logo

QBot: Laying the Foundations for Black Basta Ransomware Activity

ID: 391a1c38-b1a9-5c5a-8812-be45d9ce4148

STIX ID: report--391a1c38-b1a9-5c5a-8812-be45d9ce4148

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2023-03-15

Date Updated: 2026-04-29

...
...

ReliaQuest observed an incident where a phishing email using HTML smuggling delivered a password-protected ZIP/ISO which executed a QBot infection; the adversary harvested credentials (DPAPI/Mimikatz), leveraged a service account in the Domain Admins group to move laterally and deploy Cobalt Strike beacons (C2: 194.165.16.95), and installed remote-access tools (AnyDesk, Atera, Splashtop). The activity—attributed to a likely Black Basta affiliate—exhibited fast breakout (77 minutes), defense-evasion (ISO/ZIP obfuscation, process injection, pass-the-hash/overpass-the-hash), and use of common post-exploitation tools; the report provides MITRE TTP mappings, IOCs, and recommendations to improve logging and detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.