Target Industry
Black Basta and Cactus ransomware groups, primarily targets the manufacturing, financial consulting, and real estate.
Overview
Black Basta and Cactus ransomware groups have adopted BackConnect malware to enhance their attacks. The BackConnect malware detected as QBACKCONNECT has links to QakBot, a loader malware previously targeted in a takedown effort. The malware enables attackers to execute commands remotely, steal sensitive data and maintain control over infected machines.
Impact
Since October 2024, most incidents involving this malware have occurred in North America and Europe, with the US being the hardest hit. The malware allows attackers to execute commands remotely, steal sensitive data, and maintain control over infected machines. This can lead to data breaches, financial losses, operational disruptions, reputational damage, and further attacks, posing a serious threat to both individuals and organisations.
Exploitation
Threat actors are utilising social engineering techniques where they are impersonating IT personnel on Microsoft Teams and exploiting Quick Assist to gain access to systems. They are also exploiting OneDriveStandaloneUpdater.exe to side-load malicious DLLs. The malware enables attackers to execute commands remotely, steal sensitive data, and maintain control over infected machines.
Containment, Mitigations & Remediations
To mitigate the threat posed by BackConnect malware, organisations should implement a multi-layered security approach. This includes regularly updating and patching software to close vulnerabilities, using robust antivirus and anti-malware solutions, and employing firewalls to block unauthorised access. Employee training is crucial to recognise and avoid social engineering tactics, including phishing and impersonation attempts.
Additionally, implementing multi-factor authentication (MFA) can add an extra layer of security to sensitive accounts. Regularly backing up data and ensuring these backups are stored securely offline can help in recovery efforts if an attack occurs. Monitoring network traffic for unusual activity and conducting regular security audits can also help identify and address potential threats early.
Indicators of Compromise
Indicators of Compromise (IoCs) of the type of malware are:
- Filename: winhttp.dll with SHA 254 hash b79c8b7fabb650bcae274b71ee741f4d2d14a626345283a268c902f43edb64fd
- Filename: wscapi.dll, with SHA 256 hash 60bca9f0134b9499751f6a5b754a9a9eff0b44d545387fffc151b5070bd3a26a
- Filename: run2.bat, with SHA 256 hash 623a43b826f95dc109f7b46303c6566298522b824e86a928834f12ac7887e952
- Command & Control (C&C) Server address: 38[.]180[.]25[.]
- C&C Server address: 45[.]8[.]157[.]199
- C&C Server address: 5[.]181[.]3[.]164
- C&C Server address: 185[.]190[.]251[.]16
- C&C Server address: 207[.]90[.]238[.]52
- C&C Server address: 89[.]185[.]80[.]86
- Domain associated with Black Basta and Cactus: pumpkinrab[.]com
- URL associated with Black Basta and Cactus: hxxps://sfu11[.]s3[.]us-east-2[.]amazonaws[.]com/js/kb052117-01[.]bpx
- URL associated with Black Basta and Cactus: hxxps://sfu11[.]s3[.]us-east-2[.]amazonaws[.]com/js/kb052123-02[.]bpx
- URL associated with Black Basta and Cactus: hxxps[://]filters14[.]s3[.]us-east-2[.]amazonaws[.]com/
Threat Landscape
More than 3.7 million companies worldwide rely on Microsoft 365 products. Microsoft has detected an increase in cyber-attack campaigns that exploit legitimate file hosting services. Due to the complexity of the BackConnect malware, it is a concerning threat because of its advanced capabilities and widespread use.
Threat Groups
There are two threat groups who have adopted BackConnect malware as their new arsenal. Black Basta and Cactus. The ensures both ransomware groups maintain control over the systems they infect for longer periods and enhances their ability to carry out attacks. Essentially, it makes their operations more effective and harder to disrupt.
Black Basta is a ransomware-as-a-service (RaaS) variant that first emerged in April 2022. This ransomware group has targeted over 500 organisations across various sectors, including healthcare, critical infrastructure, and private industry, primarily in North
America, Europe, and Australia. Black Basta affiliates use common initial access techniques like phishing and exploiting known vulnerabilities. They employ a double-extortion model, encrypting systems and exfiltrating data, and then demand a ransom to prevent the publication of the stolen data. The group’s activities have caused significant disruption and financial losses for affected organisations.
Cactus ransomware is a relatively new threat that has been active since March 2023. It targets large commercial organisations by exploiting vulnerabilities in VPN appliances to gain initial access. Once inside the network, the attackers use various tools and custom scripts to disable security measures and deploy the ransomware. Cactus encrypts files and exfiltrates sensitive data, demanding a ransom for decryption and to prevent data leaks. The ransomware is notable for its use of a unique encryption method that requires a key to decrypt the binary, making it harder to detect and remove.
TTPs
- T1566: Phishing
- T1566.001: Phishing: Spearphishing Attachment
- T1112: Modify Registry
- T1574.002: Hijack Execution Flow: DLL Side-Loading
- T1562.004: Impair Defenses: Disable or Modify System Firewall
- T1657: Financial Theft
- T1021.002: Remote Services: SMB/Windows Admin Shares
- T1021.004: Remote Services: SSH
- T1021.006: Remote Services: Windows Remote Management
- T1219: Remote Access Software
- T1102: Web Service
- T1059: Command and Scripting Interpreter
- T1059.003: Command and Scripting Interpreter: Windows Command Shell
- T1486: Data Encrypted for Impact
- T1656: Impersonation
Further Information
- https://securityonline.info/black-basta-and-cactus-ransomware-groups-weaponize-backconnect-malware/
- https://www.trendmicro.com/en_us/research/25/b/black-basta-cactus-ransomware-backconnect.html
- https://undercodenews.com/black-basta-and-cactus-ransomware-the-rise-of-backconnect-malware/













