Black Basta Ransomware Group Affiliates Leveraging Windows Quick Assist for Initial Access
ID: a7af681c-b227-5885-865c-a09cc341fbfc
STIX ID: report--a7af681c-b227-5885-865c-a09cc341fbfc
Feed Name: Arctic Wolf
Arctic Wolf is tracking an active Black Basta affiliate campaign (since April 2024) that uses social-engineering (vishing and mailbox bombing) to trick victims into granting access via Microsoft Quick Assist and Microsoft Teams; once connected, actors download and execute payloads (e.g., Qakbot, Cobalt Strike, SystemBC) and use tools like PsExec to move laterally and deploy Black Basta ransomware. The bulletin covers observed TTPs, detection capabilities, and recommended mitigations such as removing unused remote-support tools and enhancing user security awareness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
