Black Basta Ransomware Uses Phishing Flood to Compromise Orgs
ID: 38a3210c-97d7-5bc8-88c4-eb52644fa3bf
STIX ID: report--38a3210c-97d7-5bc8-88c4-eb52644fa3bf
Feed Name: KnowBe4 Blog
Threat Score
Rapid7 and CISA-observed activity: Black Basta floods victims with legitimate-seeming emails to evade filters, then impersonates an IT help desk to persuade users to install remote management software; attackers use that access to install malware, exfiltrate data, and encrypt systems—defenses recommended include user training, reporting mass-email incidents, and blocking unauthorized remote management services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
