UNC4393: Collaboration Leads to BASTA Ransomware Attacks
ID: f0c598ba-2cef-5097-a8a5-95069888caf8
STIX ID: report--f0c598ba-2cef-5097-a8a5-95069888caf8
Feed Name: Cyber Press
Threat Score
UNC4393, the core operator behind the BASTA ransomware, conducts financially motivated ransomware and extortion campaigns across multiple industries (over 40 intrusions), has a growing presence in healthcare, and uses a complex, evolving toolset (BASTA, SYSTEMBC, DAWNCRY, PORTYARD, KNOTROCK, COGSCAN, SILENTNIGHT) and varied access methods (QAKBOT historically, now malvertising) to perform reconnaissance, lateral movement, exfiltration, and automated encryption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
