Black Basta ransomware switches to more evasive custom malware

Teilen:

The Black Basta ransomware gang has shown resilience and an ability to adapt to a constantly shifting space, using new custom tools and tactics to evade detection and spread throughout a network.

Black Basta is a ransomware operator who has been active since April 2022 and is responsible for over 500 successful attacks on companies worldwide.

The ransomware group follows a double-extortion strategy, combining data theft and encryption, and demands large ransom payments in the millions. The ransomware gang previously partnered with the QBot botnet to gain initial access to corporate networks.

However, after the QBot botnet was disrupted by law enforcement, Mandiant reports that the ransomware gang had to create new partnerships to breach corporate networks.

Moreover, Mandiant, who tracks the threat actors as UNC4393, has identified new malware and tools used in Black Basta intrusions, demonstrating evolution and resilience.

The Black Basta ransomware gang has had an active year thus far, compromising notable entities such as Veolia North America, Hyundai Motor Europe, and Keytronic.

The threat group’s sophistication is reflected in the fact that it often has access to zero-day vulnerability exploits, including Windows privilege elevation (2024-26169) and VMware ESXi authentication bypass flaws (CVE-2024-37085).

New Black Basta tactics and tools

After the FBI and DOJ took down the QBot infrastructure in late 2023, Black Basta turned to other initial access distribution clusters, most notably those delivering DarkGate malware.

Later, Black Basta switched to using SilentNight, a versatile backdoor malware delivered through malvertising, marking a departure from phishing as their primary method for initial access.

Mandiant reports that Black Basta has gradually switched from using publicly available tools to internally developed custom malware.

In early 2024, UNC4393 was observed deploying a custom memory-only dropper named DawnCry. This dropper initiated a multi-stage infection, followed by DaveShell, which ultimately led to the PortYard tunneler.

PortYard, also a custom tool, establishes connections to Black Basta’s command and control (C2) infrastructure and proxies traffic.

Other noteworthy custom tools used by Black Basta in recent operations are:

  • CogScan: A .NET reconnaissance tool used to gather a list of hosts available on the network and collect system information.
  • SystemBC: A tunneler that retrieves proxy-related commands from a C2 server using a custom binary protocol over TCP.
  • KnockTrock: A .NET-based utility that creates symbolic links on network shares and executes the BASTA ransomware executable, providing it with the path to the newly created symbolic link.
  • KnowTrap:  A memory-only dropper written in C/C++ that can execute an additional payload in memory.

Combined with the above, Black Basta continues using “living off the land” binaries and readily available tools in its latest attacks, including the Windows certutil command-line utility to download SilentNight and the Rclone tool to exfiltrate data.

All in all, Black Basta remains a significant global threat and one of the top players in the ransomware space.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:54 pm, Jan. 21, 2025
Wetter-Symbol 3°C
L: 2° | H: 4°
overcast clouds
Luftfeuchtigkeit: 89 %
Druck: 1009 mb
Wind: 3 mph SSE
Windböe: 5 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:53 am
Sonnenuntergang: 4:29 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 9:00 pm
Wetter-Symbol
2° | 4°°C 1 mm 100% 5 mph 97 % 1009 mb 0 mm/h
Do. Jan. 23 9:00 pm
Wetter-Symbol
3° | 8°°C 1 mm 100% 18 mph 92 % 1005 mb 0 mm/h
Fr. Jan. 24 9:00 pm
Wetter-Symbol
5° | 10°°C 1 mm 100% 25 mph 88 % 1004 mb 0 mm/h
Sa. Jan. 25 9:00 pm
Wetter-Symbol
2° | 5°°C 0.26 mm 26% 8 mph 84 % 1014 mb 0 mm/h
So. Jan. 26 9:00 pm
Wetter-Symbol
3° | 7°°C 0 mm 0% 14 mph 85 % 1013 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 3 mph 89 % 1009 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 3 mph 92 % 1008 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
3° | 4°°C 1 mm 100% 3 mph 95 % 1006 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
4° | 4°°C 1 mm 100% 2 mph 97 % 1004 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
4° | 4°°C 0.8 mm 80% 3 mph 94 % 1003 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 5 mph 93 % 1002 mb 0 mm/h
Tomorrow 6:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 4 mph 89 % 1003 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 4 mph 90 % 1004 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€101,686.04
2.72%
Ethereum(ETH)
€3,186.69
0.70%
XRP(XRP)
€3.03
0.69%
Fesseln(USDT)
€0.96
0.12%
Solana(SOL)
€239.02
0.56%
Dogecoin(DOGE)
€0.355845
3.27%
USDC(USDC)
€0.96
0.01%
Shiba Inu(SHIB)
€0.000020
1.65%
Pepe(PEPE)
€0.000015
-0.17%
Peanut das Eichhörnchen(PNUT)
€0.355110
-2.89%
Nach oben scrollen