Black Basta Ransomware Campaign Drops Zbot, DarkGate, & Custom Malware
(www.rapid7.com)
from Joker@sh.itjust.works to cybersecurity@infosec.pub on 09 Dec 21:52
https://sh.itjust.works/post/29260005
from Joker@sh.itjust.works to cybersecurity@infosec.pub on 09 Dec 21:52
https://sh.itjust.works/post/29260005
> Beginning in early October, Rapid7 has observed a resurgence of activity related to the ongoing social engineering campaign being conducted by Black Basta ransomware operators. Rapid7 initially reported the discovery of the novel social engineering campaign back in May, 2024, followed by an update in August 2024, when the operators updated their tactics and malware payloads and began sending lures via Microsoft Teams. Now, the procedures followed by the threat actors in the early stages of the social engineering attacks have been refined again, with new malware payloads, improved delivery, and increased defense evasion.
Executive Summary
threaded - newest