BlackSuit Continues Social Engineering Attacks in Wake of Black Basta’s Internal Conflict


There has been a significant decrease in social engineering attacks linked to the Black Basta ransomware group since late December 2024.

This lapse also included the leaked Black Basta chat logs in February 2025, indicating internal conflict within the group. Despite this, Rapid7 has observed sustained social engineering attacks. Evidence now suggests that BlackSuit affiliates have either adopted Black Basta’s strategy or absorbed members of the group. The developer(s) of a previously identified Java malware family, distributed during social engineering attacks, have now been assessed as likely initial access brokers, having potentially provided historical access for Black Basta and/or FIN7 affiliates.

Read more…
Source: Rapid7


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Pakistan, China to boost liaison in intelligence sharing, cybercrime prevention

    February 6, 2026

    Pakistan and China on Thursday agreed to enhance cooperation in intelligence sharing and cybercrime prevention. The understanding was reached during a meeting between Federal Interior Minister Mohsin Naqvi and Chinese Ambassador in Pakistan Jiang Zaidong. Upon his arrival at the Ministry of Interior, the Federal Interior Minister welcomed the Chinese Ambassador. During the meeting, detailed discussions ...

  • Stan Ghouls targeting Russia and Uzbekistan with NetSupport RAT

    February 5, 2026

    Stan Ghouls (also known as Bloody Wolf) is an cybercriminal group that has been launching targeted attacks against organizations in Russia, Kyrgyzstan, Kazakhstan, and Uzbekistan since at least 2023. These attackers primarily have their sights set on the manufacturing, finance, and IT sectors. Their campaigns are meticulously prepared and tailored to specific victims, featuring a signature ...

  • Substack confirms data breach affects users’ email addresses and phone numbers

    February 5, 2026

    Newsletter platform Substack has confirmed a data breach in an email to users. The company said that in October, an “unauthorized third party” accessed user data, including email addresses, phone numbers, and other unspecified “internal metadata.” Substack specified that more sensitive data, such as credit card numbers, passwords, and other financial information, was unaffected. In an ...

  • Open the wrong “PDF” and attackers gain remote access to your PC

    February 5, 2026

    Cybercriminals behind a campaign dubbed DEAD#VAX are taking phishing one step further by delivering malware inside virtual hard disks that pretend to be ordinary PDF documents. Open the wrong “invoice” or “purchase order” and you won’t see a document at all. Instead, Windows mounts a virtual drive that quietly installs AsyncRAT, a backdoor Trojan that allows ...

  • Data breach at govtech giant Conduent balloons, affecting millions more Americans

    February 5, 2026

    A data breach at government technology giant Conduent appears to affect far more people than first disclosed, with the number of victims potentially stretching to dozens of millions of people across the United States. The January 2025 ransomware attack, which knocked out Conduent’s operations for several days, is now known to affect at least 15.4 million ...

  • Paris prosecutor’s cybercrime unit searches X office

    February 3, 2026

    French police raided the offices of Elon Musk’s social media network X on Tuesday and prosecutors ordered the tech billionaire to face questions in April in a widening investigation, amid growing scrutiny of the platform by authorities across Europe. France’s raid and the summoning of Musk — which could further increase tensions between Europe and the ...