ATT&CKReferencesDeep Instinct Black Basta August 2022

Deep Instinct Black Basta August 2022

Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1027.006
HTML Smuggling
MalwareQakBot

QakBot has been delivered in ZIP files via HTML smuggling.

T1059.003
Windows Command Shell
MalwareBlack Basta

Black Basta can use `cmd.exe` to enable shadow copy deletion.

T1083
File and Directory Discovery
MalwareBlack Basta

Black Basta can enumerate specific files for encryption.

T1112
Modify Registry
MalwareBlack Basta

Black Basta has modified the Registry to enable itself to run in safe mode, to change the icons and file extensions for encrypted files, and to add the malware path for persistence.

T1204.002
Malicious File
MalwareQakBot

QakBot has gained execution through users opening malicious attachments.

T1218.010
Regsvr32
MalwareQakBot

QakBot can use Regsvr32 to execute malicious DLLs.

T1480.002
Mutual Exclusion
MalwareBlack Basta

Black Basta will check for the presence of a hard-coded mutex `dsajdhas.0` before executing.

T1486
Data Encrypted for Impact
MalwareBlack Basta

Black Basta can encrypt files with the ChaCha20 cypher and using a multithreaded process to increase speed. Black Basta has also encrypted files while the victim system is in safe mode, appending `.basta` upon completion.

T1490
Inhibit System Recovery
MalwareBlack Basta

Black Basta can delete shadow copies using vssadmin.exe.

T1491.001
Internal Defacement
MalwareBlack Basta

Black Basta has set the desktop wallpaper on victims' machines to display a ransom note.

T1553.002
Code Signing
MalwareQakBot

QakBot can use signed loaders to evade detection.

T1566.001
Spearphishing Attachment
MalwareQakBot

QakBot has spread through emails with malicious attachments.

T1574.001
DLL
MalwareQakBot

QakBot has the ability to use DLL side-loading for execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.