Transcript
A (0:00)
Foreign.
B (0:06)
This is Katanin Campano and this is a Risky Business interview with Will Thomas, the co founder of CTI Community Research Project curated intelligence and author and instructor at the SANS Institute. Welcome, Will.
A (0:17)
Thanks, Kathleen. Thanks for having me on.
B (0:19)
I invited Will to have a chat about something that happened earlier this month when internal chats leaked from the Blkbasta ransomware group. Chats that expose quite a lot of information. The leak, I don't think after a week we know where exactly it originated, but it was everywhere. On hacking forums, Telegram, Mega. An individual going by the name of bastawhisperer allegedly leaked the internal chat logs of the black Basta gang they extracted from a Matrix chat server. The leak contains about 200,000 messages, so it's quite a lot of them. I don't think anyone them from start to finish, but they only cover about one year of the group's activity from September 2023 to September 2024. So it's not up to the latest development with the gang. The security firm which first spotted the leaks product says they've been monitoring the gang and the group basically kind of stopped all the activity at the start of the year. So there's three months missing from the leak which might have showed how the gang disbanded, but they're not in there. So we're here to talk about what's in there. I know you published a blog post last week when you specifically looked at the group and how they ransomed a US Healthcare chain named Ascension Health. The attack took place a few months after another ransomware attack on a US Healthcare provider named Change Healthcare basically crippled a lot of the US medical system like it was a big deal. Even in mainstream media, where the White House were constantly being asked, what's being done to restore access to medical payments through Change Healthcare systems. It was a very big deal. And initially when Blkbasta ransomed Ascension Health, they realized, oh my God, we hit another major provider, we're going to pay. They're basically salivating in the chats, but they quickly realized they kind of screwed up. So what's the story of that attack?
A (2:11)
Thanks so much, Caitlin. Yeah, thanks for providing that background info. I think it's been a really interesting case of going through hundreds of thousands of messages, right. Trying to piece this all together step by step and trying to get into the head of the adversaries whilst they're. Because the chat messages are live from when they're actually dealing with it at the time of the event. So you can really feel like you're Sat in the room with them, watching them, trying to handle this. You almost. One of the sudden realizations I had while I was going through these messages was that it almost feels like you're some sort of, you know, government agency that's, you know, gained access to all of these internal communications. But the fact that they've leaked, they've kind of, you know, we all have access to it. So that's really interesting. But basically, from going through these chats, you know, as I was starting to uncover the mystery of this Ascension Health incident, I was coming across all sorts of interesting messages. In one case, to another company, they demanded a 28.7 million US dollar ransom initially. And then there's another message I came across where one of the companies agreed to pay, like a $750,000 ransom from the UK. So it's all sorts of really crazy stuff in these chat logs, but as I started to pick up on this case of Ascension Health, I could see the adversaries going from, yes, from thinking that it's going to be a massive payday, to suddenly having regret, having instant regret, being worried about people dying and having cancer patients, delayed appointments, or the maternity ward being impacted and ambulances being redirected. So as the news was breaking about the attack, the ransomware gang was actually paying attention to that as the news broke and sharing it amongst themselves, making comments. And there was this very poignant message that some of them were repeating, which was, we are pen testers and not killers. Which is a pretty interesting thing to come across without. This is something we would learn without ever seeing it ourselves, without having access to this chat log. But it's quite evident from these messages, as they were handling the intrusion, that they began to realize basically a massive mistake that they've made. And the money, the idea of getting millions of dollars quickly turned into panic and paranoia.
