Former Black Basta Members Use Microsoft Teams and Python Scripts in 2025 Attacks
11 Articles
11 Articles
Former players who were previously attributed to the ransomware group Black Basta continue their activities with well-known methods – including email bombings and phishing via Microsoft teams. However, security researchers from ReliaQuest found that attackers are increasingly combining these techniques with Python scripts to specifically reload and execute malware via cURL requests. This further development suggests that, despite internal setbac…
Former Black Basta Members Use Microsoft Teams and Python Scripts in 2025 Attacks
Former members tied to the Black Basta ransomware operation have been observed sticking to their tried-and-tested approach of email bombing and Microsoft Teams phishing to establish persistent access to target networks. "Recently, attackers have introduced Python script execution alongside these techniques, using cURL requests to fetch and deploy malicious payloads," ReliaQuest said in a report
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
To view factuality data please Upgrade to Premium