Black Basta’s Evolution: Sophisticated Social Engineering Meets Advanced Payloads

Amber | Attack Report
Download PDF

The Black Basta ransomware group has shifted its social engineering tactics, now distributing payloads like Zbot and DarkGate since October 2024. Their approach often involves email bombing, where a victim’s email is flooded with subscriptions to numerous mailing lists, creating a distraction or hiding malicious activity. Despite these new methods, the group’s objective remains consistent, gain rapid access, enumerate the environment, and extract the victim’s credentials.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox