• News/
  • https://www.bleepingcomputer.com/news/security/microsoft-teams-tactics-malware-connect-black-basta-cactus-ransomware/

Microsoft Teams tactics, malware connect Black Basta, Cactus ransomware

BleepingComputer
·
Lawrence Abrams
·
Published Mar 4, 2025
·
Updated

New research has uncovered further links between the Black Basta and Cactus ransomware gangs, with members of both groups utilizing the same social engineering attacks and the BackConnect proxy malware for post-exploitation access to corporate networks. In January, Zscaler discovered a Zloader malware sample that contained what appeared to be a new DNS tunneling feature. Further research by Walmart indicated that Zloader was dropping a new proxy malware called BackConnect that contained code references to the Qbot (QakBot) malware. BackConnect is malware that acts as a proxy tool for remote access to compromised servers. BackConnect allows cybercriminals to tunnel traffic, obfuscate their activities, and escalate attacks within a victim's environment without being detected. Both Zloader, Qbot, and BackConnect are all believed to be linked to the Black Basta ransomware operation, with members utilizing the malware to breach and spread through corporate networks. These ties are further strengthened by a recent BlackBasta data leak that exposed the operation's internal conversations, including those between the ransomware gang's manager and someone believed to be the developer of Qbot. Black Basta is a ransomware gang that launched in April 2022. It is believed to include members of the Conti Ransomware gang, which shut down in May 2022 after suffering a massive data leak of source code and internal conversations. The ransomware gang has historically used Qakbot to gain initial...

Read full article

Affected Software

1 affected component
Microsoft Teams
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the tactics used by Black Basta and Cactus ransomware gangs, particularly their use of Microsoft Teams for social engineering attacks.

2

What security implications are discussed in this article?

The article highlights the risks associated with malware that utilizes Microsoft Teams to facilitate communication and coordination among cybercriminals.

3

What specific malware is mentioned in connection with the ransomware gangs?

The BackConnect proxy malware is mentioned as a tool used for post-exploitation by the Black Basta and Cactus ransomware groups.

4

Which software platform is identified as being exploited by these ransomware gangs?

Microsoft Teams is identified as being exploited for social engineering attacks by the ransomware gangs.

5

How do Black Basta and Cactus ransomware groups operate according to the article?

They employ similar social engineering attacks and utilize sophisticated malware to connect and communicate during their operations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203