logo

Black Basta Ransomware Group Affiliates Leveraging Windows Quick Assist for Initial Access

ID: eee343d4-51d4-5de9-b745-c20b823bd4ca

STIX ID: report--eee343d4-51d4-5de9-b745-c20b823bd4ca

Feed Name: Arctic Wolf

Threat Score
75/100

Date Published: 2024-06-17

Date Updated: 2026-07-25

Author: Andres Ramos

...
...

Executive summary: Arctic Wolf is tracking an active Black Basta affiliate campaign (since April 2024) that uses vishing, email-bombing, and Microsoft Teams to trick users into granting remote access via Quick Assist; attackers deploy loaders and RATs (Qakbot, ScreenConnect, NetSupport Manager, Cobalt Strike, SystemBC), perform discovery and lateral movement (PsExec), and deploy Black Basta ransomware — the advisory includes detections and mitigations such as uninstalling Quick Assist and user awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.