The Black Basta ransomware-as-a-service (RaaS) operation has targeted over 500 entities across North America, Europe, and Australia since its emergence in April 2022. A joint advisory by CISA, FBI, HHS, and MS-ISAC revealed that Black Basta affiliates utilized common initial access techniques like phishing and exploiting vulnerabilities, followed by a double-extortion model of encrypting systems and exfiltrating data. Unlike typical ransomware groups, Black Basta's ransom notes don't include an initial demand but instruct victims to contact the gang via a .onion URL. The group was first observed in April 2022, using QakBot as an initial vector, and has since remained a prominent ransomware actor. Statistics from Malwarebytes show Black Basta's involvement in 28 out of 373 confirmed ransomware attacks in April 2024, while Kaspersky ranked it as the 12th most active family in 2023. The group's activity spiked 41% in Q1 2024, signifying ongoing threats. Black Basta's attack chains rely on various tools for network scanning, lateral movement, privilege escalation, and data exfiltration. They exploit security flaws like ZeroLogon, NoPac, and PrintNightmare, and employ tools like Backstab to disable endpoint detection. The ransomware encrypts files using ChaCha20 with an RSA-4096 key and deletes volume shadow copies to hinder recovery. The ransomware landscape is evolving, with declines in activity noted, yet ransom amounts are rising, showcasing the evolving tactics and challenges faced in combating ransomware threats.
Security researchers have disclosed a significant security vulnerability affecting Google Cloud Vertex AI, Google's managed machine learning and generative AI platform. The fla...
Kodak has disclosed that it is investigating a cybersecurity incident after unauthorized actors gained access to a portion of the company's data. The organization stated that i...
Researchers have identified a sophisticated macOS malware campaign attributed to the North Korean threat group Sapphire Sleet. The attackers use social engineering lures disguised ...