Security researchers at Sentinel Labs have found evidence linking the Black Basta ransomware group to FIN7, a financially motivated hacking group also known as “Carbanak.”.

Researchers discovered that the developer who built the tools used by the FIN7 threat actor also created the EDR (Endpoint Detection and Response) tools that Black Basta has been using exclusively since June 2022.
Additional evidence linking these two threat actors comes from IP addresses and certain strategies (tactics, techniques, and procedures) used by FIN7 in early 2022 that were observed months later during actual Black Basta attacks.
Background
FIN7 is a group of Russian-speaking hackers motivated by money. They have been active since at least 2015 and have developed POS malware and launched targeted spear-phishing against hundreds of businesses.
In 2020, the group began working on ransomware, and in October 2021, it was revealed that the group had launched its own network hacking operation.
A report from 2022 explained that the FIN7 group was working with various ransomware gangs, including Maze, Ryuk, Darkside, and BlackCat/ALPHV. These gangs apparently carried out the initial breach.
Black Basta is a ransomware operation that began in April 2022. The group showed signs of previous experience, immediately announcing multiple high-profile victims and convincing many analysts that it was a rebranding of the Conti or at least contained members from the now-defunct operation.
The new ransomware group has maintained a closed profile and has not promoted itself as a ransomware-as-a-service, suggesting that it may be a private group.

A programmer for FIN7
Since June 2022, the Black Basta group has been observed developing a custom EDR evasion tool used exclusively by its members.
Upon further investigation, Sentinel Labs discovered an executable file named “WindefCheck.exe” that displays a fake Windows Security GUI and a tray icon. This gives users the false impression that Windows Defender is working properly.
While the malware is active in the background, it disables Windows Defender and any other tools to prevent anything from interfering with operations .
This tool is illustrated below, where the top image shows the fake Windows Security screen, with various security settings appearing to be enabled and protecting the device.
However, the screen below shows the actual status of these security settings that are disabled.

After recovering more samples associated with the tool, analysts found a sample packaged with an unknown packager. This was later identified as “SocksBot,” a backdoor that FIN 7 has been using and developing since 2018.
Additionally, the backdoor gains access to a C2 IP address associated with “pq.hosting,” which is a hosting provider that FIN7 trusts and uses .
There is additional evidence linking FIN7 to Black Basta, including their experimentation with the Cobalt Strike and Meterpreter C2 frameworks in early 2022 in simulated malware-dropping attacks.

Many months later, Black Basta appeared to be using the same tools, plugins, and methods to carry out its attacks.
While there are many technical similarities between the members of Fin7 and the Black Basta operation, it is still unclear what their exact relationship is. Are they simply devs for the group or collaborators using their own tools during attacks.
Information source: bleepingcomputer.com
