Response to CISA Advisory (AA24-131A): #StopRansomware: Black Basta
ID: 19a6948a-3fc6-53c0-8994-b3bd33db6f03
STIX ID: report--19a6948a-3fc6-53c0-8994-b3bd33db6f03
Feed Name: Security Boulevard
AttackIQ describes an emulated attack graph based on CISA and vendor reporting for Black Basta ransomware: a Ransomware-as-a-Service strain that has conducted double-extortion operations against multiple critical infrastructure sectors since 2022. The report maps observed TTPs to MITRE ATT&CK (debugger checks, system/account discovery and creation, disabling defenses, RDP lateral movement, vssadmin shadow copy deletion, and RSA-4096+ChaCha20 file encryption), and provides detection and mitigation recommendations for defenders to validate and improve controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
