logo

Uptick in Social Engineering Campaign Deploying Black Basta Ransomware

ID: c17a9f20-824e-55ec-9d40-3c98e79e20ab

STIX ID: report--c17a9f20-824e-55ec-9d40-3c98e79e20ab

Feed Name: Arctic Wolf Blog

Threat Score
75/100

Date Published: 2024-12-19

Date Updated: 2026-04-27

...
...

Arctic Wolf reports increased activity in a Black Basta ransomware campaign that leverages Microsoft Teams, email spam, and vishing to trick victims into granting remote access via Microsoft Quick Assist; attackers then deploy secondary malware (EvilProxy, Qakbot, SystemBC, ScreenConnect, NetSupport Manager, Cobalt Strike), establish persistence, perform credential harvesting and lateral movement, and ultimately deploy Black Basta for double-extortion. The bulletin provides detection recommendations, advises uninstalling or disabling Quick Assist and unapproved RMM tools, and recommends deploying Arctic Wolf Agent and Sysmon plus security awareness training and Teams-specific safeguards.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.