Happy Monday everyone!

Today's #readoftheday is brought to you by Trend Micro and they share their findings related to #BlackBasta and #CactusRansomware adding a piece of malware known as #BackConnect to their toolbox.

The report states "The BackConnect malware is a tool that cybercriminals use to establish and maintain persistent control over compromised systems. Once infiltrated, it grants attackers a wide range of remote control capabilities, allowing them to execute commands on the infected machine. This enables them to steal sensitive data, such as login credentials, financial information, and personal files."

Behaviors (MITRE ATT&CK):
Initial Access - TA0001:
Phishing: Spearphishing Voice - T1566.004 - The attackers conducted an email bombing campaign then contacted the victim posing as "IT Support" or "HelpDesk".

Command and Control - TA0011:
Remote Access Software - T1219 -
The attackers used QuickAssist to access the victim's environment once they were successfully social engineered.

Lateral Movement - TA0008:
Remote Services: SMB/ Windows Admin Shares - T1021.002 -
Remote Services: Windows Remote Management - T1021.006
The attackers leveraged both SMB, shared folders, and WinRM for lateral movement.

Go check out the rest of the technical details! Enjoy and Happy Hunting!

Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal
https://www.trendmicro.com/en_us/research/25/b/black-basta-cactus-ransomware-backconnect.html?&web_view=true

Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting

Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal

Trend Micro

Despite global efforts to combat ransomware, the ransomware-as-a-service (RaaS) model remains a persistent and lucrative avenue for extorting money from targets.

#Cybersecurity #Vulnerabilities #CACTUSRansomware #Qlik

https://cybersec84.wordpress.com/2023/11/30/critical-qlik-sense-vulnerabilities-used-in-cactus-ransomware-attacks/

Critical Qlik Sense Vulnerabilities Used in CACTUS Ransomware Attacks

A recent CACTUS ransomware campaign has been detected, exploiting recently revealed vulnerabilities in Qlik Sense, a cloud analytics and business intelligence platform. This marks the initial docum…

CyberSec84 | Cybersecurity news.