Black Basta’s playbook lives on as former affiliates launch fast-scale intrusion campaign
ID: 3e6c9e67-7a73-5669-997c-807b0c6c40f4
STIX ID: report--3e6c9e67-7a73-5669-997c-807b0c6c40f4
Feed Name: CyberScoop
ReliaQuest observed a coordinated Black Basta–style social engineering campaign (dating to at least May 2025) in which former affiliates targeted over 100 employees—primarily senior leaders—across dozens of organizations using email-bombing and Microsoft Teams help-desk impersonation to rapidly gain remote access for potential data theft, extortion, or ransomware; researchers noted use of remote access tooling, sector concentration (manufacturing, professional services, finance/insurance, construction, technology), and released IOCs after a March surge in activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
