logo

Black Basta, Bl00dy ransomware gangs join ScreenConnect attacks

ID: bff5efcc-e35c-57b7-8d5f-6190a5916f8e

STIX ID: report--bff5efcc-e35c-57b7-8d5f-6190a5916f8e

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-02-27

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

**Executive summary:** The Black Basta and Bl00dy ransomware gangs and other threat actors are actively exploiting a critical ScreenConnect authentication bypass (CVE-2024-1709) to create admin accounts on internet-exposed servers, delete other users, deploy web shells and backdoors, and stage ransomware and malware (Cobalt Strike, XWorm, LockBit-derived payloads); ConnectWise released patches, CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, and telemetry (Shadowserver, Shodan) shows large-scale exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.