home.social

#blackbasta — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #blackbasta, aggregated by home.social.

  1. Node.js: Old Technique Makes a Comeback

    A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.

    Pulse ID: 6a996ed3562f794a642feaaf
    Pulse Link: otx.alienvault.com/pulse/6a996
    Pulse Author: AlienVault
    Created: 2026-09-03 12:57:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #8Base #Akira #Asia #BackDoor #BlackBasta #BlockChain #CyberSecurity #EtherHiding #Government #InfoSec #Java #JavaScript #Malware #Nodejs #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #Rust #bot #AlienVault

  2. Node.js: Old Technique Makes a Comeback

    A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.

    Pulse ID: 6a996ed3562f794a642feaaf
    Pulse Link: otx.alienvault.com/pulse/6a996
    Pulse Author: AlienVault
    Created: 2026-09-03 12:57:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #8Base #Akira #Asia #BackDoor #BlackBasta #BlockChain #CyberSecurity #EtherHiding #Government #InfoSec #Java #JavaScript #Malware #Nodejs #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #Rust #bot #AlienVault

  3. Node.js: Old Technique Makes a Comeback

    A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.

    Pulse ID: 6a996ed3562f794a642feaaf
    Pulse Link: otx.alienvault.com/pulse/6a996
    Pulse Author: AlienVault
    Created: 2026-09-03 12:57:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #8Base #Akira #Asia #BackDoor #BlackBasta #BlockChain #CyberSecurity #EtherHiding #Government #InfoSec #Java #JavaScript #Malware #Nodejs #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #Rust #bot #AlienVault

  4. Node.js: Old Technique Makes a Comeback

    A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.

    Pulse ID: 6a996ed3562f794a642feaaf
    Pulse Link: otx.alienvault.com/pulse/6a996
    Pulse Author: AlienVault
    Created: 2026-09-03 12:57:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #8Base #Akira #Asia #BackDoor #BlackBasta #BlockChain #CyberSecurity #EtherHiding #Government #InfoSec #Java #JavaScript #Malware #Nodejs #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #Rust #bot #AlienVault

  5. Node.js: Old Technique Makes a Comeback

    A resurgence in Node.js abuse has been observed since February 2026, targeting government departments, technology companies, and hotels. Attackers leverage the legitimate, signed node.exe binary to execute malicious JavaScript payloads, evading signature-based detection. In one intrusion at an Asian technology company, attackers downloaded the official Node.js installer after repeated payload blocks and used it to run an implant communicating with Ethereum blockchain gateways via EtherHiding techniques. The same threat actors compromised a U.S. fintech firm, deploying the Rust-based C2Looper backdoor linked to ransomware operations. Multiple attacks involved ModeloRAT, associated with initial access broker Woodgnat, connected to ransomware families including Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and Embargo. Attackers employ ClickFix techniques for initial access and combine living-off-the-land tools with commodity malware.

    Pulse ID: 6a996ed3562f794a642feaaf
    Pulse Link: otx.alienvault.com/pulse/6a996
    Pulse Author: AlienVault
    Created: 2026-09-03 12:57:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #8Base #Akira #Asia #BackDoor #BlackBasta #BlockChain #CyberSecurity #EtherHiding #Government #InfoSec #Java #JavaScript #Malware #Nodejs #OTX #OpenThreatExchange #RAT #RansomWare #Rhysida #Rust #bot #AlienVault

  6. Ransomware: математический аппарат на службе зла

    Привет, Хабр! Я Илья Борисов, старший специалист отдела экспертизы MaxPatrol EDR антивирусной лаборатории Positive Technologies. В 2025 году команда аналитиков антивирусной лаборатории PT ESC провела исследование актуальных семейств ransomware (aka шифровальщиков), чтобы повысить эффективность их обнаружения нашим продуктом. Этот вид ВПО оказался одной из наиболее значимых и заметных разновидностей вредоносов, используемых в атаках в 2025 году. Мы проанализировали образцы, замеченные в период с конца 2024 года по конец 2025-го. Были разобраны как давно известные семейства шифровальщиков, такие как Black Basta, MedusaLocker и LockBit, и относительно недавно появившиеся Lynx, HellCat и BERT. В этой статье хочу поделиться результатами этого исследования. Для начала расскажу про типы шифровальщиков, на кого они нацелены, как работают, подсвечу технические детали, а также ретроспективно прослежу некоторые тенденции в эволюции ransomware.

    habr.com/ru/companies/pt/artic

    #ransomware #шифровальщики #вредоносное_по #lockbit #blackbasta #ransom #вымогательство #выкуп #кибератаки

  7. Основано на реальных событиях: как шифровальщики ведут переговоры и что советуют жертвам

    Программы-вымогатели — одна из главных киберугроз для российских компаний. Только в прошлом году, по данным F.A.C.C.T. , количество атак шифровальщиков на бизнес увеличилось в 2,5 раза. В некоторых случаях суммы выкупа достигали 321 млн рублей. Мы изучили реальные переписки с вымогателями за последние два года. Самые показательные примеры и выводы — в этой статье.

    habr.com/ru/companies/nubes/ar

    #информационная_безопасность #защита_информации #защита_данных #шифровальщики #шифрование_данных #вымогатели #группировка #lockbit #akira #blackbasta