{"id":3597,"date":"2024-05-16T08:31:01","date_gmt":"2024-05-16T13:31:01","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/windows-quick-assist-anchors-black-basta-ransomware"},"modified":"2024-05-16T08:31:01","modified_gmt":"2024-05-16T13:31:01","slug":"windows-quick-assist-anchors-black-basta-ransomware-gambit","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/16\/windows-quick-assist-anchors-black-basta-ransomware-gambit\/","title":{"rendered":"Windows Quick Assist Anchors Black Basta Ransomware Gambit"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt3753ff03096fa852\/654e3980485688040a4f6c03\/remoteaccess_Alex_Brylov_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/windows-quick-assist-anchors-black-basta-ransomware-gambit.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/windows-quick-assist-anchors-black-basta-ransomware-gambit.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Following a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/500-victims-later-black-basta-reinvents-novel-vishing-strategy\" rel=\"noopener\">recently documented<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> Black Basta ransomware vishing campaign, Microsoft Threat Intelligence acknowledged May 15 that a financially motivated threat actor tracked as Storm-1811 since mid-April has been following the playbook.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The threat group is using a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/mgm-and-caesars-attacks-highlight-social-engineering-risks\" rel=\"noopener\">socially engineered <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">campaign to trick victims into letting them <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/500-victims-later-black-basta-reinvents-novel-vishing-strategy\" rel=\"noopener\">use Quick Assist<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for remote access to their machines by posing as trusted contacts, such as Microsoft technical support or an IT professional from the targeted user&#8217;s company. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/client-management\/client-tools\/quick-assist\" rel=\"noopener\">Quick Assist<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> is a Windows app that enables a person to share their Windows or macOS device with someone else over a remote connection.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/sophisticated-vishing-campaigns-take-world-by-storm\" rel=\"noopener\">Vishing campaigns<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in which a threat actor has been abusing a Windows remote-access app to deliver Black Basta ransomware demonstrates the risk inherent in such solutions when they are paired with sophisticated social engineering. This threat demands a similarly savvy response from enterprise security teams, who must bolster vigilance and advise employees across organizations to do the same, experts say.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Abusing Legitimate Windows Tools\">Abusing Legitimate Windows Tools<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Once they establish trust and gained remote access, Storm-1811 then uses this channel to deliver various malware remotely to victim machines, culminating in the delivery of Black Basta ransomware for financial gain, according to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/05\/15\/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware\/\" rel=\"noopener\">a blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by Microsoft Threat Intelligence. Victims also may receive a bomb of emails and then vishing calls from threat actors impersonating IT or help-desk personnel.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The attacks demonstrate how easy it is for threat actors to abuse legitimate remote-access tools to deceive and compromise users, especially if their social-engineering skills to get a victim to fall for a malicious ruse are solid, security experts said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Advanced social engineering attacks are what cybercriminals use when \u2026 they cannot breach [an organization] using simpler methods such as basic phishing emails or compromising weak credentials,&#8221; notes Darren Guccione, CEO and co-founder&nbsp;of security firm <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.keepersecurity.com\/\" rel=\"noopener\">Keeper Security<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, in an email to Dark Reading.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The growing sophistication that attackers have demonstrated with these tactics and their clever use of remote-access tools highlights the continued need for ongoing training and education of employees in how to spot such tricks as they evolve, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Because Quick Assist allows the user to share their device over a remote connection, the application carries the potential for damaging malicious activity,&#8221; Guccione says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Advanced Social Engineering\">Advanced Social Engineering<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the attack vector described by Microsoft Threat Intelligence, Storm-1811 either uses <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/chinese-redzei-victims-vishing\" rel=\"noopener\">vishing<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to &#8220;impersonate IT or help desk personnel, pretending to conduct generic fixes on a device,&#8221; or engages in email bombing to flood users&#8217; inboxes with content on services that they&#8217;ve subscribed to.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Following the email flood, the threat actor impersonates IT support through phone calls to the target user, claiming to offer assistance in remediating the spam issue,&#8221; according to Microsoft.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Indeed, this email bombing is a critical aspect of advanced social engineering, serving &#8220;to overwhelm and confuse the victim before the attacker reaches out by phone to manipulate them into accepting a malicious Quick Assist request,&#8221; Stephen Kowski, field CTO at <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.slashnext.com\/\" rel=\"noopener\">SlashNext<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, notes.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Once this connection is set up, attackers are free to operate at will on a victim&#8217;s machine. In the case of the attacks described by both Rapid 7 and Microsoft, this activity ultimately ends with the deployment of Black Basta ransomware.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Flurry of Malware Used in Storm-1811 Campaign\">Flurry of Malware Used in Storm-1811 Campaign<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Microsoft also observed Storm-1811 delivering a flurry of malware to victim machines in the leadup to the Black Basta payload, including remote monitoring and management (RMM) tools like ScreenConnect and NetSupport Manager, malware such as Qakbot, and Cobalt Strike.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Once access was gained via Quick Assist, the attacker ran a scripted curl command to download a series of batch files or ZIP files used to deliver the varied malicious payloads. Some of the batch scripts suggested the use of fake spam filter updates that required the targets to provide sign-in credentials, according to Microsoft.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Storm-1811 then used <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/pikabot-malware-qakbot-replacement-black-basta-attacks\" rel=\"noopener\">Qakbot <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">to deliver a Cobalt Strike Beacon, and next established persistence and conducted lateral movement within the compromised environment via ScreenConnect.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">NetSupport Manager, another remote access tool, likely was deployed to maintain control over compromised devices to further download and install additional malware, as well as launch arbitrary commands, according to Microsoft.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In some cases, Storm-1811 also leveraged the OpenSSH tunneling tool to establish a secure shell (SSH) tunnel for persistence.&nbsp;Eventually, the actor used PsExec to deploy <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/black-basta-buster-exploits-ransomware-bug-file-recovery\" rel=\"noopener\">Black Basta <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">ransomware throughout the network.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Mitigating Quick Assist Attacks\">Mitigating Quick Assist Attacks<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Given how vulnerable an organization is once a corporate user gives attackers remote access to his or her machine willingly, one way to mitigate such attacks is to uninstall such tools as Quick Assist when they are not in use, both Microsoft and experts advised.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Organizations also can implement a privilege access management (PAM) solution with a zero-trust architecture, which &#8220;prevents unauthorized privilege escalation and ensures that user access roles are strongly enforced,&#8221; Guccione says.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;A major goal of zero trust is to limit users to the resources and information for which they are authorized, which reduces the blast radius in the event of a breach,&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Both Microsoft and experts also advised that organizations use advanced and consistent employee training to help them spot vishing and social engineering-based attacks, which can prevent compromise even though Guccione acknowledged that <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/dont-answer-phone-inside-real-life-vishing-attack\" rel=\"noopener\">&#8220;anyone&#8221;<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> can fall for them.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Still, &#8220;employees are better equipped to combat them when their organization provides regular security training and educates employees about malicious attachments, links, and tech support scams such as this,&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Event monitoring and advanced email solutions also can neutralize the email bombing tactic of such campaigns, &#8220;causing the subsequent phone call to stand out as suspicious and illegitimate immediately,&#8221; Kowski says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Luckily, nowadays, GenAI phishing solutions are installed in five minutes without any changes in user experience or significant infrastructure changes,&#8221; he says.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/windows-quick-assist-anchors-black-basta-ransomware\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Following a recently documented Black Basta ransomware vishing campaign, Microsoft<\/p>\n","protected":false},"author":12,"featured_media":3598,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3597","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/windows-quick-assist-anchors-black-basta-ransomware-gambit.jpg?fit=1000%2C907&ssl=1",1000,907,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/windows-quick-assist-anchors-black-basta-ransomware-gambit.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/windows-quick-assist-anchors-black-basta-ransomware-gambit.jpg?fit=300%2C272&ssl=1",300,272,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/windows-quick-assist-anchors-black-basta-ransomware-gambit.jpg?fit=640%2C581&ssl=1",640,581,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/windows-quick-assist-anchors-black-basta-ransomware-gambit.jpg?fit=640%2C580&ssl=1",640,580,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/windows-quick-assist-anchors-black-basta-ransomware-gambit.jpg?fit=1000%2C907&ssl=1",1000,907,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/windows-quick-assist-anchors-black-basta-ransomware-gambit.jpg?fit=1000%2C907&ssl=1",1000,907,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/windows-quick-assist-anchors-black-basta-ransomware-gambit.jpg?fit=1000%2C907&ssl=1",1000,907,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/windows-quick-assist-anchors-black-basta-ransomware-gambit.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/windows-quick-assist-anchors-black-basta-ransomware-gambit.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/windows-quick-assist-anchors-black-basta-ransomware-gambit.jpg?fit=1000%2C907&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3597","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3597"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3597\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3598"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3597"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3597"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3597"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}