logo

Black Basta Ransomware Uses Phishing Flood to Compromise Orgs

ID: 38a3210c-97d7-5bc8-88c4-eb52644fa3bf

STIX ID: report--38a3210c-97d7-5bc8-88c4-eb52644fa3bf

Feed Name: KnowBe4 Blog

Threat Score
75/100

Date Published: 2024-05-16

Date Updated: 2026-04-28

Author: Roger Grimes

...
...

Rapid7 and CISA-observed activity: Black Basta floods victims with legitimate-seeming emails to evade filters, then impersonates an IT help desk to persuade users to install remote management software; attackers use that access to install malware, exfiltrate data, and encrypt systems—defenses recommended include user training, reporting mass-email incidents, and blocking unauthorized remote management services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.