ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Black Basta ransomware attacks linked to FIN7 hackers

A new analysis of tools used in the Black Basta ransomware attacks, which emerged earlier this year and claimed over 90 organizations as of September 2022, has found clear ties between their threat actor and the FIN7 cybercrime syndicate (aka Carbanak), which is active since 2012.

 

In a technical write-up, cybersecurity firm SentinelOne said that this link implies that Black Basta and FIN7 have a close relationship or that one or more people are members of both organizations.

 

SentinelOne notes that the group stands out because there haven’t been any indications that its operators are trying to find affiliates or are promoting the malware as a RaaS on darknet forums or crimeware marketplaces. This has increased the likelihood that the Black Basta developers will either sever the chain of affiliates and distribute the ransomware using their unique toolset or work closely with a small group of affiliates without advertising their warez.

 

Black Basta attack chains use QBot (also known as Qakbot), which is then distributed using phishing emails containing Microsoft Office documents with macros. Newer infections use ISO images and LNK droppers to get around Microsoft’s decision to, by default, block macros in files downloaded from the web.

 

The Black Basta operator enters the scene to conduct surveillance once Qakbot has established a stable foothold in the target environment. To do this, the operator connects to the victim through a backdoor and uses known vulnerabilities (such as ZeroLogon, PrintNightmare, and NoPac) to escalate privileges.

 

Backdoors like SystemBC (also known as Coroxy) are also used at this point to download additional malicious modules and exfiltrate data before performing the lateral movement and taking action to weaken defenses by disabling installed security tools.

 

This also includes a unique EDR evasion tool that has only been used in Black Basta incidents and comes embedded with a backdoor called BIRDDOG, also known as SocksBot and used in several previous attacks that the FIN7 group was accused of carrying out.

 

The FIN7 hackers have a history of launching extensive malware campaigns that target point-of-sale (PoS) systems used by the hospitality, gaming, and restaurant industries. However, over the past two years, the group has shifted to using ransomware to covertly generate income, first under the names Darkside, BlackMatter, and BlackCat, and creating fictitious front companies to hire unwitting penetration testers to carry out ransomware attacks.

 

The revelation comes at a time when the U.S. Financial Crimes Enforcement Network (FinCEN) reported a rise in ransomware attacks against domestic entities from 487 in 2020 to 1,489 in 2021, costing $1.2 billion, an increase of 188% from $416 million the previous year.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543