BlackBasta Ransomware Gang Uses New Social Engineering Tactics To Target Corporate Networks
ReliaQuest warns that the BlackBasta ransomware gang is using new social engineering tactics to obtain initial access within corporate networks.
The threat actor begins by sending mass email spam campaigns targeting employees, then adding people who fall for the emails to Microsoft Teams chats with external users.
These external users pose as IT support or help desk staff, and send employees Microsoft Teams messages containing malicious QR codes. In some cases, the attackers used voice phishing (vishing) phone calls to convince users to install remote management software.
“The underlying motivation is likely to lay the groundwork for follow-up social engineering techniques, convince users to download remote monitoring and management (RMM) tools, and gain initial access to the targeted environment,” the researchers write. “Ultimately, the attackers’ end goal in these incidents is almost certainly the deployment of ransomware.”
ReliaQuest emphasizes the massive scale of the campaign, with one user receiving a thousand malicious emails in under an hour.
“This rapidly escalating campaign poses a significant threat to organizations,” the researchers write. “The threat group is targeting many of our customers across diverse sectors and geographies with alarming intensity. The sheer volume of activity is also unique; in one incident alone, we observed approximately 1,000 emails bombarding a single user within just 50 minutes. Due to commonalities in domain creation and Cobalt Strike configurations, we attribute this activity to Black Basta with high confidence.”
Only one employee needs to fall for a phishing attack for an attacker to gain access to your network. New-school security awareness training can give your organization an essential layer of defense against social engineering tactics. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
ReliaQuest has the story.
Free Ransomware Simulator Tool
Threat actors are constantly coming out with new strains to evade detection. Is your network effective in blocking all of them when employees fall for social engineering attacks?
KnowBe4’s “RanSim” gives you a quick look at the effectiveness of your existing network protection. RanSim will simulate 24 ransomware infection scenarios and 1 cryptomining infection scenario and show you if a workstation is vulnerable.
Here’s how it works:
- 100% harmless simulation of real ransomware and cryptomining infections
- Does not use any of your own files
- Tests 25 types of infection scenarios
- Just download the install and run it
- Results in a few minutes!
PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/ransomware-simulator-tool-partner?partnerid=001a000001lWEoJAAW