#blackbasta — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #blackbasta, aggregated by home.social.
-
Node.js: Old Technique Makes a Comeback
A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.
Pulse ID: 6a996ed3562f794a642feaaf
Pulse Link: https://otx.alienvault.com/pulse/6a996ed3562f794a642feaaf
Pulse Author: AlienVault
Created: 2026-09-03 12:57:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#8Base #Akira #Asia #BackDoor #BlackBasta #BlockChain #CyberSecurity #EtherHiding #Government #InfoSec #Java #JavaScript #Malware #Nodejs #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #Rust #bot #AlienVault
-
Node.js: Old Technique Makes a Comeback
A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.
Pulse ID: 6a996ed3562f794a642feaaf
Pulse Link: https://otx.alienvault.com/pulse/6a996ed3562f794a642feaaf
Pulse Author: AlienVault
Created: 2026-09-03 12:57:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#8Base #Akira #Asia #BackDoor #BlackBasta #BlockChain #CyberSecurity #EtherHiding #Government #InfoSec #Java #JavaScript #Malware #Nodejs #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #Rust #bot #AlienVault
-
Node.js: Old Technique Makes a Comeback
A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.
Pulse ID: 6a996ed3562f794a642feaaf
Pulse Link: https://otx.alienvault.com/pulse/6a996ed3562f794a642feaaf
Pulse Author: AlienVault
Created: 2026-09-03 12:57:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#8Base #Akira #Asia #BackDoor #BlackBasta #BlockChain #CyberSecurity #EtherHiding #Government #InfoSec #Java #JavaScript #Malware #Nodejs #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #Rust #bot #AlienVault
-
Node.js: Old Technique Makes a Comeback
A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.
Pulse ID: 6a996ed3562f794a642feaaf
Pulse Link: https://otx.alienvault.com/pulse/6a996ed3562f794a642feaaf
Pulse Author: AlienVault
Created: 2026-09-03 12:57:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#8Base #Akira #Asia #BackDoor #BlackBasta #BlockChain #CyberSecurity #EtherHiding #Government #InfoSec #Java #JavaScript #Malware #Nodejs #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #Rust #bot #AlienVault
-
Node.js: Old Technique Makes a Comeback
A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.
Pulse ID: 6a996ed3562f794a642feaaf
Pulse Link: https://otx.alienvault.com/pulse/6a996ed3562f794a642feaaf
Pulse Author: AlienVault
Created: 2026-09-03 12:57:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#8Base #Akira #Asia #BackDoor #BlackBasta #BlockChain #CyberSecurity #EtherHiding #Government #InfoSec #Java #JavaScript #Malware #Nodejs #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #Rust #bot #AlienVault
-
Operation Endgame 2: 15 Millionen E-Mail-Adressen und 43 Millionen Passwörter | Security https://www.heise.de/news/Operation-Endgame-2-15-Millionen-E-Mail-Adressen-und-43-Millionen-Passwoerter-10396199.html #HaveIBeenPwned #Malware #Ransomware #Hacking #CyberCrime #Bumblebee #Latrodectus #Qakbot #DanaBot #HijackLoader #Warmcookie #Trickbot #Prolock #Doppelpaymer #REvil #Conti #BlackBasta #Cactus #OperationEndgame2
-
Operation Endgame 2.0: 20 Haftbefehle, Hunderte Server außer Gefecht gesetzt | Security https://www.heise.de/news/Operation-Endgame-2-0-20-Haftbefehle-Hunderte-Server-ausser-Gefecht-gesetzt-10394215.html #OperationEndgame #OperationEndgame2 #Malware #Ranswomware #Hacking #CyberCrime #Bumblebee #Latrodectus #Qakbot #DanaBot #HijackLoader #Warmcookie #Trickbot #Prolock #Doppelpaymer #REvil #Conti #BlackBasta #Cactus