Black Basta affiliates used a multi-stage social-engineering campaign to breach corporate networks by impersonating IT support staff in Microsoft Teams and persuading employees to grant remote access through Windows Quick Assist and AnyDesk. Researchers said the attacks often began with email bombing to overwhelm targets, followed by Teams chats or calls from attacker-controlled external Entra ID tenants using names such as "Help Desk" or "support." In earlier incidents, the group similarly abused Quick Assist after contacting victims by phone, showing a consistent pattern of using legitimate remote-support tools to gain initial access.
After access was established, the attackers deployed additional tooling including ScreenConnect, NetSupport Manager, Cobalt Strike, and SystemBC-linked payloads, while also using credential-theft and lateral-movement activity such as accessing LSASS, scanning internal hosts, and running Impacket secretsdump.py. ReliaQuest also observed malicious QR-code lures tied to domains such as qr-s1[.]com through qr-s4[.]com, and a VBS-based infection chain that contacted 179.60.149[.]194 to retrieve follow-on payloads. The activity was attributed to Black Basta with high confidence, with reporting indicating infrastructure and Teams activity linked to Russia, and defenders were urged to restrict external Teams communications, limit trusted domains, and improve Teams, email, and remote-access monitoring.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
In late October 2024, Black Basta targeted users with mass email spam and then added them to one-on-one Microsoft Teams chats from external accounts using deceptive tenant names and 'Help Desk' display names.
In October 2024, ReliaQuest investigated an Impacket-related alert and identified a broader Black Basta intrusion chain involving AnyDesk, fake anti-spam binaries, credential theft, internal scanning, Cobalt Strike, and secretsdump.py before containment.
In October 2024, ReliaQuest observed Black Basta evolving from phone-based impersonation to Microsoft Teams messages from attacker-controlled Entra ID tenants posing as help-desk or support staff.
In May 2024, Rapid7 and ReliaQuest released advisories about a Black Basta social-engineering campaign that used email flooding, fake IT-help-desk contact, and remote-access tools.
After the Conti cybercrime syndicate shut down in June 2022, one resulting faction was believed to be Black Basta.
Black Basta was active by April 2022, marking the start of the ransomware operation later tied to the social-engineering campaigns described in the references.
In one late-November 2024 incident, attackers used Teams communications and a follow-up call to trick a user into downloading filter_update.vbs, which attempted domain enumeration, contacted 179.60.149[.]194, and tried to download additional payloads before the activity was contained.
In late November 2024, ReliaQuest responded to several Black Basta-related incidents and identified new tactics including Teams messages and calls following mass email bombing.
3 references tracked. Mallory keeps watching after this page renders.
google.com
Open sourcereliaquest.com
Open sourcegoogle.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.