Inside Ransomware: Facts and Findings from the Blackbasta and Lockbit Leaks

Director, Offensive Security, risk3sixty

00:00

/

00:00

When an anonymous actor calling themselves “ExploitWhispers” posted nearly a year’s worth of BlackBasta’s internal Matrix chats in February 2025, the industry received an unfiltered window into the criminal enterprise behind dozens of high-profile intrusions.

Twelve weeks later, a separate breach dumped the entire MySQL backend of LockBit’s affiliate panel. 20 tables covering build pipelines, negotiation transcripts, and cryptocurrency payout data were released onto public code-sharing sites with a Tor-site defacement confirming the compromise. Together these disclosures offer something incident responders rarely get: the attackers own words, workflows, and source artifacts.

In this talk we will take a deep dive into those data sets—walking through the process of parsing thousands of lines of attacker conversations, configuration files, and build logs to surface the tactics, techniques, and procedures (TTPs) that drive day-to-day ransomware operations.

This talk will focus on the approach for processing these large data sets, how affiliate recruitment, initial access, payload testing, negotiation, and cash-out weave together into a repeatable playbook, and the CI/CD build pipelines which allow for rapid development and deployment of malicious payloads.

Attendees will leave with a comprehensive understanding of how ransomware crews operate, insights into their financial gains, and the underlying motivations that drive their activities.

A Movement to Counter Emerging Threats.

This is some text inside of a div block.
The SESSIONS
This is some text inside of a div block.
The SESSIONS
This is some text inside of a div block.

00:00

/

00:00

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript