Windows Quick Assist Anchors Black Basta Ransomware Gambit
ID: 76d5da08-d272-50a2-9f6e-4a60aa18b242
STIX ID: report--76d5da08-d272-50a2-9f6e-4a60aa18b242
Feed Name: Dark Reading
Date Published: 2024-05-16
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Microsoft Threat Intelligence reports that the financially-motivated actor Storm-1811 is conducting a vishing and email-bombing campaign that socially engineers victims into granting remote access via Microsoft Quick Assist, then stages a multi-tool intrusion (Qakbot, Cobalt Strike, ScreenConnect, NetSupport Manager, PsExec, OpenSSH) culminating in Black Basta ransomware deployment; mitigations recommended include removing unnecessary remote-access tools, applying least privilege/zero-trust controls, and enhanced employee training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
