{"id":3543,"date":"2024-05-13T16:04:26","date_gmt":"2024-05-13T21:04:26","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/500-victims-later-black-basta-reinvents-novel-vishing-strategy"},"modified":"2024-05-13T16:04:26","modified_gmt":"2024-05-13T21:04:26","slug":"500-victims-in-black-basta-reinvents-with-novel-vishing-strategy","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/13\/500-victims-in-black-basta-reinvents-with-novel-vishing-strategy\/","title":{"rendered":"500 Victims In, Black Basta Reinvents With Novel Vishing Strategy"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt943d6fdb773bd038\/66426c1e66741b7aa82de97d\/Black_noodles-ciaobucarest-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/500-victims-in-black-basta-reinvents-with-novel-vishing-strategy.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/500-victims-in-black-basta-reinvents-with-novel-vishing-strategy.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A new Black Basta campaign is annoying victims into submission with onslaughts of spam emails and fake customer service representatives tricking them into downloading malware.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The news comes against the backdrop of a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa24-131a\" rel=\"noopener\">fresh joint cybersecurity advisory<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> from the FBI, Cybersecurity and Infrastructure Security Agency (CISA), Department of Health and Human Services (HHS), and Multi-State Information Sharing and Analysis Center (MS-ISAC), warning about Black Basta&#8217;s prolific attacks against critical infrastructure. The ransomware-as-a-service (RaaS) operation, the government says, typically uses spearphishing and software vulnerabilities to gain initial access into sensitive and high-value organizations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But now, at least one prong of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/black-basta-buster-exploits-ransomware-bug-file-recovery\" rel=\"noopener\">the Black Basta operation<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> is taking a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.rapid7.com\/blog\/post\/2024\/05\/10\/ongoing-social-engineering-campaign-linked-to-black-basta-ransomware-operators\/\" rel=\"noopener\">new approach<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Instead of such incisive, targeted breaches, researchers from Rapid7 observed it sending gobs of spam emails to victims, only to then call them offering help. When victims accept the help, the intrusion commences.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Thus far, those victims have spanned industries such as manufacturing, construction, food and beverage, and transportation, says Robert Knapp, senior manager of incident response services at Rapid7, adding that, &#8220;given the array of organizations impacted, these attacks appear to be more opportunistic than targeted.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Black Basta's Latest, Most Annoying Trick\">Black Basta&#8217;s Latest, Most Annoying Trick<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Black Basta has compromised a wide range of organizations since it was first discovered in April 2022, including a dozen of the 16 US-defined critical infrastructure sectors. In total, affiliates have struck more than 500 organizations globally, most often in the US, Europe, and Australia.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Historically, the least interesting aspect of its modus operandi has been its means of obtaining initial access into systems. As the joint alert mentioned, spearphishing is its go-to, though, since February, affiliates have also been doing the job by exploiting the 10.0 &#8220;critical&#8221;-rated <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/remote-workforce\/connectwise-screenconnect-mass-exploitation-delivers-ransomware\" rel=\"noopener\">ConnectWise ScreenConnect bug CVE-2024-1709<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The aforementioned veering from the script has been in place since April, Rapid7 researchers said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Attacks in the latest campaign begin with a wave of emails (enough to overwhelm basic spam protections) to a group of victims in a targeted environment. Plenty of the emails themselves are legitimate, consisting mostly of sign-up notices for newsletters belonging to real, honest organizations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">With targets annoyed and confused, the attackers then <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/dont-answer-phone-inside-real-life-vishing-attack\" rel=\"noopener\">start to make calls<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. One by one they pose as members of the targets&#8217; IT staff, offering help with their issue, in a variation of the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/microsoft-tech-support-scams-on-the-rise\" rel=\"noopener\">classic tech-support scam<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. To do so, they say, the victim needs to download a remote support tool, either the AnyDesk remote monitoring and management (RMM) platform, or Windows&#8217; native Quick Assist utility.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">If a target does not abide, the attacker simply ends the call and moves on to their next victim.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">If the target does run AnyDesk or Quick Assist, the attacker instructs them on how to hand over access to their computer. Once inside, the attacker runs a series of batch scripts masked as software updates. The first of those scripts confirms connectivity with the attacker&#8217;s command-and-control (C2) infrastructure, then downloads a ZIP archive housing OpenSSH, which enables the execution of remote commands.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For its next annoying trick, the Black Basta script creates run key entries in the Windows registry. These entries point to additional batch scripts, which establish a reverse shell to be executed at run time. Thus an infinite loop is created, where an attacker gets a shell to their command-and-control (C2) any time the victim machine is restarted.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"What to Do\">What to Do<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Though researchers did observe the attackers harvesting some credentials, notably, they did not spot any instance of mass data exfiltration or extortion. Those steps may be yet to come.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Rapid7 recommended that organizations take stock of which RMM solutions they use, and utilize &#8220;allowlisting&#8221; tools such as AppLocker or Microsoft Defender Application Control to block any others they don&#8217;t. For extra safety, organizations can also block domains associated with such disallowed RMMs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">If all else fails, Knapp says, &#8220;Should an organization be unable to outright block this activity, the recommended approach would be diligent monitoring and response procedures. Organizations can monitor for the installation and execution of AnyDesk, comparing that activity against their known methods of software deployment which likely originates from expected deployment systems from expected user accounts, and investigate any behavior that falls outside of baselines.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/500-victims-later-black-basta-reinvents-novel-vishing-strategy\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new Black Basta campaign is annoying victims into submission<\/p>\n","protected":false},"author":12,"featured_media":3544,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3543","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/500-victims-in-black-basta-reinvents-with-novel-vishing-strategy-scaled.jpg?fit=2560%2C1920&ssl=1",2560,1920,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/500-victims-in-black-basta-reinvents-with-novel-vishing-strategy-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/500-victims-in-black-basta-reinvents-with-novel-vishing-strategy-scaled.jpg?fit=300%2C225&ssl=1",300,225,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/500-victims-in-black-basta-reinvents-with-novel-vishing-strategy-scaled.jpg?fit=640%2C480&ssl=1",640,480,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/500-victims-in-black-basta-reinvents-with-novel-vishing-strategy-scaled.jpg?fit=640%2C480&ssl=1",640,480,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/500-victims-in-black-basta-reinvents-with-novel-vishing-strategy-scaled.jpg?fit=1536%2C1152&ssl=1",1536,1152,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/500-victims-in-black-basta-reinvents-with-novel-vishing-strategy-scaled.jpg?fit=2048%2C1536&ssl=1",2048,1536,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/500-victims-in-black-basta-reinvents-with-novel-vishing-strategy-scaled.jpg?fit=1024%2C768&ssl=1",1024,768,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/500-victims-in-black-basta-reinvents-with-novel-vishing-strategy-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/500-victims-in-black-basta-reinvents-with-novel-vishing-strategy-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/500-victims-in-black-basta-reinvents-with-novel-vishing-strategy-scaled.jpg?fit=2560%2C1920&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3543","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3543"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3543\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3544"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3543"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3543"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3543"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}