Black Basta ransomware switches to more evasive custom malware
ID: 62895a73-3848-5ac4-9c60-9897495f0713
STIX ID: report--62895a73-3848-5ac4-9c60-9897495f0713
Feed Name: Bleeping Computer
Black Basta (UNC4393) is a prolific double-extortion ransomware group active since April 2022 and responsible for 500+ successful attacks against global organizations (notable victims include Veolia North America, Hyundai Motor Europe, and Keytronic). Following the disruption of QBot, the group adopted new initial-access malware (DarkGate, SilentNight) and developed custom tools — including memory-only droppers (DawnCry, KnowTrap), backdoors (DaveShell, SilentNight), tunnellers/proxies (PortYard, SystemBC), and reconnaissance utilities (CogScan, KnockTrock) — while leveraging living-off-the-land techniques and exploiting zero-day vulnerabilities (e.g., Windows privilege elevation 2024-26169 and VMware ESXi CVE-2024-37085) for lateral movement, data theft, and ransomware deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
