logo

Inside BRUTED: Black Basta (RaaS) Members Used Automated Brute Forcing Framework to Target Edge Network Devices

ID: ce4caa2f-589b-5cb6-ae07-9f3a3ef0adea

STIX ID: report--ce4caa2f-589b-5cb6-ae07-9f3a3ef0adea

Feed Name: EclecticIQ

Threat Score
78/100

Date Published: 2025-03-13

Date Updated: 2026-04-27

Author: Arda Büyükkaya

...
...

EclecticIQ analyzed leaked Black Basta internal chats and recovered the BRUTED PHP-based brute-forcing framework used since 2023 to mass-scan and credential-stuff VPNs, firewalls, and RDWeb endpoints; the report details targeted products and vulnerabilities, infrastructure IPs and domains, operational tactics (proxy rotation, C2 reporting, distributed execution), victimology, and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.