## page was copied from DnsTemplate ##master-page:HelpTemplate <> <> Black Basta Ransomware Gang Actively Infiltrating U.S. Companies with Qakbot Malware November 24, 2022Ravie Lakshmanan https://thehackernews.com/2022/11/black-basta-ransomware-gang-actively.html The attack chain commences with a spear-phishing email bearing a malicious disk image file that, when opened, kickstarts the execution of Qbot, which, for its part, connects to a remote server to retrieve the Cobalt Strike payload. == history == {{{ "In this latest campaign, the Black Basta ransomware gang is using QakBot malware to create an initial point of entry and move laterally within an organization's network," Cybereason researchers Joakim Kandefelt and Danielle Frankel said in a report shared with The Hacker News. }}} ---- CategoryDns CategoryWatch CategoryTemplate