Windows Quick Assist abused in Black Basta ransomware attacks
ID: d8ba034f-f43c-5aa7-a994-8c238641dbf3
STIX ID: report--d8ba034f-f43c-5aa7-a994-8c238641dbf3
Feed Name: Bleeping Computer
Microsoft and security vendors observed a financially motivated campaign (tracked as Storm-1811) that email-bombs targets, then uses phone-based social engineering to trick users into launching Windows Quick Assist; attackers remotely execute scripted downloads (Qakbot, RMM tools, Cobalt Strike), harvest credentials via PowerShell, exfiltrate data, perform lateral movement, and deploy Black Basta ransomware (often using PsExec). The report details Black Basta's widespread impact (500+ organizations, high-profile victims, and significant extortion revenue), and recommends blocking/uninstalling Quick Assist and similar RMM tools and training staff to recognize tech-support scams.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
