Black Basta Pivots to Cactus Ransomware Group
ID: ac8c43a6-2b08-50e7-8218-d8e5c81699be
STIX ID: report--ac8c43a6-2b08-50e7-8218-d8e5c81699be
Feed Name: Dark Reading
Date Published: 2025-03-05
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Trend Micro observed that experienced operators from the Black Basta ransomware group appear to be operating under the Cactus ransomware umbrella, deploying a new persistence malware named BackConnect and leveraging social-engineering (email bombing, Microsoft Teams) and legitimate remote-assistance tools (Windows Quick Assist) to gain access. The report notes ~500 historical Black Basta victims, recent attacks concentrated in North America and Europe across manufacturing, finance, and real estate, and recommends restricting remote-assistance tools, enforcing access controls, and training employees.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
