Cyber Security News

Black Basta Ransomware Attacking Microsoft Teams With Advanced Social Engineering Tactics

The notorious Black Basta ransomware group has escalated its attack strategy, now leveraging Microsoft Teams as a potent tool for social engineering.

This alarming development, observed throughout October 2024, has targeted hundreds of organizations across various sectors, including finance, technology, and government contractors.

Black Basta, active since April 2022, has been known for its aggressive spam and social engineering techniques.

However, cybersecurity analysts at OP Innovate discovered their latest approach that marks a significant shift in their modus operandi:-

  1. Email Bombardment: The attack begins with a flood of non-malicious spam emails, overwhelming users’ inboxes.
  2. Microsoft Teams Impersonation: Instead of phone calls, attackers now contact victims directly through Teams chats, posing as IT help desk personnel.
  3. Remote Access Deployment: Attackers trick users into installing remote access tools like Quick Assist or AnyDesk.
  4. Network Infiltration: Once connected, the attackers deploy malware for persistent access and lateral movement.

Analyze cyber threats with ANYRUN's powerful sandbox. Black Friday Deals : Get up to 3 Free Licenses.

Why Microsoft Teams is a Vulnerable Attack Vector?

The use of Microsoft Teams introduces new risks for organizations:-

  • External account spoofing: Attackers create convincing Entra ID tenants resembling legitimate IT accounts.
  • Lack of identity verification: Employees often trust messages received through Teams without verification.
  • Unrestricted remote access: Collaboration tools make it easier for attackers to convince users to install remote monitoring and management (RMM) tools.
Evolution of Black Basta Tactics (Source – OP Innovate)

The shift to Microsoft Teams allows Black Basta to bypass traditional email security tools, making it easier to deceive employees.

ReliaQuest, a leading threat research firm, has reported hundreds of incidents across industries, with damages exceeding $15 million.

To defend against these evolving threats, organizations should:-

  • Disable external communications within Teams or allow only trusted domains.
  • Enable logging and alerts for Teams ChatCreated events.
  • Strengthen anti-spam policies and educate employees on social engineering tactics.
  • Control RMM tool usage and monitor for Cobalt Strike beacons.

As Black Basta continues to refine its attack methods, organizations must remain vigilant and adapt their security measures accordingly.

The exploitation of trusted platforms like Microsoft Teams underscores the need for comprehensive security strategies that encompass all communication channels within an organization.

Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago