logo

Black Basta Ransomware Group Affiliates Leveraging Windows Quick Assist for Initial Access

ID: a7af681c-b227-5885-865c-a09cc341fbfc

STIX ID: report--a7af681c-b227-5885-865c-a09cc341fbfc

Feed Name: Arctic Wolf

Threat Score
78/100

Date Published: 2024-06-17

Date Updated: 2026-07-25

Author: Andres Ramos

...
...

Arctic Wolf is tracking an active Black Basta affiliate campaign (since April 2024) that uses social-engineering (vishing and mailbox bombing) to trick victims into granting access via Microsoft Quick Assist and Microsoft Teams; once connected, actors download and execute payloads (e.g., Qakbot, Cobalt Strike, SystemBC) and use tools like PsExec to move laterally and deploy Black Basta ransomware. The bulletin covers observed TTPs, detection capabilities, and recommended mitigations such as removing unused remote-support tools and enhancing user security awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.