HomeSecurityBlack Basta and Bl00dy ransomware target ScreenConnect

Black Basta and Bl00dy ransomware target ScreenConnect

The Black Basta and Bl00dy ransomware groups have joined forces in widespread attacks targeting ScreenConnect servers that have not been notified of a serious, maximum severity authentication bypass vulnerability

See also: ConnectWise: ScreenConnect update due to critical RCE
Black Basta Bl00dy ScreenConnect

This critical flaw (CVE-2024-1709) allows attackers to create administrator accounts on privileged servers exposed to the internet, delete all other users, and take control of any vulnerable device.

The CVE-2024-1709 has been actively exploited since last Tuesday, a day after security updates were issued by ConnectWise and proof-of-concepts were published by several cybersecurity.

Last week, ConnectWise also patched a high severity routing vulnerability (CVE-2024-1708) that can only be exploited by threat actors with high privileges.

The company removed all license restrictions last week so that customers with expired licenses can protect their servers from attacks affecting all versions of ScreenConnect. On Thursday, CISA also added CVE-2024-1709 to the Exploitable Vulnerabilities List, urging U.S. federal agencies to secure servers by Feb. 29.

Shadowserver reports that the CVE-2024-1709 vulnerability is being widely exploited in attacks, with dozens of IPs targeting servers exposed to the internet, while Shodan currently monitors over 10,000 ScreenConnect servers (only 1,559 are running the updated ScreenConnect 23.9.8).

See also: LockBit ransomware: Infects networks via ScreenConnect vulnerability

Black Basta Bl00dy ransomware

While analyzing these ongoing attacks, Trend Micro discovered that the Black Basta and Bl00dy ransomware groups also began exploiting the ScreenConnect flaw for initial access and installation of backdoors on victims' networks with web shells.

While investigating the attacks, Trend Micro observed reconnaissance, discovery, and privilege escalation activities after the attackers gained access and deployed Cobalt Strike beacons associated with Black Basta on compromised systems.

The Bl00dy team used loads built using leak creators Conti and LockBit Black.

Trend Micro also observed attacks in which attackers used the XWorm malware with RAT and ransomware capabilities.

Other malicious actors used their newly gained access to compromised ScreenConnect servers to install various remote administration tools , such as Atera and Syncro .

Sophos first revealed in a report on Thursday that recently patched flaws in ScreenConnect are being exploited in ransomware attacks .

Cybersecurity firm Huntress also confirmed its findings last week and said that “a local government entity, including systems likely connected to their 911 systems” and a “healthcare center” have also been hit by ransomware that exploited the CVE-2024-1709 authorization revocation vulnerability to invade the victims’ networks.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Blackcat ransomware: Targets healthcare centers

Black Basta and Bl00dy ransomware target ScreenConnect

What are the best practices for preventing ransomware?

To protect yourself from ransomware attacks like the one by Black Basta and Bl00dy on ScreenConnect, user awareness and education are crucial. Users should be aware of the common signs of ransomware attacks, such as suspicious emails and links. Use a strong antivirus program and keep it up-to-date. Keep your operating systems and software up-to-date. Updates often include security patches that can protect your system from ransomware. Regularly back up important data and store it in a safe place, such as an external hard drive or a cloud service. Limit user privileges to the bare minimum. Users who do not need administrator privileges should not have access to them, as this can reduce the risk of ransomware attacks.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS