KELA REPORT

Unveiling Black Basta’s Use of PhaaS Platforms Report

How Top-Tier Ransomware Relies on External Phishing Services.

Share:

A new investigation by KELA reveals how ransomware operators like Black Basta rely on professionalized Phishing-as-a-Service (PhaaS) offerings to scale their initial access operations. Based on leaked internal chats, the report exposes how these underground services play a critical role in the broader cybercrime ecosystem.

This report is for CISOs, threat intel analysts, SOC teams, and incident responders focused on ransomware defense and early access detection.

In this report, you’ll learn:

  • How demand for PhaaS has surged 650% since early 2023
  • Which phishing tools and vendors Black Basta uses, including EvilVNC, kalashnikov, and verb0
  • Intelligence and indicators for detecting access sold through phishing services
  • Strategic recommendations for threat intelligence and security teams

Download the Report

Related Resources

KELA on-demand webinar banner: The TeamPCP arrests, from the inside, with Ben Kapon and Jimmy

The TeamPCP arrests, from the inside

KELA report cover: TeamPCP Threat Actor Profile

TeamPCP Threat Actor Profile

KELA press release banner: "Breaking: KELA research leads to alleged TeamPCP members arrested," with police escorting a person in custody

KELA research leads to alleged TeamPCP Members Arrested