reliaquest.com Revival of Black Basta Tactics: Targeting Executives with Automated Phishing
Article Content
- •77% of recent attacks targeted senior executives, up from 59% earlier in 2026.
- •Attackers use email bombing followed by Teams impersonation to gain remote access.
- •The campaign has affected over 100 employees, primarily in manufacturing and professional services.
A resurgence of cyber attacks has been linked to former affiliates of the defunct Black Basta ransomware group, focusing on senior executives across various sectors. Recent reports indicate that from March 1 to April 1, 2026, 77% of targeted incidents involved high-level employees, a significant increase from 59% earlier in the year. The attackers employ a two-stage social engineering method, beginning with mass email bombing to overwhelm inboxes, followed by impersonation of IT staff via Microsoft Teams to gain remote access. This campaign has affected over 100 employees in sectors such as manufacturing and professional services, which align with Black Basta's historical targets. Attackers utilize tools like Supremo Remote Desktop and Windows Quick Assist to establish control over compromised systems. The speed of these attacks has also increased, with malicious scripts being executed in as little as 12 minutes after initial contact. The findings suggest a coordinated effort by former affiliates, rather than isolated incidents, indicating a potential evolution of tactics from a previously dismantled group.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (11)
Following this threat?
Track Black Basta in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…