home.social

#blackbasta — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #blackbasta, aggregated by home.social.

fetched live
  1. Ransomware: математический аппарат на службе зла

    Привет, Хабр! Я Илья Борисов, старший специалист отдела экспертизы MaxPatrol EDR антивирусной лаборатории Positive Technologies. В 2025 году команда аналитиков антивирусной лаборатории PT ESC провела исследование актуальных семейств ransomware (aka шифровальщиков), чтобы повысить эффективность их обнаружения нашим продуктом. Этот вид ВПО оказался одной из наиболее значимых и заметных разновидностей вредоносов, используемых в атаках в 2025 году. Мы проанализировали образцы, замеченные в период с конца 2024 года по конец 2025-го. Были разобраны как давно известные семейства шифровальщиков, такие как Black Basta, MedusaLocker и LockBit, и относительно недавно появившиеся Lynx, HellCat и BERT. В этой статье хочу поделиться результатами этого исследования. Для начала расскажу про типы шифровальщиков, на кого они нацелены, как работают, подсвечу технические детали, а также ретроспективно прослежу некоторые тенденции в эволюции ransomware.

    habr.com/ru/companies/pt/artic

    #ransomware #шифровальщики #вредоносное_по #lockbit #blackbasta #ransom #вымогательство #выкуп #кибератаки

  2. #cyber #cyberSecurity #conti #blackBasta

    infosec.exchange/@BleepingComp
    [email protected] - The identity of the Black Basta ransomware gang leader has been confirmed by law enforcement in Ukraine and Germany, and the individual has been added to the wanted list of Europol and Interpol.

    bleepingcomputer.com/news/secu

  3. @deepthoughts10 @BleepingComputer Agreed, AVCheck was used by BlackBasta to check their malware creations. Would be awesome to see scanner[.]to taken down soon as well. Lots of malicious binaries and scripts scanned on scanner[.]to in the Basta chat logs. The screenshot is one of their sample's results pages.

    #BlackBasta #Ransomware #CTI #threatintelligence

  4. Une campagne de malware très avancée a détourné KeePass, un gestionnaire de mots de passe open source populaire.
    ⬇️
    Des cybercriminels ont modifié le code source de KeePass, l’ont recompilé avec un certificat numérique valide et diffusé via de la pub malveillante (malvertising) sur des moteurs de recherche. (merci-pas-merci Google)

    Résultat : une version piégée de KeePass était distribuée à des victimes pensant télécharger l’original. Cette fausse version :

    Exfiltrait les bases de données KeePass avec les mots de passe en clair

    Déployait un malware furtif (Cobalt Strike) servant à prendre le contrôle de l’ordi et propager une attaque (type ransomware).

    Le malware se cachait sous des fichiers normaux, utilisait le nom “KeeLoader” et évitait d’être détecté par les antivirus. Il restait discret jusqu’à l’ouverture d’un fichier de mot de passe.

    4️⃣ Technique d’infection :

    • Faux site KeePass (ex: keeppaswrd.com)

    • Téléchargement infecté

    • Déploiement du malware + vol des mots de passe

    • Prise de contrôle du réseau (RDP, SSH, etc.)

    • Chiffrement des données (ransomware)

    Des indices montrent des liens avec des groupes comme Black Basta et l’utilisation de services criminels "as-a-service" (certificats, infra, etc.).

    N’abandonnons pas les gestionnaires de mots de passe…
    Mais téléchargeons-les uniquement depuis les sites officiels

    "KeePass trojanised in advanced malware campaign

    In 2025, WithSecure discovered a trojanised, and signed version of the open-source password manager KeePass, used to deliver malware and exfiltrate credentials. Named KeeLoader, this modified installer was signed with trusted certificates and distributed via malvertising and typo-squat domains to victims across Europe."
    👇
    labs.withsecure.com/publicatio
    👇📄
    labs.withsecure.com/content/da

    #CyberVeille #KeePass #BlackBasta

  5. #BlackBasta : The Fallen #Ransomware Gang That Lives On

    After a series of setbacks, the notorious Black Basta ransomware gang went underground. Researchers are bracing for its probable return in a new form.
    #scammer #security #privacy

    wired.com/story/black-basta-ra

  6. A massive leak of internal chat logs from the notorious Black Basta ransomware-as-a-service (RaaS) group has exposed potential ties to Russian authorities, extensive use of artificial intelligence in its operations and plans for a complete rebranding.

    computing.co.uk/news/2025/secu

    #technews #ransomware #blackbasta #raas #infosec #cybersecurity #russia

  7. 📦 Our latest investigation of Black Basta's leaked chats shows how they were plotting to exploit open source package registries to deploy ransomware, plus our analysis of & wiperware packages already in the wild.

    socket.dev/blog/black-basta-de

  8. Happy Monday everyone!

    Today's #readoftheday is brought to you by Trend Micro and they share their findings related to #BlackBasta and #CactusRansomware adding a piece of malware known as #BackConnect to their toolbox.

    The report states "The BackConnect malware is a tool that cybercriminals use to establish and maintain persistent control over compromised systems. Once infiltrated, it grants attackers a wide range of remote control capabilities, allowing them to execute commands on the infected machine. This enables them to steal sensitive data, such as login credentials, financial information, and personal files."

    Behaviors (MITRE ATT&CK):
    Initial Access - TA0001:
    Phishing: Spearphishing Voice - T1566.004 - The attackers conducted an email bombing campaign then contacted the victim posing as "IT Support" or "HelpDesk".

    Command and Control - TA0011:
    Remote Access Software - T1219 -
    The attackers used QuickAssist to access the victim's environment once they were successfully social engineered.

    Lateral Movement - TA0008:
    Remote Services: SMB/ Windows Admin Shares - T1021.002 -
    Remote Services: Windows Remote Management - T1021.006
    The attackers leveraged both SMB, shared folders, and WinRM for lateral movement.

    Go check out the rest of the technical details! Enjoy and Happy Hunting!

    Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal
    trendmicro.com/en_us/research/

    Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting