#StopRansomware: Black Basta
ID: 0a256fdd-b087-5d0b-aeb3-b688015298d2
STIX ID: report--0a256fdd-b087-5d0b-aeb3-b688015298d2
Feed Name: CISA Cybersecurity Advisories
This joint advisory from FBI, CISA, HHS, and MS-ISAC details Black Basta, a ransomware-as-a-service group that has impacted hundreds of organizations across critical infrastructure; it summarizes initial access methods (spearphishing, exploitation of ConnectWise CVE-2024-1709, credential abuse), privilege escalation and lateral movement techniques, tools used (AnyDesk, RClone, Mimikatz, Cobalt Strike, etc.), exfiltration and encryption behavior including double-extortion, current IOCs, and recommended mitigations and reporting procedures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
