{"id":10894,"date":"2026-01-18T05:12:38","date_gmt":"2026-01-18T05:12:38","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=10894"},"modified":"2026-01-18T05:12:38","modified_gmt":"2026-01-18T05:12:38","slug":"black-basta-ransomware-chief-added-to-eu-most-needed-and-interpol-crimson-discover","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=10894","title":{"rendered":"Black Basta Ransomware Chief Added to EU Most Needed and INTERPOL Crimson Discover"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jan 17, 2026<\/span><\/span><span class=\"p-tags\">Regulation Enforcement \/ Cybercrime<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh3VY2I87McGcsRT2S52vO2sa1A9ZvLo_H6YYLk5sCypOvjoX1H4Ee9QkvAiFJIvy0qW0dvgi_db78HgDvWHJKW9Fkaf5sLOt-RA2sP8fooQrHtv0qFf6Cazo7YjXAKY7NXJdNotK4w8aiiuz1nzNzmGbiJ6l81rbrU5-Sa7oOlMiRl08-4_4p9XtsjB1Am\/s900-e365\/Ukrainian-hacker.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh3VY2I87McGcsRT2S52vO2sa1A9ZvLo_H6YYLk5sCypOvjoX1H4Ee9QkvAiFJIvy0qW0dvgi_db78HgDvWHJKW9Fkaf5sLOt-RA2sP8fooQrHtv0qFf6Cazo7YjXAKY7NXJdNotK4w8aiiuz1nzNzmGbiJ6l81rbrU5-Sa7oOlMiRl08-4_4p9XtsjB1Am\/s900-e365\/Ukrainian-hacker.jpg\" alt=\"\" border=\"0\" data-original-height=\"470\" data-original-width=\"900\"\/><\/a><\/div>\n<p>Ukrainian and German legislation enforcement authorities have <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/cyberpolice.gov.ua\/news\/naczpolicziya-vykryla-chleniv-mizhnarodnogo-xakerskogo-ugrupovannya-ta-identyfikuvala-jogo-organizatora-6407\/\" rel=\"noopener\" target=\"_blank\">recognized<\/a> two Ukrainians suspected of working for the Russia-linked ransomware-as-a-service (RaaS) group Black Basta.<\/p>\n<p>As well as, the group&#8217;s alleged chief, a 35-year-old Russian nationwide named Oleg Evgenievich Nefedov (\u041d\u0435\u0444\u0435\u0434\u043e\u0432 \u041e\u043b\u0435\u0433 \u0415\u0432\u0433\u0435\u043d\u044c\u0435\u0432\u0438\u0447), has been <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bka.de\/DE\/IhreSicherheit\/Fahndungen\/Personen\/BekanntePersonen\/BlackBasta\/Sachverhalt.html?nn=26874#sprachversionen261512\" rel=\"noopener\" target=\"_blank\">added<\/a> to the European Union&#8217;s <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/eumostwanted.eu\/#\/nefedov-oleg-evgenievich\" rel=\"noopener\" target=\"_blank\">Most Needed<\/a> and INTERPOL&#8217;s <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.interpol.int\/How-we-work\/Notices\/Red-Notices\/View-Red-Notices#2025-100086\" rel=\"noopener\" target=\"_blank\">Crimson Discover<\/a> lists, authorities famous.<\/p>\n<p>&#8220;In line with the investigation, the suspects specialised in technical hacking of protected methods and had been concerned in making ready cyberattacks utilizing ransomware,&#8221; the Cyber Police of Ukraine mentioned in a press release. <\/p>\n<p>The company mentioned the accused people functioned as &#8220;hash crackers,&#8221; who concentrate on extracting passwords from info methods utilizing specialised software program. As soon as the credential info was obtained, members of the ransomware group broke into company networks and in the end deployed ransomware and extorted cash to get better the encrypted info.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.uk\/zero-trust-summit-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgqlhh16hjmE7NRyQeAR2_sLZ1uDwyQH2jkPHmDTAtveTHoIjCrfmK6JLqlZuNKOPG1RGLtwJk-ZJDwQiV-McwmzAUu1iOSwwMjs_tqI1KjcL_tCvc0M2XuKBPfJ1RXpKxnx-eGdWwM0wlNDnUYHvXr-1LZk2zRmDNLIEbYGalGQJsd6QwC0pyCrLavN0fz\/s728-e100\/threatlocker-inside-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Authorities carried out searches on the defendants&#8217; residences positioned in Ivano-Frankivsk and Lviv, permitting them to grab digital storage gadgets and cryptocurrency belongings.<\/p>\n<p>Black Basta <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/02\/leaked-black-basta-chat-logs-reveal.html\" rel=\"noopener\" target=\"_blank\">first emerged<\/a> within the risk panorama in April 2022, and is claimed to have focused greater than 500 firms throughout North America, Europe, and Australia. The ransomware group is estimated to have earned tons of of thousands and thousands of {dollars} in cryptocurrency from illicit funds.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" name=\"more\"\/><\/p>\n<p>Early final yr, a yr&#8217;s value of inside chat logs from Black Basta <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.s-rminform.com\/latest-thinking\/the-blackbasta-leaks-cyber-briefing-note\" rel=\"noopener\" target=\"_blank\">leaked on-line<\/a>, providing a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.kelacyber.com\/blog\/black-basta-leak-how-ransomware-operators-gain-access\/\" rel=\"noopener\" target=\"_blank\">glimpse<\/a> into the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/info.ke-la.com\/hubfs\/Reports\/KELA%20Report%20-%20Black%20Basta%20Leak_%20How%20Ransomware%20Operators%20Gain%20Access.pdf\" rel=\"noopener\" target=\"_blank\">group&#8217;s internal workings<\/a>, its construction and key members, and the varied safety vulnerabilities exploited to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blog.bushidotoken.net\/2025\/02\/blackbasta-leaks-lessons-from-ascension.html\" rel=\"noopener\" target=\"_blank\">achieve preliminary entry<\/a> to organizations of curiosity.<\/p>\n<p>The leaked file additionally unmasked <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.suspectfile.com\/tramp-the-shadowy-figure-behind-black-bastas-ransomware-operations\/\" rel=\"noopener\" target=\"_blank\">Nefedov<\/a> as Black Basta&#8217;s ringleader, including he goes by numerous aliases, corresponding to Tramp, Trump, GG, and AA. Some paperwork alleged that Nefedov had ties to high-ranking Russian politicians and intelligence businesses, together with the FSB and GRU.<\/p>\n<p>Nefedov is believed to have leveraged these connections to guard his operations and evade worldwide justice. A subsequent evaluation from Trellix <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/03\/leaked-black-basta-chats-suggest.html\" rel=\"noopener\" target=\"_blank\">revealed<\/a> that Nefedov was capable of safe his freedom regardless of getting arrested in Yerevan, Armenia, in June 2024. His different aliases embrace kurva, Washingt0n, and S.Jimmi. Though Nefedov is claimed to be in Russia, his precise whereabouts are unknown.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi_KDmIkVmcUX13qNzaY7VHnSKQsqTN0XLdSZ5AijAT1YabZKY9p5nJ7mN8A812DllGlh2RNS5ztmNoLWwTk96BDz2j1LQqQv6loXJBGJWvsgxSKCxRSYmzZzBv6jJ1AkWeiJEM5tuEdre79EOa6Brfj_v_t4qhh979rgN-bkdhzrx7-zHxkJ204ctVKxFp\/s900-e365\/hacker-arrested.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi_KDmIkVmcUX13qNzaY7VHnSKQsqTN0XLdSZ5AijAT1YabZKY9p5nJ7mN8A812DllGlh2RNS5ztmNoLWwTk96BDz2j1LQqQv6loXJBGJWvsgxSKCxRSYmzZzBv6jJ1AkWeiJEM5tuEdre79EOa6Brfj_v_t4qhh979rgN-bkdhzrx7-zHxkJ204ctVKxFp\/s900-e365\/hacker-arrested.jpg\" alt=\"\" border=\"0\" data-original-height=\"954\" data-original-width=\"1507\"\/><\/a><\/div>\n<p>Moreover, there&#8217;s proof linking Nefedov to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2022\/05\/conti-ransomware-gang-shut-down-after.html\" rel=\"noopener\" target=\"_blank\">Conti<\/a>, a now-defunct group that sprang forth in 2020 as a successor to Ryuk. In August 2022, the U.S. State Division <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2022\/08\/us-government-offers-10-million-reward.html\" rel=\"noopener\" target=\"_blank\">introduced<\/a> a $10 million reward for info associated to 5 people related to the Conti ransomware group. They included Goal, Tramp, Dandis, Professor, and Reshaev.<\/p>\n<p>It is value mentioning right here that Black Basta surfaced as an autonomous group, alongside BlackByte and KaraKurt, following the retirement of the Conti model in 2022. Different members joined teams like <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2024\/03\/exit-scam-blackcat-ransomware-group.html\" rel=\"noopener\" target=\"_blank\">BlackCat<\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2024\/02\/us-offers-10-million-bounty-for-info.html\" rel=\"noopener\" target=\"_blank\">Hive<\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2023\/10\/fbi-cisa-warn-of-rising-avoslocker.html\" rel=\"noopener\" target=\"_blank\">AvosLocker<\/a>, and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2023\/11\/hellokitty-ransomware-group-exploiting.html\" rel=\"noopener\" target=\"_blank\">HelloKitty<\/a>, all of which at the moment are not lively.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.uk\/attack-surface-insight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgj01_-EPEkxaROaED9e8h2OIIeT0oXXmcnWEAb3xbOAumwdFU9z8fpwY4vjL11Reywiz9PTesXqQ86D2Eb6FQI46Rcq3mfmaqzr4RxV8S18OBZ7YrmcPIm3T-5ki1ME8gNTIwhKiysr2545hOD7b_O4k9GLx5L4XWdPyaRHJggufYNeAFej_TqWhlmNWxL\/s728-e100\/Sprocket-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>&#8220;He served as the top of the group. As such, he determined who or which organisations could be the targets of assaults, recruited members, assigned them duties, took half in ransom negotiations, managed the ransom obtained by extortion, and used it to pay the members of the group,&#8221; Germany&#8217;s Federal Legal Police Workplace (BKA or Bundeskriminalamt) mentioned.<\/p>\n<p>The leaks have led to Black Basta&#8217;s obvious demise, with the group remaining silent after February and taking down its information leak later that month. However with ransomware gangs recognized to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blog.barracuda.com\/2025\/03\/07\/black-basta-s-rapid-collapse\" rel=\"noopener\" target=\"_blank\">shut down, rebrand, and reemerge<\/a> underneath a unique identification, it will not be stunning if members of the erstwhile prison syndicate pivot to different ransomware teams or type new ones.<\/p>\n<p>Certainly, per experiences from <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/06\/former-black-basta-members-use.html\" rel=\"noopener\" target=\"_blank\">ReliaQuest<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/03\/researchers-link-cactus-ransomware.html\" rel=\"noopener\" target=\"_blank\">Pattern Micro<\/a>, it is suspected that a number of of the previous Black Basta associates may need migrated to the CACTUS ransomware operation \u2013 an evaluation primarily based on the truth that there was an enormous spike in organizations named on the latter&#8217;s information leak web site in February 2025, coinciding with Black Basta&#8217;s web site going offline.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jan 17, 2026Regulation Enforcement \/ Cybercrime Ukrainian and German legislation enforcement authorities have recognized two Ukrainians suspected of working for the Russia-linked ransomware-as-a-service (RaaS) group Black Basta. As well as, the group&#8217;s alleged chief, a 35-year-old Russian nationwide named Oleg Evgenievich Nefedov (\u041d\u0435\u0444\u0435\u0434\u043e\u0432 \u041e\u043b\u0435\u0433 \u0415\u0432\u0433\u0435\u043d\u044c\u0435\u0432\u0438\u0447), has been added to the European Union&#8217;s Most Needed [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":10896,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[3310,7446,449,7447,4093,7448,500,2501,4594],"class_list":["post-10894","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-added","tag-basta","tag-black","tag-interpol","tag-leader","tag-notice","tag-ransomware","tag-red","tag-wanted"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10894","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10894"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10894\/revisions"}],"predecessor-version":[{"id":10895,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10894\/revisions\/10895"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/10896"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10894"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10894"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10894"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-07-29 09:26:12 UTC -->