Black Basta Develops Custom Malware in Wake of Qakbot Takedown
ID: e304ab31-1c7c-51b2-9be5-884f570df147
STIX ID: report--e304ab31-1c7c-51b2-9be5-884f570df147
Feed Name: Dark Reading
Date Published: 2024-08-01
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
The report describes how the Black Basta ransomware gang (UNC4393) has adapted after the takedown of Qakbot by shifting from commodity tooling and phishing to custom malware and diversified initial-access methods; researchers observed reuse of the SilentNight backdoor via malvertising, new .NET reconnaissance and deployment tools (Cogscan, Knotrock), tunneling (Portyard) and an in-memory dropper (DawnCry) to speed discovery, lateral movement, exfiltration and large-scale encryption for extortion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
