#blackbasta — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #blackbasta, aggregated by home.social.
-
New Backdoor May be Linked to Ransomware Access Broker
A stealthy new backdoor called Mistic has been deployed in cybercrime intrusions since April 2026, potentially linked to Woodgnat, an initial access broker associated with multiple ransomware operations including Qilin, Interlock, Rhysida, Akira, 8Base and Black Basta. Mistic was deployed alongside ModeloRAT in at least one case, a tool developed by Woodgnat. The backdoor uses sideloading techniques through legitimate Microsoft files and executes payloads in memory without writing to disk. It includes typical backdoor capabilities plus a self-delete kill switch for enhanced stealth. Targeting appears opportunistic across insurance, education, IT and professional services sectors. Woodgnat operates as an IAB, establishing durable remote access within enterprises and selling this access to ransomware affiliates, using various social-engineering techniques including ClickFix, FileFix and CrashFix lures delivered through compromised WordPress sites.
Pulse ID: 6a3bde32e46aafdb90f9593b
Pulse Link: https://otx.alienvault.com/pulse/6a3bde32e46aafdb90f9593b
Pulse Author: AlienVault
Created: 2026-06-24 13:40:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#8Base #Akira #BackDoor #BlackBasta #CyberCrime #CyberSecurity #ELF #Education #InfoSec #Microsoft #OTX #OpenThreatExchange #RAT #RDP #RansomWare #Rhysida #SideLoading #Word #Wordpress #bot #AlienVault
-
New Backdoor May be Linked to Ransomware Access Broker
A stealthy new backdoor called Mistic has been deployed in cybercrime intrusions since April 2026, potentially linked to Woodgnat, an initial access broker associated with multiple ransomware operations including Qilin, Interlock, Rhysida, Akira, 8Base and Black Basta. Mistic was deployed alongside ModeloRAT in at least one case, a tool developed by Woodgnat. The backdoor uses sideloading techniques through legitimate Microsoft files and executes payloads in memory without writing to disk. It includes typical backdoor capabilities plus a self-delete kill switch for enhanced stealth. Targeting appears opportunistic across insurance, education, IT and professional services sectors. Woodgnat operates as an IAB, establishing durable remote access within enterprises and selling this access to ransomware affiliates, using various social-engineering techniques including ClickFix, FileFix and CrashFix lures delivered through compromised WordPress sites.
Pulse ID: 6a3bde32e46aafdb90f9593b
Pulse Link: https://otx.alienvault.com/pulse/6a3bde32e46aafdb90f9593b
Pulse Author: AlienVault
Created: 2026-06-24 13:40:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#8Base #Akira #BackDoor #BlackBasta #CyberCrime #CyberSecurity #ELF #Education #InfoSec #Microsoft #OTX #OpenThreatExchange #RAT #RDP #RansomWare #Rhysida #SideLoading #Word #Wordpress #bot #AlienVault
-
Ransomware: математический аппарат на службе зла
Привет, Хабр! Я Илья Борисов, старший специалист отдела экспертизы MaxPatrol EDR антивирусной лаборатории Positive Technologies. В 2025 году команда аналитиков антивирусной лаборатории PT ESC провела исследование актуальных семейств ransomware (aka шифровальщиков), чтобы повысить эффективность их обнаружения нашим продуктом. Этот вид ВПО оказался одной из наиболее значимых и заметных разновидностей вредоносов, используемых в атаках в 2025 году. Мы проанализировали образцы, замеченные в период с конца 2024 года по конец 2025-го. Были разобраны как давно известные семейства шифровальщиков, такие как Black Basta, MedusaLocker и LockBit, и относительно недавно появившиеся Lynx, HellCat и BERT. В этой статье хочу поделиться результатами этого исследования. Для начала расскажу про типы шифровальщиков, на кого они нацелены, как работают, подсвечу технические детали, а также ретроспективно прослежу некоторые тенденции в эволюции ransomware.
https://habr.com/ru/companies/pt/articles/1039170/
#ransomware #шифровальщики #вредоносное_по #lockbit #blackbasta #ransom #вымогательство #выкуп #кибератаки
-
Ransomware: математический аппарат на службе зла
Привет, Хабр! Я Илья Борисов, старший специалист отдела экспертизы MaxPatrol EDR антивирусной лаборатории Positive Technologies. В 2025 году команда аналитиков антивирусной лаборатории PT ESC провела исследование актуальных семейств ransomware (aka шифровальщиков), чтобы повысить эффективность их обнаружения нашим продуктом. Этот вид ВПО оказался одной из наиболее значимых и заметных разновидностей вредоносов, используемых в атаках в 2025 году. Мы проанализировали образцы, замеченные в период с конца 2024 года по конец 2025-го. Были разобраны как давно известные семейства шифровальщиков, такие как Black Basta, MedusaLocker и LockBit, и относительно недавно появившиеся Lynx, HellCat и BERT. В этой статье хочу поделиться результатами этого исследования. Для начала расскажу про типы шифровальщиков, на кого они нацелены, как работают, подсвечу технические детали, а также ретроспективно прослежу некоторые тенденции в эволюции ransomware.
https://habr.com/ru/companies/pt/articles/1039170/
#ransomware #шифровальщики #вредоносное_по #lockbit #blackbasta #ransom #вымогательство #выкуп #кибератаки
-
Ransomware: математический аппарат на службе зла
Привет, Хабр! Я Илья Борисов, старший специалист отдела экспертизы MaxPatrol EDR антивирусной лаборатории Positive Technologies. В 2025 году команда аналитиков антивирусной лаборатории PT ESC провела исследование актуальных семейств ransomware (aka шифровальщиков), чтобы повысить эффективность их обнаружения нашим продуктом. Этот вид ВПО оказался одной из наиболее значимых и заметных разновидностей вредоносов, используемых в атаках в 2025 году. Мы проанализировали образцы, замеченные в период с конца 2024 года по конец 2025-го. Были разобраны как давно известные семейства шифровальщиков, такие как Black Basta, MedusaLocker и LockBit, и относительно недавно появившиеся Lynx, HellCat и BERT. В этой статье хочу поделиться результатами этого исследования. Для начала расскажу про типы шифровальщиков, на кого они нацелены, как работают, подсвечу технические детали, а также ретроспективно прослежу некоторые тенденции в эволюции ransomware.
https://habr.com/ru/companies/pt/articles/1039170/
#ransomware #шифровальщики #вредоносное_по #lockbit #blackbasta #ransom #вымогательство #выкуп #кибератаки
-
Internationale Fahndung nach Kopf von #BlackBasta - inside-it.ch https://www.inside-it.ch/internationale-fahndung-nach-kopf-von-black-basta-20260116 #Ransomware #Malware #CyberCrime
-
Internationale Fahndung nach Kopf von #BlackBasta - inside-it.ch https://www.inside-it.ch/internationale-fahndung-nach-kopf-von-black-basta-20260116 #Ransomware #Malware #CyberCrime
-
German police have identified the alleged ringleader of Black Basta ransomware, placing him on the EU most-wanted list with an INTERPOL Red Notice.
Black Basta is linked to ~700 global attacks since 2022.
Does naming leadership actually disrupt RaaS operations long-term?
-
#cyber #cyberSecurity #conti #blackBasta
https://infosec.exchange/@BleepingComputer/115906316667250247
[email protected] - The identity of the Black Basta ransomware gang leader has been confirmed by law enforcement in Ukraine and Germany, and the individual has been added to the wanted list of Europol and Interpol. -
Des nouvelles de la lutte contre le #CyberCrime par le #FBI : "Révélations sur le « Group 78 », une unité secrète américaine chargée de la lutte contre les cybercriminels" #Group78 #CyberSécurité #BlackBasta ...
-
Fake Ukrainian Police Emails Spread New CountLoader Malware Loader https://hackread.com/fake-ukrainian-police-emails-countloader-malware-loader/ #Cybersecurity #CyberAttacks #PhishingScam #CountLoader #BlackBasta #Ransomware #Security #Phishing #LockBit #Malware #Ukraine #Police #Russia #Fraud #Qilin #Scam
-
Fake Ukrainian Police Emails Spread New CountLoader Malware Loader https://hackread.com/fake-ukrainian-police-emails-countloader-malware-loader/ #Cybersecurity #CyberAttacks #PhishingScam #CountLoader #BlackBasta #Ransomware #Security #Phishing #LockBit #Malware #Ukraine #Police #Russia #Fraud #Qilin #Scam
-
Threat Intelligence Executive Report – Volume 2025, Number 3 – Source: news.sophos.com https://ciso2ciso.com/threat-intelligence-executive-report-volume-2025-number-3-source-news-sophos-com/ #postquantumcryptography #employmentscam #humanresources #ThreatResearch #GOLDREBELLION #nakedsecurity #0CISO2CISO #BlackBasta #NorthKorea #featured #ctu
-
Threat Intelligence Executive Report – Volume 2025, Number 3 – Source: news.sophos.com https://ciso2ciso.com/threat-intelligence-executive-report-volume-2025-number-3-source-news-sophos-com/ #postquantumcryptography #employmentscam #humanresources #ThreatResearch #GOLDREBELLION #nakedsecurity #0CISO2CISO #BlackBasta #NorthKorea #featured #ctu
-
Different Tinker.
-
Different Tinker.
-
@deepthoughts10 @BleepingComputer Agreed, AVCheck was used by BlackBasta to check their malware creations. Would be awesome to see scanner[.]to taken down soon as well. Lots of malicious binaries and scripts scanned on scanner[.]to in the Basta chat logs. The screenshot is one of their sample's results pages.
-
@deepthoughts10 @BleepingComputer Agreed, AVCheck was used by BlackBasta to check their malware creations. Would be awesome to see scanner[.]to taken down soon as well. Lots of malicious binaries and scripts scanned on scanner[.]to in the Basta chat logs. The screenshot is one of their sample's results pages.
-
Operation Endgame 2: 15 Millionen E-Mail-Adressen und 43 Millionen Passwörter | Security https://www.heise.de/news/Operation-Endgame-2-15-Millionen-E-Mail-Adressen-und-43-Millionen-Passwoerter-10396199.html #HaveIBeenPwned #Malware #Ransomware #Hacking #CyberCrime #Bumblebee #Latrodectus #Qakbot #DanaBot #HijackLoader #Warmcookie #Trickbot #Prolock #Doppelpaymer #REvil #Conti #BlackBasta #Cactus #OperationEndgame2
-
Operation Endgame 2.0: 20 Haftbefehle, Hunderte Server außer Gefecht gesetzt | Security https://www.heise.de/news/Operation-Endgame-2-0-20-Haftbefehle-Hunderte-Server-ausser-Gefecht-gesetzt-10394215.html #OperationEndgame #OperationEndgame2 #Malware #Ranswomware #Hacking #CyberCrime #Bumblebee #Latrodectus #Qakbot #DanaBot #HijackLoader #Warmcookie #Trickbot #Prolock #Doppelpaymer #REvil #Conti #BlackBasta #Cactus
-
International Operation Targets Qakbot Hacker, $24M in Crypto Seized https://thecyberexpress.com/doj-indicts-alleged-qakbot-malware/ #RustamRafailevichGallyamov #USJusticeDepartment #ransomwareattacks #CryptoCrackdown #maliciousemails #RansomwareNews #cryptocurrency #FirewallDaily #Qakbotmalware #BlackBasta #CyberNews #Gallyamov #Qakbot #REvil #FBI
-
International Operation Targets Qakbot Hacker, $24M in Crypto Seized https://thecyberexpress.com/doj-indicts-alleged-qakbot-malware/ #RustamRafailevichGallyamov #USJusticeDepartment #ransomwareattacks #CryptoCrackdown #maliciousemails #RansomwareNews #cryptocurrency #FirewallDaily #Qakbotmalware #BlackBasta #CyberNews #Gallyamov #Qakbot #REvil #FBI
-
Une campagne de malware très avancée a détourné KeePass, un gestionnaire de mots de passe open source populaire.
⬇️
Des cybercriminels ont modifié le code source de KeePass, l’ont recompilé avec un certificat numérique valide et diffusé via de la pub malveillante (malvertising) sur des moteurs de recherche. (merci-pas-merci Google)Résultat : une version piégée de KeePass était distribuée à des victimes pensant télécharger l’original. Cette fausse version :
Exfiltrait les bases de données KeePass avec les mots de passe en clair
Déployait un malware furtif (Cobalt Strike) servant à prendre le contrôle de l’ordi et propager une attaque (type ransomware).
Le malware se cachait sous des fichiers normaux, utilisait le nom “KeeLoader” et évitait d’être détecté par les antivirus. Il restait discret jusqu’à l’ouverture d’un fichier de mot de passe.
4️⃣ Technique d’infection :
Faux site KeePass (ex: keeppaswrd.com)
Téléchargement infecté
Déploiement du malware + vol des mots de passe
Prise de contrôle du réseau (RDP, SSH, etc.)
Chiffrement des données (ransomware)
Des indices montrent des liens avec des groupes comme Black Basta et l’utilisation de services criminels "as-a-service" (certificats, infra, etc.).
N’abandonnons pas les gestionnaires de mots de passe…
Mais téléchargeons-les uniquement depuis les sites officiels"KeePass trojanised in advanced malware campaign
In 2025, WithSecure discovered a trojanised, and signed version of the open-source password manager KeePass, used to deliver malware and exfiltrate credentials. Named KeeLoader, this modified installer was signed with trusted certificates and distributed via malvertising and typo-squat domains to victims across Europe."
👇
https://labs.withsecure.com/publications/keepass-trojanised-in-advanced-malware-campaign
👇📄
https://labs.withsecure.com/content/dam/labs/docs/W_Intel_Research_KeePass_Trojanised_Malware_Campaign.pdf -
Une campagne de malware très avancée a détourné KeePass, un gestionnaire de mots de passe open source populaire.
⬇️
Des cybercriminels ont modifié le code source de KeePass, l’ont recompilé avec un certificat numérique valide et diffusé via de la pub malveillante (malvertising) sur des moteurs de recherche. (merci-pas-merci Google)Résultat : une version piégée de KeePass était distribuée à des victimes pensant télécharger l’original. Cette fausse version :
Exfiltrait les bases de données KeePass avec les mots de passe en clair
Déployait un malware furtif (Cobalt Strike) servant à prendre le contrôle de l’ordi et propager une attaque (type ransomware).
Le malware se cachait sous des fichiers normaux, utilisait le nom “KeeLoader” et évitait d’être détecté par les antivirus. Il restait discret jusqu’à l’ouverture d’un fichier de mot de passe.
4️⃣ Technique d’infection :
Faux site KeePass (ex: keeppaswrd.com)
Téléchargement infecté
Déploiement du malware + vol des mots de passe
Prise de contrôle du réseau (RDP, SSH, etc.)
Chiffrement des données (ransomware)
Des indices montrent des liens avec des groupes comme Black Basta et l’utilisation de services criminels "as-a-service" (certificats, infra, etc.).
N’abandonnons pas les gestionnaires de mots de passe…
Mais téléchargeons-les uniquement depuis les sites officiels"KeePass trojanised in advanced malware campaign
In 2025, WithSecure discovered a trojanised, and signed version of the open-source password manager KeePass, used to deliver malware and exfiltrate credentials. Named KeeLoader, this modified installer was signed with trusted certificates and distributed via malvertising and typo-squat domains to victims across Europe."
👇
https://labs.withsecure.com/publications/keepass-trojanised-in-advanced-malware-campaign
👇📄
https://labs.withsecure.com/content/dam/labs/docs/W_Intel_Research_KeePass_Trojanised_Malware_Campaign.pdf -
Skitnet is shaking up the cybercrime scene—this stealthy ransomware tool is now powering high-stakes attacks by notorious groups. Ever wonder how hackers pull off such seamless heists? Dive into the story behind the tool that's rewriting the rules.
https://thedefendopsdiaries.com/skitnet-a-new-era-in-ransomware-tools/
#skitnet
#ransomware
#cybersecurity
#postexploitation
#blackbasta -
Skitnet is shaking up the ransomware scene with stealthy tactics and jaw-dropping capabilities—already in use by notorious gangs. What does this mean for our digital defenses? Dive into the details.
https://thedefendopsdiaries.com/skitnet-a-new-era-in-ransomware-tools/
#skitnet
#ransomware
#cybersecurity
#postexploitation
#blackbasta -
#BlackBasta : The Fallen #Ransomware Gang That Lives On
After a series of setbacks, the notorious Black Basta ransomware gang went underground. Researchers are bracing for its probable return in a new form.
#scammer #security #privacy -
#BlackBasta : The Fallen #Ransomware Gang That Lives On
After a series of setbacks, the notorious Black Basta ransomware gang went underground. Researchers are bracing for its probable return in a new form.
#scammer #security #privacy -
Vulnerabilidad de Windows aprovechada para instalar ransomware BlackBasta https://blog.elhacker.net/2025/04/vulnerabilidad-windows-aprovechada-ransowmare-blackbasta.html #vulnerabilidad #blackbasta #ransomware #Windows #0-day #cve
-
Vulnerabilidad de Windows aprovechada para instalar ransomware BlackBasta https://blog.elhacker.net/2025/04/vulnerabilidad-windows-aprovechada-ransowmare-blackbasta.html #vulnerabilidad #blackbasta #ransomware #Windows #0-day #cve
-
A massive leak of internal chat logs from the notorious Black Basta ransomware-as-a-service (RaaS) group has exposed potential ties to Russian authorities, extensive use of artificial intelligence in its operations and plans for a complete rebranding.
#technews #ransomware #blackbasta #raas #infosec #cybersecurity #russia
-
A massive leak of internal chat logs from the notorious Black Basta ransomware-as-a-service (RaaS) group has exposed potential ties to Russian authorities, extensive use of artificial intelligence in its operations and plans for a complete rebranding.
#technews #ransomware #blackbasta #raas #infosec #cybersecurity #russia
-
📦 Our latest investigation of Black Basta's leaked chats shows how they were plotting to exploit open source package registries to deploy ransomware, plus our analysis of #ransomware & wiperware packages already in the wild.
https://socket.dev/blog/black-basta-dependency-confusion-ambitions-and-ransomware-in-open-source-ecosystems #BlackBasta #CyberSecurity
-
📦 Our latest investigation of Black Basta's leaked chats shows how they were plotting to exploit open source package registries to deploy ransomware, plus our analysis of #ransomware & wiperware packages already in the wild.
https://socket.dev/blog/black-basta-dependency-confusion-ambitions-and-ransomware-in-open-source-ecosystems #BlackBasta #CyberSecurity
-
BlackBasta Ransomware Gang Exposed: Connections to Russian Authorities Revealed - https://www.redpacketsecurity.com/blackbasta-ransomware-ties-to-russian-authorities-uncovered/
-
BlackBasta Ransomware Gang Exposed: Connections to Russian Authorities Revealed - https://www.redpacketsecurity.com/blackbasta-ransomware-ties-to-russian-authorities-uncovered/
-
BlackBasta Ransomware Ties to Russian Authorities Uncovered – Source: www.infosecurity-magazine.com https://ciso2ciso.com/blackbasta-ransomware-ties-to-russian-authorities-uncovered-source-www-infosecurity-magazine-com/ #rssfeedpostgeneratorecho #InfoSecurityMagazine #InfosecurityMagazine #CyberSecurityNews #BlackBasta
-
BlackBasta Ransomware Ties to Russian Authorities Uncovered – Source: www.infosecurity-magazine.com https://ciso2ciso.com/blackbasta-ransomware-ties-to-russian-authorities-uncovered-source-www-infosecurity-magazine-com/ #rssfeedpostgeneratorecho #InfoSecurityMagazine #InfosecurityMagazine #CyberSecurityNews #BlackBasta
-
#TrendMicro discusses how the #BlackBasta and #Cactus #ransomware groups utilized the #BackConnect #malware to maintain persistent control and exfiltrate sensitive data from compromised machines. Learn more -> https://www.trendmicro.com/en_us/research/25/b/black-basta-cactus-ransomware-backconnect.html
-
#TrendMicro discusses how the #BlackBasta and #Cactus #ransomware groups utilized the #BackConnect #malware to maintain persistent control and exfiltrate sensitive data from compromised machines. Learn more -> https://www.trendmicro.com/en_us/research/25/b/black-basta-cactus-ransomware-backconnect.html
-
Cactus ransomware: what you need to know – Source: www.tripwire.com https://ciso2ciso.com/cactus-ransomware-what-you-need-to-know-source-www-tripwire-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #grahamcluleycom #Grahamcluley #blackbasta #ransomware #Guestblog #Dataloss #Malware
-
Cactus ransomware: what you need to know – Source: www.tripwire.com https://ciso2ciso.com/cactus-ransomware-what-you-need-to-know-source-www-tripwire-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #grahamcluleycom #Grahamcluley #blackbasta #ransomware #Guestblog #Dataloss #Malware
-
Cactus ransomware: what you need to know https://www.tripwire.com/state-of-security/cactus-ransomware-what-you-need-know #Ransomware #BlackBasta #ransomware #Guestblog #Dataloss #Malware
-
Cactus ransomware: what you need to know https://www.tripwire.com/state-of-security/cactus-ransomware-what-you-need-know #Ransomware #BlackBasta #ransomware #Guestblog #Dataloss #Malware
-
Fake IT Support Calls Trick Microsoft Teams Users into Installing Ransomware https://hackread.com/fake-it-support-calls-microsoft-teams-users-install-ransomware/ #MicrosoftTeams #Cybersecurity #CyberAttacks #CyberAttack #QuickAssist #BlackBasta #Ransomware #Security #OneDrive #Malware #CACTUS
-
Fake IT Support Calls Trick Microsoft Teams Users into Installing Ransomware https://hackread.com/fake-it-support-calls-microsoft-teams-users-install-ransomware/ #MicrosoftTeams #Cybersecurity #CyberAttacks #CyberAttack #QuickAssist #BlackBasta #Ransomware #Security #OneDrive #Malware #CACTUS
-
Fake IT Support Calls Trick Microsoft Teams Users into Installing Ransomware – Source:hackread.com https://ciso2ciso.com/fake-it-support-calls-trick-microsoft-teams-users-into-installing-ransomware-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #MicrosoftTeams #cybersecurity #CyberAttacks #CyberAttack #QuickAssist #BlackBasta #Ransomware #Hackread #OneDrive #security #malware #CACTUS
-
Fake IT Support Calls Trick Microsoft Teams Users into Installing Ransomware – Source:hackread.com https://ciso2ciso.com/fake-it-support-calls-trick-microsoft-teams-users-into-installing-ransomware-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #MicrosoftTeams #cybersecurity #CyberAttacks #CyberAttack #QuickAssist #BlackBasta #Ransomware #Hackread #OneDrive #security #malware #CACTUS
-
Happy Monday everyone!
Today's #readoftheday is brought to you by Trend Micro and they share their findings related to #BlackBasta and #CactusRansomware adding a piece of malware known as #BackConnect to their toolbox.
The report states "The BackConnect malware is a tool that cybercriminals use to establish and maintain persistent control over compromised systems. Once infiltrated, it grants attackers a wide range of remote control capabilities, allowing them to execute commands on the infected machine. This enables them to steal sensitive data, such as login credentials, financial information, and personal files."
Behaviors (MITRE ATT&CK):
Initial Access - TA0001:
Phishing: Spearphishing Voice - T1566.004 - The attackers conducted an email bombing campaign then contacted the victim posing as "IT Support" or "HelpDesk".Command and Control - TA0011:
Remote Access Software - T1219 -
The attackers used QuickAssist to access the victim's environment once they were successfully social engineered.Lateral Movement - TA0008:
Remote Services: SMB/ Windows Admin Shares - T1021.002 -
Remote Services: Windows Remote Management - T1021.006
The attackers leveraged both SMB, shared folders, and WinRM for lateral movement.Go check out the rest of the technical details! Enjoy and Happy Hunting!
Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal
https://www.trendmicro.com/en_us/research/25/b/black-basta-cactus-ransomware-backconnect.html?&web_view=trueIntel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting
-
Happy Monday everyone!
Today's #readoftheday is brought to you by Trend Micro and they share their findings related to #BlackBasta and #CactusRansomware adding a piece of malware known as #BackConnect to their toolbox.
The report states "The BackConnect malware is a tool that cybercriminals use to establish and maintain persistent control over compromised systems. Once infiltrated, it grants attackers a wide range of remote control capabilities, allowing them to execute commands on the infected machine. This enables them to steal sensitive data, such as login credentials, financial information, and personal files."
Behaviors (MITRE ATT&CK):
Initial Access - TA0001:
Phishing: Spearphishing Voice - T1566.004 - The attackers conducted an email bombing campaign then contacted the victim posing as "IT Support" or "HelpDesk".Command and Control - TA0011:
Remote Access Software - T1219 -
The attackers used QuickAssist to access the victim's environment once they were successfully social engineered.Lateral Movement - TA0008:
Remote Services: SMB/ Windows Admin Shares - T1021.002 -
Remote Services: Windows Remote Management - T1021.006
The attackers leveraged both SMB, shared folders, and WinRM for lateral movement.Go check out the rest of the technical details! Enjoy and Happy Hunting!
Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal
https://www.trendmicro.com/en_us/research/25/b/black-basta-cactus-ransomware-backconnect.html?&web_view=trueIntel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting