New research has revealed further links between the Black Basta and Cactus, with members of both groups using the same social engineering and BackConnect malware to access corporate networks.
See also: Southern Water: Black Basta ransomware attack cost £4.5m

In January, Zscaler discovered a sample of the Zloader malware, which contained what appeared to be a new DNS tunneling capability. Further investigation by Walmart showed that Zloader was spreading a new malware called BackConnect, which contained code references to the Qbot (QakBot) malware.
BackConnect is malware that acts as a proxy tool for remote access to compromised servers. BackConnect allows cybercriminals to funnel traffic, obfuscate their activities, and escalate attacks into the victim's environment without being detected.
Zloader, Qbot, and BackConnect are all believed to be linked to the Black Basta ransomware operation , with members using the malware to compromise and spread through corporate networks. These ties are further strengthened by a recent BlackBasta data leak that revealed the company’s internal conversations, including those between the ransomware gang’s administrator and someone believed to be the Qbot developer
See also: Were conversations of the Black Basta ransomware group leaked?
Cactus ransomware emerged in early 2023 and has since targeted a number of organizations using tactics similar to Black Basta.

Previous reports on Cactus also indicated links between the two ransomware gangs, with Cactus using a PowerShell script called TotalExec , which is often seen in Black Basta ransomware attacks. Additionally, the Black Basta ransomware gang adopted an encryption that was originally unique to Cactus ransomware attacks, further strengthening the ties between the two groups.
The sharing of tactics, BackConnect, and other operational similarities raises questions about whether Cactus ransomware is a rebrand of Black Basta or simply an overlap between members.
See also: Black Basta abuses Teams Chat to spread malware
Protection against ransomware attacks
Protecting yourself from ransomware requires a multi-pronged approach that includes preventative measures, risk identification, and recovery strategies. Here are some important steps to protect yourself:
- Upgrading software and security systems
- User training
- Backups
- Use strong passwords and multi-factor authentication
- Installing anti-malware software
- Ransomware detection and isolation
Source: bleepingcomputer
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
