Campaigns
Black Basta’s Tactical Evolution: Deploying Zbot, DarkGate, and Bespoke Malware

Black Basta’s Tactical Evolution: Deploying Zbot, DarkGate, and Bespoke Malware

Black BastaZbot MalwareDarkGate MalwareSocial EngineeringMicrosoft Teams Exploitation
Black Basta ransomware operators have enhanced their social engineering tactics to distribute Zbot, DarkGate, and custom malware. The campaign involves flooding victims' inboxes with phishing emails and posing as fake IT support personnel via Microsoft Teams to establish trust. Victims are persuaded to install remote access tools like AnyDesk or Quick Assist, enabling attackers to deploy malware capable of stealing credentials, collecting system data, and executing remote commands.

Indicators of Compromise

No domains found for this campaign

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

REMEDIATION


1. Abuse Elevation Control Mechanism: Bypass User Account Control (T1548.002)

  • Enforce strict privilege management policies to prevent unauthorized elevation.

  • Use application whitelisting to restrict the execution of unauthorized binaries.


2. Access Token Manipulation: Parent PID Spoofing (T1134.004)

  • Monitor for anomalous parent-child process relationships.

  • Use endpoint detection solutions to identify suspicious process behavior.


3. Account Manipulation: Additional Local or Domain Groups (T1098.007)

  • Regularly audit user and group memberships for anomalies.

  • Implement alerts for unauthorized modifications to accounts or group privileges.


4. Acquire Infrastructure: Domains (T1583.001)

  • Use domain monitoring tools to detect and block suspicious or newly registered domains.

  • Implement DNS filtering to prevent malicious domain resolution.


5. Application Layer Protocol: DNS (T1071.004)

  • Monitor DNS traffic for irregular patterns, such as high volumes of TXT record queries.

  • Implement DNS security extensions (DNSSEC) and logging for analysis.


6. Application Window Discovery (T1010)

  • Restrict user access to only essential applications.

  • Use endpoint monitoring to detect attempts to enumerate application windows.

7. Automated Collection (T1119)

  • Limit access to sensitive files and implement strong encryption for credential storage.

  • Monitor for abnormal file access or automated collection activities.

8. Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001)

  • Implement monitoring for changes in registry Run keys and startup folders.

  • Use tools to lock down critical registry paths.

9. Clipboard Data (T1115)

  • Encrypt sensitive data during processing to prevent clipboard-based attacks.

  • Monitor clipboard activity for suspicious patterns.


10. Command and Scripting Interpreter (T1059)

  • Disable or restrict script execution (e.g., VBScript, PowerShell, AutoIt) unless explicitly needed.

  • Monitor script execution for anomalous behavior.

11. Create Account: Local Account (T1136.001)

  • Enable alerts for the creation of new local accounts, especially on servers or critical endpoints.

  • Use multi-factor authentication (MFA) to secure user accounts.


12. Credentials from Password Stores (T1555)

  • Disable storage of plaintext passwords in browsers and other software.

  • Regularly update passwords and use password managers with strong encryption.

13. Data Encrypted for Impact (T1486)

  • Use robust backup and recovery solutions to minimize the impact of ransomware.

  • Monitor for sudden file encryption activity or spikes in I/O operations.


14. Data Obfuscation (T1001)

  • Monitor network traffic for signs of obfuscated or encrypted commands.

  • Block known obfuscation techniques at the firewall or IDS/IPS level.

15. Debugger Evasion (T1622)

  • Use anti-tamper software to protect critical applications.

  • Employ monitoring to detect execution under debugging tools.

16. Deobfuscate/Decode Files or Information (T1140)

  • Detect and block the execution of scripts that perform file decoding operations.

  • Monitor for the presence of encoded files in suspicious directories.


17. Execution Guardrails (T1480)

  • Use file monitoring to detect unauthorized changes in configuration files.

  • Implement restrictions on the download or execution of specific file types.


18. Exfiltration Over C2 Channel (T1041)

  • Use DLP (Data Loss Prevention) solutions to detect and block exfiltration attempts.

  • Monitor for unusual data transfer volumes over command and control channels.


19. File and Directory Discovery (T1083)

  • Restrict directory browsing permissions and use auditing to monitor access.

  • Implement tools to detect suspicious file or directory access attempts.


20. Financial Theft (T1657)

  • Use fraud detection mechanisms for financial transactions.

  • Monitor for abnormal behaviors associated with cryptocurrency wallets.


21. Hide Artifacts (T1564.001)

  • Use endpoint monitoring to detect hidden files or directories.

  • Implement tools that flag processes using hidden paths.


22. Hijack Execution Flow (T1574)

  • Monitor registry changes for unauthorized edits, particularly in critical execution keys.

  • Enforce application control to block the execution of unapproved binaries or scripts.


Reports & References1

Observed Countries250

AD (246)
AE (539)
AF (253)
AG (59)
AI (440)
AL (48)
AM (88)
AO (984)
AQ (462)
AR (229)
AS (96)
AT (335)
AU (83)
AW (393)
AX (239)
AZ (767)
BA (521)
BB (424)
BD (422)
BE (196)
BF (597)
BG (333)
BH (183)
BI (507)
BJ (364)
BL (623)
BM (335)
BN (488)
BO (796)
BQ (107)
BR (397)
BS (46)
BT (219)
BV (339)
BW (556)
BY (454)
BZ (805)
CA (717)
CC (527)
CD (898)
CF (655)
CG (782)
CH (73)
CI (302)
CK (183)
CL (350)
CM (574)
CN (292)
CO (913)
CR (861)
CU (40)
CV (607)
CW (989)
CX (198)
CY (851)
CZ (435)
DE (578)
DJ (320)
DK (961)
DM (850)
DO (850)
DZ (332)
EC (80)
EE (207)
EG (801)
EH (815)
ER (530)
ES (443)
ET (829)
FI (389)
FJ (33)
FK (437)
FM (149)
FO (233)
FR (567)
GA (906)
GB (222)
GD (739)
GE (976)
GF (248)
GG (294)
GH (1)
GI (558)
GL (867)
GM (965)
GN (947)
GP (130)
GQ (680)
GR (412)
GS (273)
GT (383)
GU (814)
GW (911)
GY (390)
HK (927)
HM (373)
HN (531)
HR (629)
HT (583)
HU (64)
ID (790)
IE (493)
IL (105)
IM (425)
IN (693)
IO (400)
IQ (331)
IR (2)
IS (415)
IT (849)
JE (155)
JM (130)
JO (423)
JP (34)
KE (913)
KG (860)
KH (81)
KI (284)
KM (606)
KN (29)
KP (545)
KR (915)
KW (856)
KY (914)
KZ (962)
LA (412)
LB (544)
LC (974)
LI (785)
LK (522)
LR (606)
LS (191)
LT (569)
LU (479)
LV (124)
LY (235)
MA (589)
MC (450)
MD (660)
ME (696)
MF (428)
MG (993)
MH (866)
MK (29)
ML (42)
MM (479)
MN (214)
MO (585)
MP (897)
MQ (97)
MR (333)
MS (796)
MT (38)
MU (127)
MV (17)
MW (474)
MX (633)
MY (645)
MZ (471)
NA (371)
NC (672)
NE (838)
NF (14)
NG (918)
NI (332)
NL (738)
NO (536)
NP (234)
NR (349)
NU (647)
NZ (609)
OM (383)
PA (110)
PE (459)
PF (530)
PG (715)
PH (4)
PK (408)
PL (570)
PM (834)
PN (760)
PR (681)
PS (484)
PT (599)
PW (112)
PY (187)
QA (583)
RE (814)
RO (225)
RS (777)
RU (908)
RW (570)
SA (578)
SB (784)
SC (229)
SD (786)
SE (691)
SG (18)
SH (76)
SI (345)
SJ (207)
SK (575)
SL (476)
SM (203)
SN (430)
SO (257)
SR (309)
SS (257)
ST (283)
SV (499)
SX (69)
SY (944)
SZ (699)
TC (35)
TD (394)
TF (74)
TG (740)
TH (679)
TJ (727)
TK (1)
TL (395)
TM (805)
TN (910)
TO (153)
TR (562)
TT (128)
TV (612)
TW (102)
TZ (398)
UA (341)
UG (491)
UM (885)
US (314)
UY (318)
UZ (112)
VA (371)
VC (565)
VE (380)
VG (827)
VI (229)
VN (726)
VU (108)
WF (442)
WS (717)
XK (102)
YE (185)
YT (966)
ZA (291)
ZM (758)
ZW (863)