
Black Basta’s Tactical Evolution: Deploying Zbot, DarkGate, and Bespoke Malware
Indicators of Compromise
No domains found for this campaign
Campaign Guidance
Remediation, mitigation, notes, history and related intelligence
REMEDIATION
1. Abuse Elevation Control Mechanism: Bypass User Account Control (T1548.002)
|
2. Access Token Manipulation: Parent PID Spoofing (T1134.004)
|
3. Account Manipulation: Additional Local or Domain Groups (T1098.007)
|
4. Acquire Infrastructure: Domains (T1583.001)
|
5. Application Layer Protocol: DNS (T1071.004)
|
6. Application Window Discovery (T1010)
|
7. Automated Collection (T1119)
|
8. Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001)
|
9. Clipboard Data (T1115)
|
10. Command and Scripting Interpreter (T1059)
|
11. Create Account: Local Account (T1136.001)
|
12. Credentials from Password Stores (T1555)
|
13. Data Encrypted for Impact (T1486)
|
14. Data Obfuscation (T1001)
|
15. Debugger Evasion (T1622)
|
16. Deobfuscate/Decode Files or Information (T1140)
|
17. Execution Guardrails (T1480)
|
18. Exfiltration Over C2 Channel (T1041)
|
19. File and Directory Discovery (T1083)
|
20. Financial Theft (T1657)
|
21. Hide Artifacts (T1564.001)
|
22. Hijack Execution Flow (T1574)
|