. Further investigation revealed that the target was a Moscow-based government entity responsible for the construction of bridges and embankments. The leader of LockBit, "LockBitSupp," a figure typically tough on law enforcement, personally intervened in the chat, apologizing profusely and offering immediate decryption, stating, "I am boss lockbit. Only me can decrypt your files. Wait, please." This incident highlights the strict geopolitical rules governing Russian-based threat actors and their fear of repercussions from Russian authorities, even if the ransomware deployment was an affiliate's mistake.

Finally, the data demonstrated that ransomware attacks are often the culmination of long-term reconnaissance and planning. The Black Basta chats included discussions about Ascension Health as early as March 2023, with lists of Ascension Health emails being shared. However, the actual ransomware attack on Ascension Health did not occur until May 2024, over a year later. This extended period indicates that threat actors often identify targets, gather intelligence, and maintain access for prolonged durations before launching the final, visible attack. This finding emphasizes that initial compromise or data exfiltration might precede the actual encryption event by many months, making continuous monitoring and proactive threat hunting crucial for early detection.

These key findings collectively paint a picture of highly organized, adaptable, and business-savvy criminal enterprises that leverage sophisticated tools and strategies, often mirroring legitimate business practices, to maximize their illicit gains.

Technical Deep Dive

▶ Watch: Black Basta Matrix chat leak details and impact (4:20)

The leaked data from Black Basta and LockBit provides a rich technical understanding of their operational methodologies, communication platforms, and the tools they leverage.

For Black Basta, the primary technical insight came from their internal communications hosted on Matrix servers. Matrix is an open standard for decentralized, real-time communication, similar to federated platforms like Mastodon. Threat actors gravitate towards Matrix due to its self-hosting capabilities, which offer a perceived layer of anonymity and control over their communication infrastructure, making it harder for law enforcement to monitor or disrupt. The 200,000 leaked Matrix chat messages provided a direct window into Black Basta's day-to-day operations, including target discussions, tool recommendations, and internal policy enforcement (such as the unwritten rule against targeting Russian entities).

LockBit's technical sophistication was revealed through the SQL dump of its affiliate panel database. This leak exposed the backend architecture of a leading Ransomware-as-a-Service (RaaS) operation. Key technical components and data points included:

  1. Bitcoin Addresses: The database contained roughly 60,000 Bitcoin addresses associated with affiliates. LockBit's system was designed to generate 10 to 20 additional "cleaning" addresses for each victim's primary Bitcoin address. These secondary addresses are used for Bitcoin tumbling or mixing services, a technique to obscure the origin and destination of cryptocurrency transactions, making it harder for financial investigators to trace illicit funds. While many of these addresses might have been empty, their sheer volume indicates a high level of operational security consciousness regarding financial obfuscation.
  2. Negotiation Chat Portal: The database included over 4,000 chat messages from LockBit's victim negotiation portal. This portal serves as the primary communication channel between victims and the ransomware operators after an encryption event. It functions much like a customer service interface, where victims can negotiate ransom amounts, request proof of data deletion, or seek decryption keys. The leaked messages provided insights into negotiation tactics, victim psychology, and the internal processes LockBit uses to manage these interactions, often handled by "customer service reps" rather than core leadership.
  3. Affiliate and Admin Accounts: The dump revealed approximately 75 affiliate and admin accounts. These accounts represent the various individuals and groups operating under the LockBit RaaS umbrella. The presence of some plaintext passwords within the dump highlighted an operational security lapse on LockBit's part, which likely contributed to the breach.
  4. Build Configurations: The database stored detailed build configurations for the ransomware executables. When an affiliate gained access to a victim's network and was ready to deploy ransomware, they would access the affiliate panel to generate a new "build." This process would produce a customized ransomware variant, often a .NET assembly or a standalone executable, tailored for the specific victim. These configurations would include parameters such as target networks, specific files to encrypt, and potentially evasion techniques. LockBit was also notable for being one of the first major ransomware groups to develop and deploy a Linux encryptor, expanding their targeting capabilities beyond traditional Windows-based Active Directory environments to include Linux servers and virtual machines, which are prevalent in enterprise infrastructure.

Beyond their internal systems, the talk highlighted the technical tools and methods adopted by these ransomware groups for their operations:

  • Reconnaissance Tools: The extensive use of ZoomInfo by Black Basta demonstrates their reliance on open-source intelligence (OSINT) tools for target profiling. ZoomInfo aggregates public and private data to provide comprehensive company profiles, including revenue, employee count, technology stack, and organizational charts. This allows threat actors to conduct financial intelligence gathering to determine optimal ransom demands and understand a target's perceived value.
  • Offensive Security Tools: Ransomware groups are quick to integrate legitimate penetration testing tools into their arsenals. Wolff specifically mentioned:
  • Sharpshares.exe: This is a .NET assembly designed for enumerating network SMB (Server Message Block) shares. It's a common tool used by red teams and penetration testers to discover accessible network resources within a compromised Windows environment. Its appearance in Black Basta's chats indicates that they use similar methods to map victim networks and identify valuable data repositories.
  • Roadtools: This toolset is designed for performing device code phishing attacks against Azure and Entra ID (formerly Azure Active Directory) environments. Device code flow is a legitimate authentication mechanism for devices with limited input capabilities. Roadtools exploits this by tricking users into authenticating to a malicious application, thereby granting the attacker access tokens. The fact that LockBit affiliates were discussing how to perform device code phishing using Roadtools underscores their proficiency in modern cloud-based attack techniques and their ability to target organizations leveraging Microsoft's cloud services.

The technical details underscore that modern ransomware operations are far from unsophisticated. They employ a structured RaaS model, leverage advanced obfuscation techniques, and continuously adapt by integrating cutting-edge offensive security tools and TTPs developed by the legitimate security research community. This makes them formidable adversaries requiring equally sophisticated defensive countermeasures.

Demo / Proof of Concept

▶ Watch: Explanation of Ransomware as a Service (RaaS) model (7:00)

While Cory Wolff's talk did not feature a live technical demonstration or a proof-of-concept exploit in the traditional sense, the entire presentation served as a powerful "demonstration" of the actionable intelligence derived from the leaked Black Basta and LockBit data. Wolff effectively walked the audience through specific findings and screenshots from the actual leaked materials, providing direct evidence of the ransomware groups' internal communications, operational procedures, and tool usage.

The "demo" was, in essence, the public release and subsequent analysis of the raw data itself. Wolff highlighted that all the data discussed was publicly available, allowing other researchers to "view for yourself" and "browse through this data yourself" to gain their own insights. He presented specific examples, such as a screenshot of LockBit's dark web affiliate sign-up page advertising the $777 fee, excerpts from Black Basta's Matrix chats discussing ZoomInfo and Sharpshares.exe, and the translated LockBit negotiation messages with the Russian government entity. These concrete examples from the primary source material effectively demonstrated the points made in the talk, providing tangible evidence of the threat actors' activities rather than theoretical explanations.

Defensive Implications

▶ Watch: Lockbit affiliate site defacement and SQL database leak (8:00)

The insights gleaned from the Black Basta and LockBit leaks offer critical implications for cybersecurity defenders, urging a re-evaluation of current security postures and strategies.

Firstly, the low barrier to entry for ransomware affiliates (e.g., $777 for LockBit) means that the threat is not limited to a few highly sophisticated groups but includes a broad spectrum of individuals with varying skill levels. This necessitates comprehensive, layered defenses that can deter both advanced persistent threats and opportunistic attackers. Organizations must assume they are a potential target for any motivated individual, not just state-sponsored or top-tier criminal organizations.

Secondly, the extensive use of open-source intelligence (OSINT) and business intelligence tools like ZoomInfo for reconnaissance highlights the need for organizations to understand and manage their public digital footprint. Defenders should proactively assess what information about their company, its revenue, employee structure, and technology stack is publicly available. This includes reviewing corporate websites, public filings, social media, and third-party data aggregators. By understanding what an adversary can learn, organizations can better predict potential attack vectors and tailor their defenses, for instance, by strengthening security around publicly known executives or high-value departments. Furthermore, understanding that ransomware groups conduct financial intelligence to gauge cyber insurance payouts suggests that organizations should review how their insurance policies are discussed internally and externally, as this information can influence ransom demands.

Thirdly, the rapid adoption of legitimate penetration testing tools (e.g., Sharpshares.exe, Roadtools) by ransomware groups underscores a critical gap: the lag between offensive security innovation and defensive implementation. Defenders must stay abreast of the latest red teaming techniques and tools. This means:

  • Proactive Threat Hunting: Implementing threat hunting programs that actively look for indicators of compromise (IOCs) related to these tools, rather than just relying on signature-based detection.
  • Endpoint Detection and Response (EDR) & Extended Detection and Response (XDR): Ensuring EDR/XDR solutions are configured to detect the behaviors associated with tools like Sharpshares.exe (e.g., extensive SMB share enumeration) and Roadtools (e.g., unusual device code flow authentications).
  • Identity and Access Management (IAM): Strengthening Azure/Entra ID security configurations, implementing multi-factor authentication (MFA) everywhere, and enforcing strict conditional access policies to mitigate device code phishing risks. Regular audits of cloud configurations are essential.
  • Network Segmentation: Implementing robust network segmentation to limit the lateral movement capabilities of tools like Sharpshares.exe, even if they gain initial access.

Fourthly, the discovery of long-term reconnaissance periods (e.g., Black Basta and Ascension Health for over a year) demands a shift from reactive security to continuous monitoring and proactive threat hunting. Initial access or data exfiltration may occur months before the visible ransomware attack. Organizations must invest in:

  • Advanced Log Management and SIEM: Centralized logging and Security Information and Event Management (SIEM) systems capable of correlating events over extended periods to detect subtle anomalies indicative of long-term compromise.
  • Behavioral Analytics: Deploying tools that can identify unusual user or entity behavior (UEBA) that might signal early-stage reconnaissance or persistent access.
  • Vigilant Threat Intelligence: Consuming and acting upon threat intelligence that details the TTPs of specific ransomware groups, including their typical reconnaissance durations and preferred initial access vectors.

Finally, while the LockBit incident with the Russian government entity is specific to the geopolitical rules of Russian cybercrime, it serves as a stark reminder of the business-like nature of these groups. They have customer service, negotiation tactics, and even internal rules. This implies that:

  • Incident Response Planning: Organizations need comprehensive incident response plans that include negotiation strategies, understanding that conversations with ransomware actors are often with "customer service reps" who follow scripts.
  • Backup and Recovery: The ultimate defense remains robust, isolated, and tested backup and recovery strategies, rendering the core extortion tactic (data encryption) less impactful.

In summary, defending against modern ransomware requires a holistic approach: understanding the adversary's business model, managing public information, staying current with offensive tooling, practicing continuous monitoring, and maintaining resilient recovery capabilities.

Key Takeaways

  • Ransomware-as-a-Service (RaaS) is Highly Accessible: Becoming a ransomware affiliate can be as simple as paying a small fee (e.g., $777 for LockBit 5.0), significantly broadening the pool of potential attackers.
  • Sophisticated Reconnaissance is Standard: Ransomware groups use legitimate tools like ZoomInfo to conduct extensive financial and organizational intelligence gathering, tailoring ransom demands based on a victim's perceived ability to pay and cyber insurance coverage.
  • Threat Actors Rapidly Adopt Offensive Security Tools: They actively monitor security research and quickly integrate penetration testing tools (e.g., Sharpshares.exe for SMB enumeration, Roadtools for Azure/Entra ID device code phishing) into their attack methodologies.
  • Ransomware Campaigns Involve Long-Term Planning: Initial compromise and reconnaissance can precede the actual ransomware deployment by many months, as seen with Black Basta's year-long monitoring of Ascension Health.
  • Geopolitical Rules Influence Targeting: Russian-based ransomware groups generally avoid targeting Russian entities, and accidental breaches of this rule can lead to significant internal pressure and immediate remediation from group leaders.
  • Robust Defensive Strategies are Paramount: Organizations must implement layered defenses, proactive threat hunting, strong identity and access management, and comprehensive backup and recovery plans to counter these adaptable and well-resourced adversaries.

About the Speaker(s)

Cory Wolff is the Director of Offensive Security at Risk 360, a cybersecurity consulting firm based out of Atlanta, Georgia. In this role, he leads a team responsible for red teaming, penetration testing, and threat intelligence operations. Beyond his professional work, Cory is a prominent figure in the cybersecurity community, serving as part of the core team for Red Team Village, which originated at Defcon in 2016. Within Red Team Village, he holds the position of Director of Workshops and Training, overseeing the submission review and scheduling processes for hands-on "tactics" and instructor-led "workshops" that provide practical, immersive learning experiences for attendees. His background blends deep technical offensive security expertise with a commitment to community education and knowledge sharing.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Solid threat intel briefing that squeezes genuine value from rare primary source material — the leaks themselves do most of the heavy lifting. Wolff synthesizes the data competently and lands a few genuinely good findings (the Ascension Health timeline, the Russian gov entity incident, the ZoomInfo OSINT angle), but the analysis rarely goes deeper than what a careful reader of the raw data could produce themselves.

Heather Calloway (CISO) — SOLID

Wolff presents genuinely rare primary source intelligence on Black Basta and LockBit with credible specificity — the Ascension Health timeline, the Russian government entity incident, the ZoomInfo reconnaissance pattern. Competent threat intelligence work that delivers real findings. But it stays at the analyst layer and never climbs to where security programs actually get run.

→ Top-rated talks at BSides NYC 2025 (0x05)

All talks from BSides NYC 2025 (0x05)