Threat Intelligence Tarot
Vol. II · 98
Criminal (Russian-speaking, Conti splinter group)
★★★★★
risk 4/5
✦ The Black Choir ✦
Black Basta
UNC4393
HealthcareManufacturingConstructionFinanceTechnologyCritical infrastructure
Active since April 2022 · Financial extortion, Ransomware-as-a-Service
The Black Choir moves in perfect institutional silence, each member playing a prescribed role in an orchestra of extortion. From Conti's ashes it rose, inheriting both the playbook and the ruthlessness to use it on hospitals.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
Notable Operations
- ◆Ascension Health attack (2024, 140 hospitals disrupted nationwide)
- ◆500+ organizations breached across 2 years of operation
- ◆ABB industrial automation breach
- ◆Cobalt Strike and Qakbot delivery pipeline for enterprise-scale ransomware
Defenses
- ▸Block macro execution in Office documents from external sourcesCIS Control 9 ↗
- ▸Phishing-resistant MFA on all RDP, VPN, and remote access pathsNIST CSF: PR.AC ↗
- ▸Healthcare-specific incident response playbook with downtime proceduresNIST CSF: RC.RP ↗
- ▸Offline immutable backups of critical clinical and operational systemsCIS Control 11 ↗
Reversed: Their Weakness
Law enforcement disruption of Qakbot in 2023 severed a critical initial access vector. Organizations that block macro-enabled documents and enforce MFA on all remote access significantly delay or prevent compromise.
Share this adversary profile
Compare →swipe to browse
Related Adversaries
Data sourced from MITRE ATT&CK. For educational purposes.