logo

Windows Quick Assist Anchors Black Basta Ransomware Gambit

ID: 76d5da08-d272-50a2-9f6e-4a60aa18b242

STIX ID: report--76d5da08-d272-50a2-9f6e-4a60aa18b242

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-05-16

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Microsoft Threat Intelligence reports that the financially-motivated actor Storm-1811 is conducting a vishing and email-bombing campaign that socially engineers victims into granting remote access via Microsoft Quick Assist, then stages a multi-tool intrusion (Qakbot, Cobalt Strike, ScreenConnect, NetSupport Manager, PsExec, OpenSSH) culminating in Black Basta ransomware deployment; mitigations recommended include removing unnecessary remote-access tools, applying least privilege/zero-trust controls, and enhanced employee training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.