Black Basta ransomware gang linked to Windows zero-day attacks
ID: 3dd653f0-c183-54d0-b7a6-773ceeea5df4
STIX ID: report--3dd653f0-c183-54d0-b7a6-773ceeea5df4
Feed Name: Bleeping Computer
Threat Score
Symantec reports that Black Basta (linked to Cardinal/UNC4394) used an exploit for CVE-2024-26169 in the Windows Error Reporting service to elevate to SYSTEM—deploying the tool after initial DarkGate loader infections and abusing the WerFault Debugger registry key—likely having working exploits days to months before Microsoft patched the flaw on March 12, 2024; organizations should apply the Microsoft patch and follow CISA ransomware guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
