home.social

#blackbasta — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #blackbasta, aggregated by home.social.

  1. New Backdoor May be Linked to Ransomware Access Broker

    A stealthy new backdoor called Mistic has been deployed in cybercrime intrusions since April 2026, potentially linked to Woodgnat, an initial access broker associated with multiple ransomware operations including Qilin, Interlock, Rhysida, Akira, 8Base and Black Basta. Mistic was deployed alongside ModeloRAT in at least one case, a tool developed by Woodgnat. The backdoor uses sideloading techniques through legitimate Microsoft files and executes payloads in memory without writing to disk. It includes typical backdoor capabilities plus a self-delete kill switch for enhanced stealth. Targeting appears opportunistic across insurance, education, IT and professional services sectors. Woodgnat operates as an IAB, establishing durable remote access within enterprises and selling this access to ransomware affiliates, using various social-engineering techniques including ClickFix, FileFix and CrashFix lures delivered through compromised WordPress sites.

    Pulse ID: 6a3bde32e46aafdb90f9593b
    Pulse Link: otx.alienvault.com/pulse/6a3bd
    Pulse Author: AlienVault
    Created: 2026-06-24 13:40:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #8Base #Akira #BackDoor #BlackBasta #CyberCrime #CyberSecurity #ELF #Education #InfoSec #Microsoft #OTX #OpenThreatExchange #RAT #RDP #RansomWare #Rhysida #SideLoading #Word #Wordpress #bot #AlienVault

  2. New Backdoor May be Linked to Ransomware Access Broker

    A stealthy new backdoor called Mistic has been deployed in cybercrime intrusions since April 2026, potentially linked to Woodgnat, an initial access broker associated with multiple ransomware operations including Qilin, Interlock, Rhysida, Akira, 8Base and Black Basta. Mistic was deployed alongside ModeloRAT in at least one case, a tool developed by Woodgnat. The backdoor uses sideloading techniques through legitimate Microsoft files and executes payloads in memory without writing to disk. It includes typical backdoor capabilities plus a self-delete kill switch for enhanced stealth. Targeting appears opportunistic across insurance, education, IT and professional services sectors. Woodgnat operates as an IAB, establishing durable remote access within enterprises and selling this access to ransomware affiliates, using various social-engineering techniques including ClickFix, FileFix and CrashFix lures delivered through compromised WordPress sites.

    Pulse ID: 6a3bde32e46aafdb90f9593b
    Pulse Link: otx.alienvault.com/pulse/6a3bd
    Pulse Author: AlienVault
    Created: 2026-06-24 13:40:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #8Base #Akira #BackDoor #BlackBasta #CyberCrime #CyberSecurity #ELF #Education #InfoSec #Microsoft #OTX #OpenThreatExchange #RAT #RDP #RansomWare #Rhysida #SideLoading #Word #Wordpress #bot #AlienVault

  3. Ransomware: математический аппарат на службе зла

    Привет, Хабр! Я Илья Борисов, старший специалист отдела экспертизы MaxPatrol EDR антивирусной лаборатории Positive Technologies. В 2025 году команда аналитиков антивирусной лаборатории PT ESC провела исследование актуальных семейств ransomware (aka шифровальщиков), чтобы повысить эффективность их обнаружения нашим продуктом. Этот вид ВПО оказался одной из наиболее значимых и заметных разновидностей вредоносов, используемых в атаках в 2025 году. Мы проанализировали образцы, замеченные в период с конца 2024 года по конец 2025-го. Были разобраны как давно известные семейства шифровальщиков, такие как Black Basta, MedusaLocker и LockBit, и относительно недавно появившиеся Lynx, HellCat и BERT. В этой статье хочу поделиться результатами этого исследования. Для начала расскажу про типы шифровальщиков, на кого они нацелены, как работают, подсвечу технические детали, а также ретроспективно прослежу некоторые тенденции в эволюции ransomware.

    habr.com/ru/companies/pt/artic

    #ransomware #шифровальщики #вредоносное_по #lockbit #blackbasta #ransom #вымогательство #выкуп #кибератаки

  4. Ransomware: математический аппарат на службе зла

    Привет, Хабр! Я Илья Борисов, старший специалист отдела экспертизы MaxPatrol EDR антивирусной лаборатории Positive Technologies. В 2025 году команда аналитиков антивирусной лаборатории PT ESC провела исследование актуальных семейств ransomware (aka шифровальщиков), чтобы повысить эффективность их обнаружения нашим продуктом. Этот вид ВПО оказался одной из наиболее значимых и заметных разновидностей вредоносов, используемых в атаках в 2025 году. Мы проанализировали образцы, замеченные в период с конца 2024 года по конец 2025-го. Были разобраны как давно известные семейства шифровальщиков, такие как Black Basta, MedusaLocker и LockBit, и относительно недавно появившиеся Lynx, HellCat и BERT. В этой статье хочу поделиться результатами этого исследования. Для начала расскажу про типы шифровальщиков, на кого они нацелены, как работают, подсвечу технические детали, а также ретроспективно прослежу некоторые тенденции в эволюции ransomware.

    habr.com/ru/companies/pt/artic

    #ransomware #шифровальщики #вредоносное_по #lockbit #blackbasta #ransom #вымогательство #выкуп #кибератаки

  5. Ransomware: математический аппарат на службе зла

    Привет, Хабр! Я Илья Борисов, старший специалист отдела экспертизы MaxPatrol EDR антивирусной лаборатории Positive Technologies. В 2025 году команда аналитиков антивирусной лаборатории PT ESC провела исследование актуальных семейств ransomware (aka шифровальщиков), чтобы повысить эффективность их обнаружения нашим продуктом. Этот вид ВПО оказался одной из наиболее значимых и заметных разновидностей вредоносов, используемых в атаках в 2025 году. Мы проанализировали образцы, замеченные в период с конца 2024 года по конец 2025-го. Были разобраны как давно известные семейства шифровальщиков, такие как Black Basta, MedusaLocker и LockBit, и относительно недавно появившиеся Lynx, HellCat и BERT. В этой статье хочу поделиться результатами этого исследования. Для начала расскажу про типы шифровальщиков, на кого они нацелены, как работают, подсвечу технические детали, а также ретроспективно прослежу некоторые тенденции в эволюции ransomware.

    habr.com/ru/companies/pt/artic

    #ransomware #шифровальщики #вредоносное_по #lockbit #blackbasta #ransom #вымогательство #выкуп #кибератаки

  6. German police have identified the alleged ringleader of Black Basta ransomware, placing him on the EU most-wanted list with an INTERPOL Red Notice.

    Black Basta is linked to ~700 global attacks since 2022.

    technadu.com/german-authoritie

    Does naming leadership actually disrupt RaaS operations long-term?

    #InfoSec #Ransomware #BlackBasta #CyberCrime

  7. #cyber #cyberSecurity #conti #blackBasta

    infosec.exchange/@BleepingComp
    [email protected] - The identity of the Black Basta ransomware gang leader has been confirmed by law enforcement in Ukraine and Germany, and the individual has been added to the wanted list of Europol and Interpol.

    bleepingcomputer.com/news/secu

  8. @deepthoughts10 @BleepingComputer Agreed, AVCheck was used by BlackBasta to check their malware creations. Would be awesome to see scanner[.]to taken down soon as well. Lots of malicious binaries and scripts scanned on scanner[.]to in the Basta chat logs. The screenshot is one of their sample's results pages.

    #BlackBasta #Ransomware #CTI #threatintelligence

  9. @deepthoughts10 @BleepingComputer Agreed, AVCheck was used by BlackBasta to check their malware creations. Would be awesome to see scanner[.]to taken down soon as well. Lots of malicious binaries and scripts scanned on scanner[.]to in the Basta chat logs. The screenshot is one of their sample's results pages.

    #BlackBasta #Ransomware #CTI #threatintelligence

  10. Une campagne de malware très avancée a détourné KeePass, un gestionnaire de mots de passe open source populaire.
    ⬇️
    Des cybercriminels ont modifié le code source de KeePass, l’ont recompilé avec un certificat numérique valide et diffusé via de la pub malveillante (malvertising) sur des moteurs de recherche. (merci-pas-merci Google)

    Résultat : une version piégée de KeePass était distribuée à des victimes pensant télécharger l’original. Cette fausse version :

    Exfiltrait les bases de données KeePass avec les mots de passe en clair

    Déployait un malware furtif (Cobalt Strike) servant à prendre le contrôle de l’ordi et propager une attaque (type ransomware).

    Le malware se cachait sous des fichiers normaux, utilisait le nom “KeeLoader” et évitait d’être détecté par les antivirus. Il restait discret jusqu’à l’ouverture d’un fichier de mot de passe.

    4️⃣ Technique d’infection :

    • Faux site KeePass (ex: keeppaswrd.com)

    • Téléchargement infecté

    • Déploiement du malware + vol des mots de passe

    • Prise de contrôle du réseau (RDP, SSH, etc.)

    • Chiffrement des données (ransomware)

    Des indices montrent des liens avec des groupes comme Black Basta et l’utilisation de services criminels "as-a-service" (certificats, infra, etc.).

    N’abandonnons pas les gestionnaires de mots de passe…
    Mais téléchargeons-les uniquement depuis les sites officiels

    "KeePass trojanised in advanced malware campaign

    In 2025, WithSecure discovered a trojanised, and signed version of the open-source password manager KeePass, used to deliver malware and exfiltrate credentials. Named KeeLoader, this modified installer was signed with trusted certificates and distributed via malvertising and typo-squat domains to victims across Europe."
    👇
    labs.withsecure.com/publicatio
    👇📄
    labs.withsecure.com/content/da

    #CyberVeille #KeePass #BlackBasta

  11. Une campagne de malware très avancée a détourné KeePass, un gestionnaire de mots de passe open source populaire.
    ⬇️
    Des cybercriminels ont modifié le code source de KeePass, l’ont recompilé avec un certificat numérique valide et diffusé via de la pub malveillante (malvertising) sur des moteurs de recherche. (merci-pas-merci Google)

    Résultat : une version piégée de KeePass était distribuée à des victimes pensant télécharger l’original. Cette fausse version :

    Exfiltrait les bases de données KeePass avec les mots de passe en clair

    Déployait un malware furtif (Cobalt Strike) servant à prendre le contrôle de l’ordi et propager une attaque (type ransomware).

    Le malware se cachait sous des fichiers normaux, utilisait le nom “KeeLoader” et évitait d’être détecté par les antivirus. Il restait discret jusqu’à l’ouverture d’un fichier de mot de passe.

    4️⃣ Technique d’infection :

    • Faux site KeePass (ex: keeppaswrd.com)

    • Téléchargement infecté

    • Déploiement du malware + vol des mots de passe

    • Prise de contrôle du réseau (RDP, SSH, etc.)

    • Chiffrement des données (ransomware)

    Des indices montrent des liens avec des groupes comme Black Basta et l’utilisation de services criminels "as-a-service" (certificats, infra, etc.).

    N’abandonnons pas les gestionnaires de mots de passe…
    Mais téléchargeons-les uniquement depuis les sites officiels

    "KeePass trojanised in advanced malware campaign

    In 2025, WithSecure discovered a trojanised, and signed version of the open-source password manager KeePass, used to deliver malware and exfiltrate credentials. Named KeeLoader, this modified installer was signed with trusted certificates and distributed via malvertising and typo-squat domains to victims across Europe."
    👇
    labs.withsecure.com/publicatio
    👇📄
    labs.withsecure.com/content/da

    #CyberVeille #KeePass #BlackBasta

  12. Skitnet is shaking up the cybercrime scene—this stealthy ransomware tool is now powering high-stakes attacks by notorious groups. Ever wonder how hackers pull off such seamless heists? Dive into the story behind the tool that's rewriting the rules.

    thedefendopsdiaries.com/skitne

    #skitnet
    #ransomware
    #cybersecurity
    #postexploitation
    #blackbasta

  13. Skitnet is shaking up the ransomware scene with stealthy tactics and jaw-dropping capabilities—already in use by notorious gangs. What does this mean for our digital defenses? Dive into the details.

    thedefendopsdiaries.com/skitne

    #skitnet
    #ransomware
    #cybersecurity
    #postexploitation
    #blackbasta

  14. #BlackBasta : The Fallen #Ransomware Gang That Lives On

    After a series of setbacks, the notorious Black Basta ransomware gang went underground. Researchers are bracing for its probable return in a new form.
    #scammer #security #privacy

    wired.com/story/black-basta-ra

  15. #BlackBasta : The Fallen #Ransomware Gang That Lives On

    After a series of setbacks, the notorious Black Basta ransomware gang went underground. Researchers are bracing for its probable return in a new form.
    #scammer #security #privacy

    wired.com/story/black-basta-ra

  16. A massive leak of internal chat logs from the notorious Black Basta ransomware-as-a-service (RaaS) group has exposed potential ties to Russian authorities, extensive use of artificial intelligence in its operations and plans for a complete rebranding.

    computing.co.uk/news/2025/secu

    #technews #ransomware #blackbasta #raas #infosec #cybersecurity #russia

  17. A massive leak of internal chat logs from the notorious Black Basta ransomware-as-a-service (RaaS) group has exposed potential ties to Russian authorities, extensive use of artificial intelligence in its operations and plans for a complete rebranding.

    computing.co.uk/news/2025/secu

    #technews #ransomware #blackbasta #raas #infosec #cybersecurity #russia

  18. 📦 Our latest investigation of Black Basta's leaked chats shows how they were plotting to exploit open source package registries to deploy ransomware, plus our analysis of & wiperware packages already in the wild.

    socket.dev/blog/black-basta-de

  19. 📦 Our latest investigation of Black Basta's leaked chats shows how they were plotting to exploit open source package registries to deploy ransomware, plus our analysis of #ransomware & wiperware packages already in the wild.

    socket.dev/blog/black-basta-de #BlackBasta #CyberSecurity

  20. Happy Monday everyone!

    Today's #readoftheday is brought to you by Trend Micro and they share their findings related to #BlackBasta and #CactusRansomware adding a piece of malware known as #BackConnect to their toolbox.

    The report states "The BackConnect malware is a tool that cybercriminals use to establish and maintain persistent control over compromised systems. Once infiltrated, it grants attackers a wide range of remote control capabilities, allowing them to execute commands on the infected machine. This enables them to steal sensitive data, such as login credentials, financial information, and personal files."

    Behaviors (MITRE ATT&CK):
    Initial Access - TA0001:
    Phishing: Spearphishing Voice - T1566.004 - The attackers conducted an email bombing campaign then contacted the victim posing as "IT Support" or "HelpDesk".

    Command and Control - TA0011:
    Remote Access Software - T1219 -
    The attackers used QuickAssist to access the victim's environment once they were successfully social engineered.

    Lateral Movement - TA0008:
    Remote Services: SMB/ Windows Admin Shares - T1021.002 -
    Remote Services: Windows Remote Management - T1021.006
    The attackers leveraged both SMB, shared folders, and WinRM for lateral movement.

    Go check out the rest of the technical details! Enjoy and Happy Hunting!

    Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal
    trendmicro.com/en_us/research/

    Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting

  21. Happy Monday everyone!

    Today's #readoftheday is brought to you by Trend Micro and they share their findings related to #BlackBasta and #CactusRansomware adding a piece of malware known as #BackConnect to their toolbox.

    The report states "The BackConnect malware is a tool that cybercriminals use to establish and maintain persistent control over compromised systems. Once infiltrated, it grants attackers a wide range of remote control capabilities, allowing them to execute commands on the infected machine. This enables them to steal sensitive data, such as login credentials, financial information, and personal files."

    Behaviors (MITRE ATT&CK):
    Initial Access - TA0001:
    Phishing: Spearphishing Voice - T1566.004 - The attackers conducted an email bombing campaign then contacted the victim posing as "IT Support" or "HelpDesk".

    Command and Control - TA0011:
    Remote Access Software - T1219 -
    The attackers used QuickAssist to access the victim's environment once they were successfully social engineered.

    Lateral Movement - TA0008:
    Remote Services: SMB/ Windows Admin Shares - T1021.002 -
    Remote Services: Windows Remote Management - T1021.006
    The attackers leveraged both SMB, shared folders, and WinRM for lateral movement.

    Go check out the rest of the technical details! Enjoy and Happy Hunting!

    Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal
    trendmicro.com/en_us/research/

    Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting