New research has uncovered further links between the Black Basta and Cactus ransomware gangs, with members of both groups utilizing the same social engineering attacks and the BackConnect proxy malware for post-exploitation access to corporate networks. In January, Zscaler discovered a Zloader malware sample that contained what appeared to be a new DNS tunneling feature. Further research by Walmart indicated that Zloader was dropping a new proxy malware called BackConnect that contained code references to the Qbot (QakBot) malware. BackConnect is malware that acts as a proxy tool for remote access to compromised servers. BackConnect allows cybercriminals to tunnel traffic, obfuscate their activities, and escalate attacks within a victim's environment without being detected. Both Zloader, Qbot, and BackConnect are all believed to be linked to the Black Basta ransomware operation, with members utilizing the malware to breach and spread through corporate networks. These ties are further strengthened by a recent BlackBasta data leak that exposed the operation's internal conversations, including those between the ransomware gang's manager and someone believed to be the developer of Qbot. Black Basta is a ransomware gang that launched in April 2022. It is believed to include members of the Conti Ransomware gang, which shut down in May 2022 after suffering a massive data leak of source code and internal conversations. The ransomware gang has historically used Qakbot to gain initial...
Microsoft Teams tactics, malware connect Black Basta, Cactus ransomware
BleepingComputer
·Lawrence Abrams
·Published Mar 4, 2025
·Updated
Affected Software
1 affected component
Microsoft Teams
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the tactics used by Black Basta and Cactus ransomware gangs, particularly their use of Microsoft Teams for social engineering attacks.
2
What security implications are discussed in this article?
The article highlights the risks associated with malware that utilizes Microsoft Teams to facilitate communication and coordination among cybercriminals.
3
What specific malware is mentioned in connection with the ransomware gangs?
The BackConnect proxy malware is mentioned as a tool used for post-exploitation by the Black Basta and Cactus ransomware groups.
4
Which software platform is identified as being exploited by these ransomware gangs?
Microsoft Teams is identified as being exploited for social engineering attacks by the ransomware gangs.
5
How do Black Basta and Cactus ransomware groups operate according to the article?
They employ similar social engineering attacks and utilize sophisticated malware to connect and communicate during their operations.