Symantec researchers suspect that the Black Basta ransomware was exploiting the Windows CVE-2024-26169 vulnerability , before a security update was released .

The vulnerability was severe and could allow elevation of privilege on an affected system (CVSS v3.1: 7.8). It was detected in the Windows Error Reporting Service and attackers could escalate their privileges to SYSTEM.
Microsoft fixed the vulnerability in question on March 12, 2024, through its monthly Patch Tuesday.
According to a report by Symantec, the vulnerability has been actively exploited by the operators of the Black Basta ransomware, likely as a zero-day.
See also: Abuse of Windows Quick Assist to distribute Black Basta ransomware
Windows: Vulnerability exploited by Black Basta ransomware
Symantec investigated an attempted ransomware attack where an exploit for CVE-2024-26169, following an initial infection by the DarkGate loader. DarkGate is known to be used by the Black Basta gang.
Additionally, analysts believe the attackers are linked to Black Basta because they used batch scripts disguised as software updates to execute malicious commands on compromised systems, a common tactic for the gang.
The Windows file werkernel.sys uses a null security descriptor when creating registry keys, and this is exactly what the tool used by hackers takes advantage of.
See also: Black Basta ransomware: Has compromised over 500 organizations
The tool's goal is to create a registry key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WerFault.exe) and set the “Debugger” value to its own executable pathname, which allows it to launch a shell with SYSTEM privileges.
According to Symantec's research, a variant of the exploit was used on February 27, 2024, while a second sample was built even earlier, on December 18, 2023. This means that the ransomware had a working exploit in place approximately 14 to 85 days before Microsoft patched the Windows vulnerability.

Timestamps on portable executables can be modified, however, it is believed that the exploitation attempts actually occurred at that time.
Black Basta ransomware is quite popular and is believed to be linked to the now-defunct Conti. It has been linked to many attacks on Windows systems.
See also: Black Basta and Bl00dy ransomware target ScreenConnect
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The discovery of the use of zero-day exploits by the Black Basta ransomware gang has raised concerns among cybersecurity experts about the evolving threat landscape. As cybercriminals become more sophisticated, it is becoming increasingly difficult for organizations to defend against attacks.
This incident also highlights the importance of regular software updates and promptly patching vulnerabilities. Technology is advancing and it is imperative that we prioritize strengthening our defenses against cyberattacks.
Source: www.bleepingcomputer.com
