HomeSecurityBackConnect malware links Black Basta and Cactus ransomware

BackConnect malware links Black Basta and Cactus ransomware

New research has revealed further links between the Black Basta and Cactus, with members of both groups using the same social engineering and BackConnect malware to access corporate networks.

See also: Southern Water: Black Basta ransomware attack cost £4.5m

Black Basta Cactus ransomware

In January, Zscaler discovered a sample of the Zloader malware, which contained what appeared to be a new DNS tunneling capability. Further investigation by Walmart showed that Zloader was spreading a new malware called BackConnect, which contained code references to the Qbot (QakBot) malware.

BackConnect is malware that acts as a proxy tool for remote access to compromised servers. BackConnect allows cybercriminals to funnel traffic, obfuscate their activities, and escalate attacks into the victim's environment without being detected.

Zloader, Qbot, and BackConnect are all believed to be linked to the Black Basta ransomware operation , with members using the malware to compromise and spread through corporate networks. These ties are further strengthened by a recent BlackBasta data leak that revealed the company’s internal conversations, including those between the ransomware gang’s administrator and someone believed to be the Qbot developer

See also: Were conversations of the Black Basta ransomware group leaked?

Cactus ransomware emerged in early 2023 and has since targeted a number of organizations using tactics similar to Black Basta.

BackConnect

Previous reports on Cactus also indicated links between the two ransomware gangs, with Cactus using a PowerShell script called TotalExec , which is often seen in Black Basta ransomware attacks. Additionally, the Black Basta ransomware gang adopted an encryption that was originally unique to Cactus ransomware attacks, further strengthening the ties between the two groups.

The sharing of tactics, BackConnect, and other operational similarities raises questions about whether Cactus ransomware is a rebrand of Black Basta or simply an overlap between members.

See also: Black Basta abuses Teams Chat to spread malware

Protection against ransomware attacks

Protecting yourself from ransomware requires a multi-pronged approach that includes preventative measures, risk identification, and recovery strategies. Here are some important steps to protect yourself:

  • Upgrading software and security systems
  • User training
  • Backups
  • Use strong passwords and multi-factor authentication
  • Installing anti-malware software
  • Ransomware detection and isolation

Source: bleepingcomputer

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS