Visualização de leitura

BlackBasta Leaks: Lessons from the Ascension Health attack


The BlackBasta ransomware group’s leaked chat logs have proven to already be another unique and fascinating opportunity for researchers to better understand the internal operations of a Russia-based organised cybercrime enterprise. These leaks followed a major leak of Conti chat logs in 2022, which also proved to be a treasure trove of intelligence on the cybercrime enterprise. The BlackBasta gang consists of former Conti ransomware members and it should come as no surprise that their operations are similar in nature and structure.

Ransomware researchers have several valuable resources to conduct investigations with nowadays. This includes ransomware.live, which contains several resources including ransomch.at, a collection of negotiation chats between ransomware gangs and their victims, as well as the ransomware tool matrix and ransomware vulnerability matrix. These resources allow to deeply understand the capabilities and motivations of these ransomware gangs. However, leaked chat logs are the final missing piece of the puzzle and offer a deeper understanding from the cybercriminal’s very own perspective and organisational structure.

Active since April 2022, BlackBasta is one of the top-tier ransomware gangs and one of the largest cybercrime enterprises in the world. According to the US Cybersecurity Infrastructure and Security Agency (CISA), BlackBasta impacted up to 500 different businesses and critical infrastructure in North America, Europe, and Australia as of May 2024.

The importance of the Ascension Health incident

This blog shall dive deep into the Ascension Health attack by BlackBasta. It is a step-by-step extraction of the conversation between the BlackBasta members while they decide how to handle the attack.

The new insights around how BlackBasta and other ransomware gangs perceive being involved with incidents at healthcare sector victim should prove useful for incident responders, law enforcement, and governments that have to resolve these types of attacks on the healthcare sector on an alarmingly regularly basis.

Background

On 9 May 2024, mainstream news organisations in the US reported about a cyberattack and significant disruption of services of Ascension Health, one of the largest healthcare providers in the country. On 11 May 2024, BleepingComputer reported that BlackBasta was to blame for the attack on Ascension Health and that ambulances had been disrupted and patients were being redirected to other hospitals.

How the Incident Began

The BlackBasta attack on Ascension Health began many months before the ransomware was deployed on their network. Reconnaissance of Ascension Health by members of BlackBasta began around 3 November 2023. They shared 14 email addresses of Ascension Health employees, which we can only assume were used for phishing or password guessing. Ransomware gangs often used Zoominfo to profile their targets to determine whether it is worth it for them to attack and get a ransom from them.

A screenshot of a chat

AI-generated content may be incorrect.

The ransomware gang themselves wrote in their Matrix chat that CBS News had written about a cyberattack on Ascension Health on 9 May 2024 and exclaimed that “it looks like one of the largest attacks of the year.”

A screenshot of a chat

AI-generated content may be incorrect.

Another BlackBasta member “gg” confirmed in the chat that it was them and appeared to be surprised that the news was writing about it.

Later, “gg” appeared to feel bad about the attack and concerned that cancer patients were suffering. However, at this stage it is hard to tell if they are serious or being sarcastic.

A close-up of a white rectangular object

AI-generated content may be incorrect.

One member of BlackBasta who used the moniker “tinker” then stated that he wanted to be the negotiator for the BlackBasta team and began to strategize how to extract a ransom payment.

A close-up of a white background

AI-generated content may be incorrect.

“gg” says they encrypted Ascension Health’s network using the Windows Safe Mode Boot technique, which is a function that BlackBasta is well-known to do.

A screenshot of a computer

AI-generated content may be incorrect.

The negotiator, “tinker” begins to weigh up their options. He states he believes the FBI and CISA will be involved, as well as Mandiant and begins to compare the incident to the Change Healthcare attack by ALPHV/BlackCat (and later RansomHub) who received a 22 million USD ransom payment.

A close-up of a sign

AI-generated content may be incorrect.

A screenshot of a message

AI-generated content may be incorrect.

“gg” shares that all the stolen data was put on a server named “ftp8” and tagged as “ALBIR_DS” and says to “tinker” that he should “look at the folder name, everything we downloaded from them is there."

The operator, “gg” also shared a summary of the target environment of Ascension Health. This includes number of servers being over 12,000, what security tools they use such as Cylance, Tanium, and McAfee. Plus, “gg” said they downloaded over 1.4TB of data to "ftp8" and used BlackBasta ransomware version 4.0 and attacked them on 8 May 2024.

A screenshot of a chat

AI-generated content may be incorrect.

Interestingly, “gg” appears to have also recommended to bluff to the victim that they stole more than 1.5TB and say to the victim that they stole 3TB instead.

Negotiation Strategizing

After having established the details of the incident, Tinker (the negotiator) began to wonder about the likelihood of getting a ransom payment as well as estimate how much Ascension Health is likely losing per day.

A close-up of a message

AI-generated content may be incorrect.

Tinker (negotiator) then explains to the rest of the BlackBasta members involved in the attack what course of action they should take to get the ransom from Ascension Health. Tinker says they would normally set a 3% of the annual revenue and negotiate from there. They note that there are clear problems with the victim being a hospital and that this attack followed the Change Health attack by ALPHV/BlackCat. They also noted that they are worried as they believe the US National Security Agency (NSA) attacked TrickBot's servers four years ago and that the FBI took down Qakbot more recently. Tinker is  also worried that one of Ascension Health’s patients will die and they will be blamed and labelled as a terrorist attack.

Tinker also noted that when BlackSuit attacked Octapharma that it was labelled by the news as "hostile actions by Russia" and they warned that Conti was already under sanctions and that because they are tied to Conti they may not get paid.

Tinker, ransomware negotiator for BlackBasta, ultimately recommended giving the decryptor for free to Ascension Health and resorting to data theft extortion. This is notable, as it is a similar situation to the Irish HSE ransomware attack by Conti, who also provided the decryptor for free.

A close up of a text

AI-generated content may be incorrect.

Healthcare Impact

The fact Ascension Health is a major medical organisation with many patients appeared to take its toll on the BlackBasta members. Tinker wrote in the BlackBasta chat they he found a post on Reddit by a doctor that works for Ascension Health who described the damage of the attack.

A screenshot of a chat

AI-generated content may be incorrect.

Another member of BlackBasta, “nn” also found out that Ascension Health is a group of hospitals. He immediately recommends giving them a decryptor for free.

A close-up of a white background

AI-generated content may be incorrect.

A screenshot of a chat

AI-generated content may be incorrect.

Interestingly, “gg” compares the attack on Change Health and also recognises Mandiant and warns that the FBI and CISA will be involved. Plus, “gg” noted that they did not encrypt via virtualization (such as vCenter, ESXi or Hyper-V) and reconfirmed they used Safe Mode Boot. Further, “gg” was also inclined to give Ascension the decryptor for free too.

A screenshot of a chat

AI-generated content may be incorrect.

Another BlackBasta member, “nickolas” comments about the situation. He warned and was particularly concerned about law enforcement retaliation, such as hacking back, sanctions, indictments. He recommended auditing the entire infrastructure and having a rebrand of the BlackBasta name, which means changing the ransomware, leak site, and other personas.

A screenshot of a chat

AI-generated content may be incorrect.

Tinker (negotiator) is aware however of the risk of someone dying and how it will impact their chances of getting the ransom.

A white background with black text

AI-generated content may be incorrect.

Tinker also discussed the politics of the scenario. He compared the situation to the colonial pipeline incident of 2021. He mentioned how Russia reacted and arrested ransomware operators. He also brought up the war in Ukraine and how ransomware attacks on the US impact the politics with Russia.

A screenshot of a message

AI-generated content may be incorrect.

Tinker highlighted that the ransomware was used to encrypt patient data and how it caused the hospital management system to crash. He was particularly concerned about the ambulances being unable to operate but also tries to minimize the severity of the incident. Nevertheless, he asked to see the stolen data himself to get a better understanding of what data BlackBasta operators have that they can leverage against Ascension Health.

A screenshot of a chat

AI-generated content may be incorrect.

By the end of deliberations, Tinker recommends giving a free decryptor and then demand a ransom for the stolen data.

A screenshot of a chat

AI-generated content may be incorrect.

tinker edited his message to then clarify that he reckons they should demand a ransom in the 10s of millions USD or over 100 million USD.

A white background with black text

AI-generated content may be incorrect.

Ransomware Negotiations

The operator “gg” then shared the opening message to Ascension Health shared via the Black Basta negotiation portal:

A screenshot of a computer screen

AI-generated content may be incorrect.

The negotiator for Ascension Health (who BlackBasta believes is Mandiant) replied to the negotiation chat portal:

A screenshot of a computer

AI-generated content may be incorrect.

“gg” then clarified the terms of the ransom demand. A payment will be needed to delete and share the stolen data He maintains the offer to provide a free decryptor:

A screenshot of a computer

AI-generated content may be incorrect.

The negotiator for Ascension Health asked for the decryption tool:

A black and white rectangular object with white text

AI-generated content may be incorrect.

The decryptor was then provided to Ascension Health:

A screenshot of a computer program

AI-generated content may be incorrect.

Later, “gg” then shares a file tree for ""DS"" (which is equal to Ascension Health). The file is added to a ZIP and shared via a temp[.]sh link and is password protected:

A black and white screen with white text

AI-generated content may be incorrect.

The operator “gg” then uses Privat (a screenshot sharing site) to show the proof that they have deleted the data of Ascension Health:

From these messages, it appears no ransom was paid and BlackBasta returned the data and deleted it.

Change of Heart

The most interesting part of this engagement with Ascension Health by BlackBasta was that the members deliberated back and forth about whether to provide a free decryption tool but all appeared to be fine with demanding a ransom for the victim data.

The operator “gg” appears to have a change of heart. He exclaims that they (the members of the BlackBasta ransomware gang) are "pentesters" and not "killers" and claims he “held a meeting in the office” which is interesting as it further proves they are a cybercrime enterprise, potentially with full-time employees.

A screenshot of a chat

AI-generated content may be incorrect.

The operator “gg” decided to help Ascension Health and requests not to work on hospitals anymore.

A screenshot of a phone

AI-generated content may be incorrect.

He also said “the software will fly to the trash” which likely means the group was thinking of ditching the brand of BlackBasta and rebrand to another name. Finally, “gg” warns other BlackBasta members not to target hospitals any more:

A screenshot of a chat

AI-generated content may be incorrect.

The Impact of the BlackBasta Attack on Ascension Health

According to the HIPAA Journal, the personal data of up to 5.6 million patients was exposed and Ascension confirmed that some patient data was stolen during the attack. Ascension said that it found no evidence that the ransomware group gained access to electronic health records or other clinical systems, so full medical histories have not been stolen. During the attack, however, Ascension was forced to divert ambulances, close pharmacies, take critical IT systems offline and resort to pen and paper to record patient information. The attack affected a large percentage of its 136 hospitals across the US and took Ascension around 6 weeks to restore access to its electronic medical record system and resume normal operations. The ransomware attack reportedly caused delays in revenue cycle processes, claims submission, and payment processing, in addition to significant remediation costs.

Lessons Learned

This chat log confirms that BlackBasta attacked Ascension Health using version 4.0 of their ransomware and used the Safe Mode Boot technique on 12,000 endpoints of the healthcare system.

If reconnaissance began on 3 November 2023 and the attack happened on the 8 May 2024, that would make the amount of time they took to gain access and deploy the ransomware was up to 187 days long or around six months. Due to this, cybercriminal campaign appears to be comparable to a more focused state-sponsored level intrusion where months of planning and numerous attempts are made to infiltrate a target.

The BlackBasta negotiator, Tinker, believed that they were going to get a very high ransom payment in the 10s of millions or up to 100 million USD and compared the attack to the Change Health incident by ALPHV/BlackCat who got 22 million USD.

The high ransom payment by Change Health has appeared to be like a dinner bell for ransomware gangs to go after other healthcare sector victims. Paying the ransom as a healthcare organisation clearly has significant downstream impact on the rest of the industry and it should be an absolute last resort and default to be to never pay the ransom.

There was an interesting change of heart and moment where the operator “gg” decided to give up on the Ascension Health attack, provide them a decryptor, provide the data back to them, and share proof that they deleted it. The members of BlackBasta were clearly concerned about hack-backs from law enforcement or intelligence services, as well as sanctions and deanonymization. The BlackBasta team also mentioned several times during this incident that they were going to have to rebrand because of the attack.

Overall, this incident goes to show that even Russia-based cybercrime enterprises with dozens of members remain paranoid about being attack by law enforcement and intelligence services. It is really interesting that they themselves admit that their actions warrant such a response.

One of the key lessons to learn from this engagement is that if a healthcare organisation is attacked by a ransomware gang, then it would be a valid strategy to tell the news about the incident. News about patients lives being at risk and dying will get the attention of these ruthless cybercriminals who will realise the mistakes they made and are potentially likely to at least provide a free decryptor and may give up entirely on their ransom payment pursuit and move on to the next target.

Lastly, these chat logs appear to prove that the West’s policies aimed at increasing pressure on Russia-based ransomware gangs is evidently working. These organised cybercrime enterprises are beginning to alter their targeting behaviour as a result to avoid the wrath of law enforcement retaliation.

Investigating Anonymous VPS services used by Ransomware Gangs

One of the challenges with investigating cybercrime is the infrastructure the adversaries leverage to conduct attacks. Cybercriminal infrastructure has evolved drastically over the last 25 years, which now involves hijacking web services, content distribution networks (CDNs), residential proxies, fast flux DNS, domain generation algorithms (DGAs), botnets of IoT devices, the Tor network, and all sorts of nested services.

This blog shall investigate a small UK-based hosting provider known as BitLaunch as an example of how challenging it can be to tackle cybercriminal infrastructure. Research into this hosting provider revealed that they appear to have a multi-year history of cybercriminals using BitLaunch to host command-and-control (C2) servers via their Anonymous VPS service.

The year-on-year growing number of CobaltStrike C2 servers hosted on BitLaunch’s services could be an indicator of tacit collusion with cybercriminals through the facilitation of cheap and quick to procurement of VPSs that end up being used to launch ransomware attacks on all sorts of victims, including hospitals, schools, governments, companies, and charities.

The concept of aiding and abetting criminal activity in law is essentially when an individual or an organisation intentionally assists, facilitates, or encourages a crime. In this case, it would be aiding and abetting the creation of cybercriminal infrastructure. If a hosting provider ignores clear red flags (e.g., cryptocurrency payments from known illicit sources or use of servers for illegal activities), they might still be held criminally liable under wilful blindness under certain laws.

In the past, authorities have taken down bulletproof hosting (BPH) providers that knowingly support cybercrime, such as CyberBunker and LolekHost. In February 2025, the UK government also sanctioned a Russia-based BPH known as ZSERVERS (aka XHOST) for facilitating LockBit attacks.

A podcast version of the blog is available here.

Update: This blog was updated with a statement from BitLaunch (see the end of this blog).

Who is BitLaunch aka BL Networks aka BLNWX?

Active since at least 2017, BitLaunch (also known as BL Networks or BLNWX) is a virtual private server (VPS) reseller whose autonomous system number (ASN) is AS399629. Up to 48 IPv4 networks belong to BitLaunch which are used to "instantly launch a Linux or Windows VPS” where customers can “pay hourly with Bitcoin, Litecoin, and Ethereum, with no firm commitments." BitLaunch also supports their customers via a command-line (CLI) tool and a Python library. BitLaunch has another name, however, in their legal terms and conditions they go by Liber Systems and have their own separate website.

Why focus on BitLaunch?

BitLaunch is quite interesting as they present themselves as a UK-based company run by two local UK businessmen. Their “anonymous Bitcoin VPS” service is regularly abused for all sorts of cybercriminal activities. What triggered this research was the fact that their nickname “BLNWX” was regularly reappearing in cyber threat intelligence (CTI) vendor reports on ransomware and other cybercriminal campaigns. It is also worth highlighting that while BitLaunch own their own IP networks, they are a VPS reseller as well who works with DigitalOcean, Linode, and Vultr, as shown from their website below.

A screenshot of a computer

AI-generated content may be incorrect.

One website that reviews so-called “offshore services” (offshore[.]cat) has listed BitLaunch as being a “verified” offshore hoster that accepts cryptocurrency, only requires email request confirmation to open an account, and is described as allowing anyone to “create VPSs in seconds, using crypto” making them an attractive hoster for cybercriminals. Their service paired with their CLI tools and Python libraries makes it super easy to stand up C2 servers rapidly.

Command and Control (C2) infrastructure on BLNWX

Significant numbers of CobaltStrike C2s among other hacking tools and malware families have been discovered on BitLaunch. I would like to thank the owner of the C2IntelFeedsBot (@drb_ra) account on X/Twitter who assisted with this research by providing their feed of C2 servers discovered on BitLaunch.

The image below shows a sampling of the known C2 servers hosted with BitLaunch between 2021 and 2025. The most notable part of this diagram is the number of CobaltStrike C2 servers in particular. Cobalt Strike is a well-known C2 framework used by organised cybercriminal groups to launch ransomware attacks. It is also favoured by state-sponsored threat groups as well.

Over the last few years, several dozen C2 servers have been identified by the C2IntelFeedsBot and each year, the number of C2s has continued to grow as more cybercriminals identify BitLaunch as a preferable service to support their ransomware campaigns.

The image below displays the totals calculated between “2021-06-26 12:33:41" and "2025-02-05 18:46:10." It is not a complete picture by any means, but this independently verifiable data gives a decent idea of the rate at which BitLaunch is being used by cybercriminals, with each year since 2022 has trended upwards.

One of the interesting things about CobaltStrike is that it is a commercial offensive security tool (OST). It is issued to legitimate customers through licenses, which have a unique watermark. While there have been several cracked versions of CobaltStrike over the years, it is possible to track certain groups through their usage of the same CobaltStrike versions.

The image below shows the distribution of the CobaltStrike watermarks gathered from BitLaunch. Notably, “0” is the most common. This is often the case when analysing CobaltStrike watermarks as this signifies it is the cracked version.

OSINT collection and analysis of the CobaltStrike watermarks revealed potential connections to several well-known cybercriminal groups using BitLaunch who have a history of conducting ransomware attacks:

  1. "426352781” – This watermark is used by ShadowSyndicate, a ransomware affiliate group tracked by Group-IB which is connected to multiple Ransomware-as-a-Serivce (Raas) platforms. This watermark is also historically associated with CobaltStrike Beacons dropped by the Qakbot malware botnet.
  2. “206546002” – This watermark is also used by ShadowSyndicate as well as Blister Loader, PLAY ransomware, and FIN7-linked ransomware operators.
  3. “1580103824” – This watermark was linked to ShadowSyndicate as well, alongside the Cleo exploitation campaign attributed CL0P ransomware. A threat group tracked by CERT-UA as UAC-0056 has also been observed using this watermark too.
  4. ”987654321” – This watermark has been associated with the IcedID malware botnet and the Dagon Locker ransomware gang previously.
  5. ”1359593325” – This watermark has been used by CobaltStrike Beacons in campaigns attributed to the Russian Foreign Intelligence Service (SVR)
  6. “391144938” and “305419896” – These watermarks have been attributed to campaigns by multiple Chinese cyber-espionage campaigns tracked by SentinelOne, Recorded Future, Zscaler, and Cisco Talos.

C2s on BLNWX attributed to Ransomware Gangs by CTI vendors

There are a number of CTI reports over the last couple years that directly reference BitLaunch Networks (BLNWX) IP addresses as Indicators of Compromise (IOCs) as part of high-profile ransomware campaigns.

This includes attribution to the Yanluowang ransomware attack against Cisco, a C2 linked to the JavaScript more_eggs backdoor used by FIN6 (who is connected to ransomware campaigns), a dozen IPs attributed to Rhysida ransomware attacks, and a Rhysida and Interlock ransomware precursor campaign tracked as TAG-124, as well as the PaperCut exploitation campaign which involved both LockBit and CL0P.

The VirusTotal graph is available here.

Additional notable CTI alerts that called out BLNWX include a report on Latrodectus, a ransomware precursor campaign, by Proofpoint; Okta-themed phishing campaigns attributed to Scattered Spider, who has carried out ALPHV/BlackCat and RansomHub attacks, by Intel471; infrastructure used to enable the BlackBasta ransomware gang by QuadrantSec, as well as C2 servers of the IcedID malware botnet that has been used by ransomware gangs for initial access.

Assessment of BitLaunch

As of February 2025, BitLaunch's parent firm Liber Systems Limited is run by two UK-based directors according to UK Companies House. While they are profiting off this Anonymous VPS service they are not taking the appropriate steps to prevent their service from being used by ransomware and malware gangs. Organised cybercrime groups have evidently found and recognised this about BitLaunch and are leveraging the cheap, crypto-accepting service that doesn’t ask too many questions.

To be fair to BitLaunch, they appear to be responsive to takedowns and are noted on Offshore[.]cat as enforcing DMCA requests. The crux of the issue though is that the cybercriminals can use their service to rapidly spin up instances for C2 for a few hours and chuck it away again. This means there often no need to submit a takedown as the cybercriminals has already abandoned the C2 and can spin up another one. Therefore, the cybercriminals can continually leverage BitLaunch without interference.

As a security researcher, and not a police officer, I cannot comment on how cooperative BitLaunch have been with the police and it is probably not something BitLaunch would want to advertise to their customers anyway based on who some of their customers are.

For BitLaunch’s two directors, this works out nicely for them. They can take the cybercriminals money via cryptocurrency and also appear to be ethical and compliant by assisting with law enforcement takedown requests. Currently, they appear to be helping both the criminals and the police, and have been getting away with it for years.

On BitLaunch’s front page advertisement they highlight as the main focus as being able to pay hourly for the use VPS and that customers can pay in “anonymous cryptocurrency.” It is in my opinion, and that of other cybersecurity researchers I have spoken to about this (including red teamers and penetration testers), that this service is perfect for C2 servers and almost nothing else legitimate.

The Broader Issue with Anonymous VPSs

In BitLaunch’s blogs, they say they believe the internet should be "open, free, and devoid of interference by any single government or authority" adding that accept cryptocurrency because "citizens of some countries do not have bank accounts and can use Bitcoin instead" because the local banks have control over who their citizens can send money to. Their blogs also state that they believe internet users should be allowed to run their own virtual private networks (VPNs) for anti-surveillance and privacy reasons. They also provide lots of guides on how to configure private VPNs for this purpose. While this is a legitimate service that is useful for some people in specific situations, having it be abused by ransomware gangs is a situation that needs to be changed.

This issue of selling anonymous VPSs is not specific to this one company. BitLaunch is obviously a small company and proactively combating cybercriminals from registering VPSs on their service is an expensive and multi-pronged challenge for any hoster, which includes preventing abuse while preserving the privacy of their customers.

Hosters such as BitLaunch could use services such as Shodan, Abuse.ch, GreyNoise, OTX Alienvault, and AbuseIPDB to check if their IP addresses are being abused. One interesting example of a hoster trying to tackle this issue is how PQ Hosting (aka Stark Industries Solutions) announced publicly on their blog that they have partnered with Team Cymru, a netflow security intelligence firm. Alternatively, hosters could use a blockchain analytics platform like Chainalysis, TRM Labs, or Arkham Intelligence, to trace cryptocurrency payments from known illicit wallet clusters.

There will, however, always be some threats that slip through the net. It is undoubtedly a difficult challenge for small hosters who do not have funds to sacrifice on network observability tools or CTI platforms. Even some of the world’s largest hosters, such as Cloudflare struggle with this as well and end up having their services abused for cybercrime operations.

The anonymous VPS problem could be compared to issues in other industries such as stolen funds being used to buy gift cards or game keys that are then resold for money laundering. Another platform often abused for a variety of scams and phishing campaigns is Gmail. Is Google being wilfully negligent to cybercrime happening on their platform? That’s a question I shall leave for readers to decide on their own.

Overall, this type of issue is analogous to a hotel offering rooms for the night and organized criminals renting them to commit various types of crimes inside them. Ultimately, the criminals are the ones breaking the law, not the hotel, but if the hotel is being constantly made aware of these activities by bystanders and law enforcement, it is their duty to shut that activity down, to the best of their abilities.

What the UK Could Do About It

In this scenario around BitLaunch, there are three potential ways the UK could help stop these small hosters being taken advantage of by cybercriminal operations.

Firstly, the cybersecurity and hosting industry could launch an initiative through institutions, such as the British Computer Society (BCS) or something, that would work to convince hosting providers that the hassle being investigated by law enforcement agencies, sanctions, or the chance of being arrested is not worth the funds generated from selling C2 servers to cybercriminals.

Secondly, as BitLaunch (or Liber Systems) is registered here, the UK Government Department for Science, Innovation, and Technology (DSIT) could work with them and other small hosters to regulate the industry and provide support to these businesses to warn them of the dangers of offering unregulated VPS services and inform them how they contribute to the damage that ransomware attacks are having on the UK and elsewhere.

Third, providing free network observability services to hosters could also help them proactively shutdown C2 servers before they are weaponised against victims. All UK hosters can sign-up to the free UK government-provided service called MyNCSC, offered by the UK NCSC, which is part of GCHQ. Hosters will then get alerts when MyNCSC detects which IPs are flagged for hosting C2 servers (such as CobaltStrike).

As the UK government’s mandate is to “make the UK the safest place in the world to live and work online” then tackling the issue with these UK-based hosters supporting ransomware should also be one of those priorities.

Indicators of Compromise

Historic Malicious BLNWX IP addresses are available below:


Updated on 09.03.2025

Statement from BitLaunch following the publication of this blog:

"BitLaunch appreciates the conversation surrounding the misuse of VPS hosting services. It is an important topic, and there is always room for improvement and reflection. That said, we believe the article contains several key inaccuracies and misleading implications. We take the prevention of abuse on our platform very seriously, and we would like to offer the following context:

We reject the notion that BitLaunch may be in "tacit collusion with cybercriminals" due to the year-on-year growth of IPs associated with CobaltStrike C2 servers. In fact, the number of abusive IPs has not increased relative to BitLaunch's rapid infrastructure growth – it is just that more IP blocks are available overall.

At the time of writing, BitLaunch has 50 /24 prefixes announced over BGP, totalling 12,800 IP addresses. As a result, 82 C2s in 2024 represents just 0.6% of our IPs over the entire year. Across all first and third party hosts, abuse per month is around 1% of active servers.

We strongly disagree that BitLaunch is "not taking the appropriate steps to prevent their service from being used by ransomware and malware gangs". BitLaunch takes regular and concrete action against abuse, including no longer serving the Russian market. We employ a full-time, dedicated abuse team that already uses various tools to proactively and passively identify malicious servers. These tools include abuse.ch, urlscan, spamhaus, and more. Servers are suspended as soon as malicious activity is suspected, per our Acceptable Use policy.

The report implies that BitLaunch may be ignoring key red flags, such as accepting cryptocurrency from known illicit sources, and mentions that hosters can use blockchain analysis services to prevent this. BitLaunch already uses Elliptic for this purpose. We also disagree with the opinion that our service is "perfect for C2 servers and almost nothing else". As previously stated, abuse per month accounts for 1% of active servers despite BitLaunch accepting payments exclusively in cryptocurrency. There are numerous reasons to pay privately with cryptocurrency that do not involve illegal activity.

We believe the report fails to disclose a potential conflict of interest. The researcher works for Carrier Hotel Equinix, which serves some of our direct competitors. One such customer, PQ Hosting, is linked in the blog as a positive example of dealing with malicious activity.

Finally, we would like to thank BushidoToken for giving us a chance to issue this addendum. We welcome constructive critique on this topic and appreciate the opportunity to reflect on our abuse-prevention strategies and their communication."

Tracking Adversaries: Ghostwriter APT Infrastructure

Introduction to Infrastructure Pivoting

Pivoting on infrastructure is a handy skill for cyber threat intelligence (CTI) analysts to learn. It can help to reveal the bigger picture when it comes to malware, phishing, or network exploitation campaigns. Infrastructure pivoting essentially is the act of looking for more systems an adversary has created. The main benefit of this pursuit is the identification of additional targets or victims, more tools or malware samples, and ultimately new insights about the adversary’s capabilities.

If done correctly, being able to pivot on adversary infrastructure will be very useful during incident response (IR) engagements. For example, it may lead to being able to attribute the intrusion to a known adversary. This will help others during an IR engagement understand the level of threat posed to the victim organisation.

Receiving Threat Data

To be able to pivot on adversary infrastructure, threat data is needed such as the intelligence shared by threat reports put out by various researchers from public and private sector organisations. This scenario, however, involves relying on the analysis skills of other researchers to explain what the infrastructure is and when they observed it in use.

This blog will examine threat data provided by public sector organisations such as the Computer Emergency Response Team of Ukraine (CERT-UA) as well as cybersecurity vendors such as Deep Instinct, Cyble, and Fortinet. These organisations have shared indicators of compromise (IOCs) uncovered following analysis of adversary intrusion activities or upload to online malware sandboxes, such as VirusTotal, among others.

Introduction to the Ghostwriter Campaign

On 3 June 2024, Fortinet shared a report on malicious XLS macro documents leading to Cobalt Strike Beacons. Analysis of the XLS documents showed that they appeared to be targeting the Ukrainian military and linked to a known Belarusian state-sponsored APT group tracked as Ghostwriter (aka UNC1151, UAC-0057, TA445). On 4 June 2024, Cyble also shared a report on a similar campaign.  

In both reports, if the XLS was opened and the macros were executed by the target, a malicious DLL file was downloaded from an adversary-created domain. In Fortinet’s report, two similar “.shop” domains were mentioned. In Cyble’s report another “.shop” domain was also called out.

Overlapping IOCs

The first pivot on Ghostwriter APT infrastructure that will be demonstrated involves finding indicators of compromise (IOCs) such as domains and IP addresses that appear in multiple threat reports.

The fastest way to realize these overlaps is through continuous collection of reported IOCs into a Threat Intelligence Platform (TIP). This will reveal IOCs that appear in multiple threat reports through tagging and sources of where IOCs come from. Eventually, one domain or IP address will get reported by multiple entities and the connection will make itself apparent.

In Figure 1 (see below) the domain “goudieelectric[.]shop” appeared in both Cyble’s blog and Fortinet’s blog. Analysis of all three domains found that they use the same generic top-level domain (gTLD), registrar, and name servers, as well as have a robots.txt directory configured. These common infrastructure characteristics indicate that all three domains were created by the same adversary.

Figure 1. Three similar domains appearing in two threat reports.

Domain Registration & Hosting Overlaps

When more IOCs are reported in other threat reports it is possible to link them to other known domains, this is due to adversaries reusing the same registrars, name servers, and gTLDs.

In Figure 2 (see below), Deep Instinct reported two more domains that could also be linked to the previous three domains through the mutual use of the PublicDomainsRegistry registrar, Cloudflare name servers, and the robots.txt file.

Figure 2. Five similar domains that appear across three threat reports.

Further, CERT-UA reported three more domains (see Figure 3 below) that could be linked to the infrastructure cluster through this same method as well. This pattern of behaviour is a strong indicator that these domains were created by the same adversary.

Figure 3. Eight similar domains that appear across four threat reports.

Finding Unreported Domains

Since the domains from the above threat reports were collected and linked together through overlapping attributes, it is now possible to use these attributes to find more domains that had gone unreported.

Using a VirusTotal domain attribute query, additional domains can be found by using the following registration pattern:

  • Name Servers: CLOUDFLARE
  • Registrar: PublicDomainRegistry
  • TLD: *.shop

This revealed up to 24 domains that matched this pattern that were likely created by Ghostwriter, a state-sponsored APT group:

  • backstagemerch[.]shop
  • bryndonovan[.]shop
  • chaptercheats[.]shop
  • clairedeco[.]shop
  • connecticutchildrens[.]shop
  • disneyfoodblog[.]shop
  • eartheclipse[.]shop
  • empoweringparents[.]shop
  • foampartyhats[.]shop
  • goudieelectric[.]shop
  • ikitas[.]shop
  • jackbenimblekids[.]shop
  • kingarthurbaking[.]shop
  • lansdownecentre[.]shop
  • lauramcinerney[.]shop
  • medicalnewstoday[.]shop
  • moonlightmixes[.]shop
  • penandthepad[.]shop
  • physio-pedia[.]shop
  • semanticscholar[.]shop
  • simonandschuster[.]shop
  • thevegan8[.]shop
  • twisterplussize[.]shop
  • utahsadventurefamily[.]shop

Note: VirusTotal domain searches are only available to VirusTotal Enterprise users. There are other providers which allow you to search for domain registration patterns such as DomainTools, Validin, and Zetalytics. There also some free OSINT sites such as nslookup.io and viewdns.info that can be useful in certain scenarios.

Finding Related Malware Samples

Using the list of similar domains that were uncovered through the registration pattern search, it is then possible to find additional malware samples communicating with them.

This can be achieved by looking at domains in VirusTotal and checking the Relations tab can show communicating files as shown in Figure 4 below.

Figure 4. Additional malware samples uncovered via the VirusTotal relations tab

Using a VirusTotal graph can help to reveal every communicating file with every domain discovered through the registration pattern search, as shown in Figure 5 below.

Figure 5. All communicating files with every additional domain identified.

URL to the VirusTotal Graph: https://www.virustotal.com/graph/embed/gd2c04407d9ba4b75b2ce73d6155d166d3ef75eaf29894ff5ac287c90400072bc?theme=dark

URL to the VirusTotal Collection: https://www.virustotal.com/gui/collection/2aa6b36a717be8bc49f7925434ca40f3ecb9f628414b491da3e985677508ca08/iocs

Lessons Learned

In conclusion, it is important for CTI analysts to closer inspect the attributes of the IOCs they come across. It is not uncommon for state-sponsored APT groups to make such mistakes when creating their infrastructure to launch attacks from. By exploiting this fact, CTI analysts can learn much more about the adversary’s targets, capabilities, and the behaviours of the humans themselves behind such campaigns.

The importance of this type of work was demonstrated in December 2023 when the US Treasury sanctioned members of the Russian APT group known as Callisto (aka Star Blizzard, BlueCharlie, COLDRIVER, GOSSAMER BEAR). The real world identity of Andrey Korinets was revealed after he was sanctioned for fraudulently creating and registering malicious domain infrastructure for Russian federal security service (FSB) spear phishing campaigns.

❌