QBot: Laying the Foundations for Black Basta Ransomware Activity
ID: 391a1c38-b1a9-5c5a-8812-be45d9ce4148
STIX ID: report--391a1c38-b1a9-5c5a-8812-be45d9ce4148
Feed Name: ReliaQuest Blog
ReliaQuest observed an incident where a phishing email using HTML smuggling delivered a password-protected ZIP/ISO which executed a QBot infection; the adversary harvested credentials (DPAPI/Mimikatz), leveraged a service account in the Domain Admins group to move laterally and deploy Cobalt Strike beacons (C2: 194.165.16.95), and installed remote-access tools (AnyDesk, Atera, Splashtop). The activity—attributed to a likely Black Basta affiliate—exhibited fast breakout (77 minutes), defense-evasion (ISO/ZIP obfuscation, process injection, pass-the-hash/overpass-the-hash), and use of common post-exploitation tools; the report provides MITRE TTP mappings, IOCs, and recommendations to improve logging and detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
