logo

Crims abusing Microsoft Quick Assist to deploy Black Basta ransomware

ID: fba653a1-dbb0-5a33-9eb7-8f093e63fd25

STIX ID: report--fba653a1-dbb0-5a33-9eb7-8f093e63fd25

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-05-16

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft warns that since mid-April a financially motivated group tracked as Storm-1811 has been abusing Windows Quick Assist in voice-phishing social-engineering attacks to obtain remote control of victims' systems, then installing Qakbot, remote monitoring/management tools (ScreenConnect, NetSupport), and Cobalt Strike, and using PsExec to deploy Black Basta ransomware across networks; Microsoft published mitigations, IOCs, and guidance to block/uninstall Quick Assist and hunt for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.