Black Basta Ransomware Group Affiliates Leveraging Windows Quick Assist for Initial Access
ID: cf30faec-b6d4-550b-a0f1-2d92f13234ac
STIX ID: report--cf30faec-b6d4-550b-a0f1-2d92f13234ac
Feed Name: Arctic Wolf Blog
Since April 2024, Arctic Wolf tracked Black Basta affiliates conducting social-engineering campaigns (vishing, email bomb, and Microsoft Teams messages/calls) to trick users into granting remote control via Microsoft Quick Assist, then using downloaded tooling (Qakbot, ScreenConnect, NetSupport, Cobalt Strike, SystemBC) and PsExec to achieve persistence, lateral movement, and widespread Black Basta ransomware deployment; the bulletin provides detections and recommends uninstalling unused remote-assistance tools, security awareness training, and Teams safeguards.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
