Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Black Basta’s playbook lives on as former affiliates launch fast-scale intrusion campaign  – CyberScoop
AttackFeed by Joe Wagner | Black Basta’s playbook lives on as former affiliates launch fast-scale intrusion campaign  - CyberScoop

Black Basta’s playbook lives on as former affiliates launch fast-scale intrusion campaign  – CyberScoop

Posted on April 14, 2026 By Matt Kapko No Comments on Black Basta’s playbook lives on as former affiliates launch fast-scale intrusion campaign  – CyberScoop
Attack Feeds

A small group of former Black Basta affiliates have targeted more than 100 employees across dozens of organizations to intrude network systems for potential data theft, ransomware deployment and extortion, according to ReliaQuest.

The social engineering campaign, which involves mass email bombing and Microsoft Teams help desk impersonation, surged last month and dates back to at least May 2025, ReliaQuest said in a report Tuesday. 

Attackers have primarily targeted senior leadership to gain highly privileged access. “Roughly three-quarters of targeted users were executives, directors, managers or similarly high-value roles,” researchers who worked on the report told CyberScoop via email. 

Cybercriminals involved in Black Basta, an offshoot of Conti, scattered after the threat group’s internal chat logs leaked online in February 2025, providing threat researchers and authorities key details about the group’s operations. 

German police publicly identified Oleg Evgenievich Nefedov, a Russian national, as Black Basta’s alleged leader in January. Nefedov, a 35-year-old who was subsequently added to the most-wanted lists of Europol and Interpol, allegedly formed and ran Black Basta since 2022, authorities said. 

He is accused of extorting more than 100 companies in Germany and about 600 other countries globally.

ReliaQuest said the recently observed campaign shares many similarities with previous Black Basta activity and follows the same playbook — tooling, targeting and execution style — associated with the once-prolific ransomware group. 

“That includes the repeated use of remote access tools, a strong concentration in sectors Black Basta historically favored, and a level of speed and coordination that suggests experienced operators are building on a playbook they already know works,” researchers said. 

“We’re careful not to treat any one artifact as definitive proof, but taken together, the similarities are strong enough that we assess it is highly likely former affiliates or closely aligned operators are involved,” ReliaQuest researchers added. 

Black Basta’s data leak site was shut down shortly after its internal chats were leaked last year, but uncaptured cybercriminals typically scatter and join new groups in the wake of a takedown or disbandment. Threat hunters warned that former members were still actively targeting additional victims earlier this year. 

ReliaQuest released its report, including indicators of compromise, after it observed a particularly sharp spike in activity in March, noting that the group’s targeting was more focused on senior employees.

“The operators are moving very quickly, with parts of the workflow becoming more automated or highly streamlined, which makes the campaign easier to scale and harder for defenders to interrupt before remote access is established,” researchers said.

The top-five sectors targeted in recent Black Basta-style attacks include manufacturing, professional services, finance and insurance, construction and technology, according to ReliaQuest.

Attackers typically bombard targeted employees with hundreds of emails within minutes and then contact targeted users, posing at IT support via direct messages on Microsoft Teams or a phone call. ReliaQuest said it’s observed some attackers achieve remote access minutes after the first sign of an email bomb.

Researchers did not say how many organizations have been successfully intruded as a result of this campaign thus far. 

While extortion appears to be the most likely objective, ReliaQuest cautioned against assuming every attack results in ransomware encryption.

“Based on what we’ve observed, the intrusion chain is built to gain access quickly, understand the environment, and create options for follow-on monetization,” researchers said. “That could lead to data theft, extortion without encryption, or ransomware deployment, depending on the victim and the opportunity.”

The post Black Basta’s playbook lives on as former affiliates launch fast-scale intrusion campaign appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud  – The Hacker News
Next Post: Kraken Exchange Faces Extortion After Insider Recorded System Footage  – Hackread – Cybersecurity News, Data Breaches, AI and More ❯

You may also like

AttackFeed by Joe Wagner | Space Force official touts AI’s impact on cyber compliance  - CyberScoop
Attack Feeds
Space Force official touts AI’s impact on cyber compliance  – CyberScoop
April 14, 2026
AttackFeed by Joe Wagner | 10 Tips for Phrasing Employee Feedback in Reviews  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
10 Tips for Phrasing Employee Feedback in Reviews  – Hackread – Cybersecurity News, Data Breaches, AI and More
May 18, 2026
AttackFeed by Joe Wagner | Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise  - The Hacker News
Attack Feeds
Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise  – The Hacker News
April 2, 2026
AttackFeed by Joe Wagner | Mate Security Introduces the Security Context Graph, an Approach to Smarter SOCs  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Mate Security Introduces the Security Context Graph, an Approach to Smarter SOCs  – Hackread – Cybersecurity News, Data Breaches, AI and More
February 17, 2026

Leave a Reply Cancel reply

You must be logged in to post a comment.

  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.