logo

Black Basta Pivots to Cactus Ransomware Group

ID: ac8c43a6-2b08-50e7-8218-d8e5c81699be

STIX ID: report--ac8c43a6-2b08-50e7-8218-d8e5c81699be

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-03-05

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Trend Micro observed that experienced operators from the Black Basta ransomware group appear to be operating under the Cactus ransomware umbrella, deploying a new persistence malware named BackConnect and leveraging social-engineering (email bombing, Microsoft Teams) and legitimate remote-assistance tools (Windows Quick Assist) to gain access. The report notes ~500 historical Black Basta victims, recent attacks concentrated in North America and Europe across manufacturing, finance, and real estate, and recommends restricting remote-assistance tools, enforcing access controls, and training employees.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.