logo

Black Basta ransomware poses as IT support on Microsoft Teams to breach networks

ID: 546d4c2e-f01d-5307-a02b-139a432dab2b

STIX ID: report--546d4c2e-f01d-5307-a02b-139a432dab2b

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-10-25

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Black Basta affiliates have adapted their social-engineering tactics by creating external Microsoft Teams accounts that impersonate corporate help-desk staff; after overwhelming targets with benign emails, they contact employees via Teams to convince them to install AnyDesk or launch Windows Quick Assist. Once connected the actors deploy payloads (Antispam*.exe flagged as SystemBC, ScreenConnect, NetSupport, Cobalt Strike) to gain persistent access, escalate privileges, exfiltrate data, and ultimately deliver ransomware; defenders are advised to restrict external Teams communication and enable chat logging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.