logo

ReliaQuest Uncovers New Black Basta Social Engineering Technique

ID: ccc85e88-6101-5bd0-b92d-f4992ab12ded

STIX ID: report--ccc85e88-6101-5bd0-b92d-f4992ab12ded

Feed Name: ReliaQuest Blog

Threat Score
78/100

Date Published: 2024-10-25

Date Updated: 2026-04-29

...
...

**Executive Summary:** ReliaQuest observed an active Black Basta campaign that escalates social engineering by flooding targets with email, then contacting them via compromised Microsoft Teams tenants and QR-code phishing to coerce installation of RMM tools (AnyDesk/QuickAssist), resulting in credential theft (LSASS access, Impacket/secretsdump) and Cobalt Strike beaconing; the report includes IoCs, detection guidance for Teams and QR-based phishing, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.