logo

Black Basta Develops Custom Malware in Wake of Qakbot Takedown

ID: e304ab31-1c7c-51b2-9be5-884f570df147

STIX ID: report--e304ab31-1c7c-51b2-9be5-884f570df147

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-08-01

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

The report describes how the Black Basta ransomware gang (UNC4393) has adapted after the takedown of Qakbot by shifting from commodity tooling and phishing to custom malware and diversified initial-access methods; researchers observed reuse of the SilentNight backdoor via malvertising, new .NET reconnaissance and deployment tools (Cogscan, Knotrock), tunneling (Portyard) and an in-memory dropper (DawnCry) to speed discovery, lateral movement, exfiltration and large-scale encryption for extortion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.