Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware


Beginning in early October, Rapid7 has observed a resurgence of activity related to the ongoing social engineering campaign being conducted by Black Basta ransomware operators.

Rapid7 initially reported the discovery of the novel social engineering campaign back in May, 2024, followed by an update in August 2024, when the operators updated their tactics and malware payloads and began sending lures via Microsoft Teams. Now, the procedures followed by the threat actors in the early stages of the social engineering attacks have been refined again, with new malware payloads, improved delivery, and increased defense evasion.

Read more…
Source: Rapid7


Sign up for our Newsletter


Related:

  • Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

    August 3, 2026

    This article analyzes new attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts. Palo Alto Unit 42 shows how an attacker can authenticate ...

  • INTERPOL report finds AI linked to more than half of cybercrime in Africa

    August 3, 2026

    Artificial intelligence is enabling 55 per cent of reported cybercrimes across Africa making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect, according to INTERPOL’s African Cyberthreat Assessment Report 2026. With more than 1.1 billion mobile subscribers recorded in 2025, Africa’s digital transformation is expanding rapidly. However, cybercrime legislation is fragmented and AI readiness ...

  • Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

    July 31, 2026

    Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some tactic, technique, and procedure (TTP) similarities to the Forest Blizzard DNS hijacking operation that we publicly disclosed in April 2026, we attribute this campaign, ...

  • Network Anomaly Detection in KATA

    July 31, 2026

    Once the attacker has breached the corporate network, subsequent stages of the attack often involve leveraging standard domain infrastructure protocols: using Kerberos, running DNS queries, accessing internal services, opening network shares, and other common networking actions. Because this activity is virtually indistinguishable from legitimate network traffic, it is extremely difficult to detect it with traditional ...

  • Toy Ghouls’ new toy: the GenieLocker ransomware

    July 30, 2026

    The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector, and attributed to the Toy Ghouls group by open-source intelligence (link in Russian). The Toy Ghouls, also known as Bearlyfy, Labubu and Laboo.boo, is a financially motivated extortion group, which ...

  • Durov’s bank accounts frozen after terrorist tag applied

    July 30, 2026

    Telegram co-founder Pavel Durov will not be able to access his bank accounts in Russia after placement on the list of terrorists by financial watchdog Rosfinmonitoring earlier on Thursday, lawyer Dmitry Agranovsky told TASS. Since 2022, Russia has recorded 153,000 crimes committed using Telegram, including the organization of a terrorist attack at the Crocus City Hall, ...