{"id":58233,"date":"2025-03-03T00:00:00","date_gmt":"2025-03-03T00:00:00","guid":{"rendered":"urn:uuid:05bb0114-5917-e495-332e-e6e5a21cd2ff"},"modified":"2025-03-03T00:00:00","modified_gmt":"2025-03-03T00:00:00","slug":"black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/","title":{"rendered":"Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/QBackConnect-thumbnail:Large?qlt=80\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/25\/QBackConnect-thumbnail.png\" class=\"ff-og-image-inserted\"><\/div>\n<div readability=\"31\">\n<div readability=\"7\">\n<p><span class=\"body-subhead-title\">Black Basta ransomware attack chain<\/span><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31.46511627907\">\n<div readability=\"10.488372093023\">\n<p>Our&nbsp;Managed XDR team analyzed a case involving a technique similar to the one used by the <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/l\/darkgate-malware.html\" target=\"_blank\" rel=\"noopener\">DarkGate malware<\/a>&nbsp;where the user experienced email flooding before being contacted by external actor posing as IT support or helpdesk. In this sample case, the external email address is<i> <b>admin_52351@brautomacao565[.]onmicrosoft[.]com<\/b><\/i>.&nbsp; &nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"38.990936555891\">\n<div readability=\"25.031218529708\">\n<p>During the call, the user was persuaded by the attacker to grant him access through the built-in Quick Assist tool. It allows users to share their Windows device remotely, enabling screen viewing, annotations, and full control for troubleshooting. Microsoft has previously published their own <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/05\/15\/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware\/\" target=\"_blank\" rel=\"noopener\">analysis<\/a> of how threat actors exploit this by impersonating IT support to gain unauthorized access. This tactic, observed since late last year, has been attributed to <a href=\"https:\/\/www.rapid7.com\/blog\/post\/2024\/12\/04\/black-basta-ransomware-campaign-drops-zbot-darkgate-and-custom-malware\/\" target=\"_blank\" rel=\"noopener\">Black Basta ransomware<\/a>.<\/p>\n<p>After gaining initial access, the attacker downloaded two different malicious .bpx files from a commercial cloud storage provider. <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/j\/fake-lockbit-real-damage-ransomware-samples-abuse-aws-s3-to-stea.html\" target=\"_blank\" rel=\"noopener\">Reports<\/a> have observed how threat actors frequently abuse commercial cloud storage services for malware distribution due to their ease of use, widespread adoption, and the risk of misconfigured or publicly accessible buckets.<\/p>\n<p>The following are the downloaded files from the first case:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">C:\\Users\\&lt;user&gt;\\Downloads\\kb052117-01.bpx<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\Users\\&lt;user&gt;\\Downloads\\kb052123-02.bpx<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div readability=\"34\">\n<div readability=\"13\">\n<p>Based on our threat intelligence, the attacker concatenates the two .bpx files into \u201cpack.zip\u201d. In this case, the attacker used the command <b><i>type kb052117-01.bpx kb052123-02.bpx&nbsp; &gt; pack.zip <\/i><\/b>that will concatenate the two .bpx files into a pack.zip, the content of which will be unpacked using Tar.&nbsp;The name of the bpx files varies from case to case. <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31\">\n<div readability=\"7\">\n<p>The following files were created after the extraction of pack.zip:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">C:\\Users\\&lt;user&gt;\\AppData\\Local\\Temp\\arch1284.cab<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\Users\\&lt;user&gt;\\AppData\\Local\\Temp\\arch1271.cab<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div readability=\"36.787965616046\">\n<div readability=\"18.89111747851\">\n<p>The file <b><i>arch1271.cab<\/i><\/b> was extracted to place those extracted files into the OneDrive folder:<\/p>\n<p><i><span class=\"blockquote\">Command: expand&nbsp; &#8220;C:\\Users\\&lt;user&gt;\\AppData\\Local\\Temp\\arch1271.cab&#8221; -F:* &#8220;C:\\Users\\&lt;user&gt;\\AppData\\Local\\Microsoft\\OneDrive&#8221;<\/span><\/i><\/p>\n<p>The following files were created\/dropped after the extraction:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">C:\\Users\\&lt;user&gt;\\AppData\\Local\\Microsoft\\OneDrive\\winhttp.dll<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\Users\\&lt;user&gt;\\AppData\\Local\\Microsoft\\OneDrive\\libssl-3-x64.dll<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\Users\\&lt;user&gt;\\AppData\\Local\\Microsoft\\OneDrive\\vcruntime140.dll<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\Users\\&lt;user&gt;\\AppData\\Local\\Microsoft\\OneDrive\\OneDriveStandaloneUpdater.exe<\/span><\/li>\n<li><span class=\"rte-red-bullet\">C:\\Users\\&lt;user&gt;\\AppData\\Local\\Microsoft\\OneDrive\\libcrypto-3-x64.dll<\/span><\/li>\n<\/ul>\n<p>The OneDriveStandaloneUpdater.exe process was later launched noninteractively via cmd.exe with the following command-line instruction:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">CLI command: &#8220;C:\\Users\\&lt;user&gt;\\AppData\\Local\\Microsoft\\OneDrive\\OneDriveStandaloneUpdater.exe&#8221; -Embedding.<\/span><\/li>\n<\/ul>\n<p><a href=\"https:\/\/medium.com\/walmartglobaltech\/qbot-is-back-connect-2d774052369f\" target=\"_blank\" rel=\"noopener\">Research<\/a> says that winhttp.dll is a malicious loader that is sideloaded by the Onedrive executable. This loader &nbsp;decrypts the backdoor from a dat file named settingsbackup.dat which is also contained in pack.zip<\/p>\n<p>Contents of pack.zip:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">libcrypto-3-x64.dll (e45b73a5f9cdf335a17aa97a25644489794af8e1)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">libssl-3-x64.dll (9c8dea7602a99aa15f89a46c2b5d070e3ead97f9)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Settingsbackup.dat (11ec09ceabc9d6bb19e2b852b4240dc7e0d8422e)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Vcruntime140.dll (00149b7a66723e3f0310f139489fe172f818ca8e)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Winhttp.dll (232fdfde3c0e180ad91ebeb863bfd8d58915dd39)<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div readability=\"34\">\n<div readability=\"13\">\n<p>After the update process, several key configuration files were modified by the <b>OneDrive Standalone Updater<\/b>:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>C:\\Users\\&lt;user&gt;\\AppData\\Local\\Temp\\.ses<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>C:\\Users\\&lt;user&gt;\\AppData\\Local\\Microsoft\\OneDrive\\StandaloneUpdater\\PreSignInSettingsConfig.json<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>C:\\Users\\&lt;user&gt;\\AppData\\Local\\Microsoft\\OneDrive\\StandaloneUpdater\\Update.xml<\/b><\/span><\/li>\n<\/ul>\n<p>We observed OneDrive Standalone Updater connecting to the external IP <b><i>38.180.25[.]3<\/i><\/b>, which is flagged as Dangerous and categorized as C&amp;C server.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"37.409836065574\">\n<div readability=\"21.377049180328\">\n<p>The attacker also added the following registry entry to store their BackConnect IPs:<\/p>\n<p><i><span class=\"blockquote\">reg&nbsp; add &#8220;HKCU\\SOFTWARE\\TitanPlus&#8221; \/v 1 \/t REG_SZ \/d &#8220;38.180.25.3A443;45.8.157.199A443;5.181.3.164A443&#8221; \/f<\/span><\/i><\/p>\n<p>Based on Trend Micro <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/network\/intrusion-prevention\/threat-intelligence.html\" target=\"_blank\" rel=\"noopener\">Threat Intelligence<\/a>, the IPs used in the above registry key are associated with Black Basta, with the IPs classified as C&amp;C servers.<\/p>\n<p><span class=\"body-subhead-title\">Cactus ransomware attack chain<\/span><\/p>\n<p>The Trend Micro IR team encountered an evolution of the attack chain we detailed earlier. While the initial tactics closely mirrored the campaign, we observed several additional techniques that provide further insight into the adversary\u2019s evolving methods.<b><\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"35.5\">\n<div readability=\"16\">\n<p>The campaign used familiar methods:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Email bombing and social engineering:<\/b> An email flood was launched, followed by contact via Microsoft Teams from the address admin_734@gamicalstudio[.]onmicrosoft[.]com. Using the previously observed social engineering techniques, the victim was persuaded to grant remote access via Quick Assist.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Malicious file downloads and archive manipulation:<\/b> Two .bpx files were downloaded, then concatenated into a single archive (pack.zip), which, upon extraction, produced files similar to those seen in the earlier attack.:<\/span>\n<ul>\n<li><span class=\"rte-circle-bullet\">C:\\Users\\&lt;user&gt;\\Downloads\\kb153056-01.bpx<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">C:\\Users\\&lt;user&gt;\\Downloads\\kb153064-02.bpx<\/span><\/li>\n<\/ul>\n<\/li>\n<li><span class=\"rte-red-bullet\">The same files were created upon extracting the \u2018.cab\u2019 archives:<\/span>\n<ul>\n<li><span class=\"rte-circle-bullet\">C:\\Users\\&lt;user&gt;\\AppData\\Local\\Microsoft\\OneDrive\\OneDriveStandaloneUpdater.exe<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">C:\\Users\\&lt;user&gt;\\AppData\\Local\\Microsoft\\OneDrive\\wscapi.dll<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">C:\\Users\\&lt;user&gt;\\AppData\\Local\\Microsoft\\OneDrive\\libssl-3-x64.dll<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">C:\\Users\\&lt;user&gt;\\AppData\\Local\\Microsoft\\OneDrive\\vcruntime140.dll<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">C:\\Users\\&lt;user&gt;\\AppData\\Local\\Microsoft\\OneDrive\\libcrypto-3-x64.dll<\/span><\/li>\n<\/ul>\n<\/li>\n<li><span class=\"rte-red-bullet\">\u201cHKCU\\SOFTWARE\\TitanPlus\u201d was also added as registry to store BACKCONNECTC2 IP addresses:<\/span>\n<ul>\n<li><span class=\"rte-circle-bullet\">add &#8220;HKLM\\SOFTWARE\\TitanPlus&#8221; \/v 1 \/t REG_SZ \/d &#8220;45B8B157B199A443;5B181B3B164A443;38B180B25B3A443&#8221;<\/span>\n<ul>\n<li><span class=\"rte-square-bullet\"><span class=\"rte-red-chevron\">45.8.157[.]199;443;5.181.3[.]164;443;38.180.25[.]3;443<\/span><\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li><span class=\"rte-red-bullet\">The same C&amp;C infrastructure was observed in case with Black Basta, being utilized with BackConnect:<\/span>\n<ul>\n<li><span class=\"rte-circle-bullet\">45[.]8[.]157[.]199<\/span>\n<ul>\n<li><span class=\"rte-circle-bullet\">5[.]181[.]3[.]164<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">38[.]180[.]25[.]3<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">185[.]190[.]251[.]16<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">207[.]90[.]238[.]52<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">89[.]185[.]80[.]86<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Building on the initial foothold, the adversary used advanced lateral movement techniques to expand their presence:<\/p>\n<p><b>Server Message Block (SMB) and Windows Remote Management (WinRM):<\/b> The attacker utilized SMB via shared folders and used WinRM to remotely execute commands and scripts, allowing them to traverse the network.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"37\">\n<div readability=\"19\">\n<p><b>ESXi host compromise:<\/b> Notably, we identified the compromise of ESXi hosts. A binary, socks.out \u2014 believed to be the SystemBC proxy malware \u2014 was deployed. By enabling an SSH session as the root user, they:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Disabled the ExecInstalledOnly setting (which normally restricts execution to binaries installed via official VIBs).<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Turned off the firewall, thereby permitting unauthorized binaries to run.<\/span><\/li>\n<\/ul>\n<p>This sequence of actions culminated in the execution of the socks.out binary without interference from system protections.<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Analysis further revealed that the attackers leveraged WinSCP\u2014an open-source file transfer client\u2014as part of their operational process:<b>Leveraging WinSCP:<\/b> &nbsp;WinSCP was employed to facilitate file transfers within the compromised environment. Firewall logs confirmed notable network activity involving WinSCP connecting to a newly registered, suspicious domain.Pumpkinrab[.]com \u2013 208[.]115[.]200[.]146.<\/span><\/li>\n<\/ul>\n<p>&nbsp;The adversary deployed WinSCP across multiple compromised hosts, suggesting that the tool was distributed to streamline their operations.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"52.331393014853\">\n<div readability=\"49.839421918908\">\n<p>Our incident response efforts successfully subverted the attempt to encrypt the victim\u2019s network. However, the sequence of events clearly indicates that encryption was their intended next step. A ransom note was sent via email, with the attackers identifying themselves as the \u201cCactus Group.\u201d<\/p>\n<p><span class=\"body-subhead-title\">The Black Basta chat log leaks<\/span><\/p>\n<p>On February 11, 2025, a significant leak exposed the internal communications and organizational structure of the Black Basta group. According to the published information, the data was released due to an internal misunderstanding. The group has reportedly targeted Russian banks. &nbsp;The leaked archive contains messages exchanged in Black Basta&#8217;s internal chat rooms between September 18, 2023, and September 28, 2024.<\/p>\n<p>Analysis of the messages uncovers a broad spectrum of information, such as phishing templates and their target emails, cryptocurrency addresses, victims&#8217; credentials, and information about gang members. The information was firstly published by <a href=\"https:\/\/x.com\/PRODAFT\/status\/1892636346885235092\" target=\"_blank\" rel=\"noopener\">PRODAFT.<\/a><\/p>\n<p>While reviewing the leak data we have observed messages indicating that Black Basta operators <b>recognize Trend Micro as a significant obstacle<\/b> and discuss ways to bypass it.&nbsp; Here are their key views:<\/p>\n<p><b>1. Trend Micro is a Major Security Challenge<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">One actor explicitly states that <b>Trend Micro is widely used<\/b> and must be bypassed:<br \/><i>&#8220;TrendMicro \u043c\u043d\u043e\u0433\u043e \u0433\u0434\u0435 \u0441\u0442\u043e\u0438\u0442, \u043d\u0430\u0434\u043e \u043e\u0431\u0445\u043e\u0434\u0438\u0442\u044c&#8221;<\/i> (&#8220;Trend Micro is used in many places, we need to bypass it&#8221;).<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Another user confirms that <b>Trend Micro XDR is particularly difficult to evade<\/b>:<br \/><i>&#8220;\u043c\u0435\u043b\u043a\u0438\u0439 \u043d\u0435 \u043c\u043e\u0436\u0435\u0442 \u043e\u0431\u0445\u043e\u0434\u0438\u0442\u044c Trend Micro XDR&#8221;<\/i> (&#8220;Melky can&#8217;t bypass Trend Micro XDR&#8221;).<\/span><\/li>\n<\/ul>\n<p><b>2. Testing and Workarounds<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Some group members discuss <b>testing Trend Micro detection capabilities<\/b> using brute-force techniques:<br \/><i>&#8220;\u0441 \u0442\u0440\u0435\u043d\u0434\u043e\u043c \u0432\u0441\u0435 \u043e\u043a \u043d\u0430 \u0431\u0440\u0443\u0442\u0435 \u0434\u043e\u043b\u0436\u043d\u043e \u0431\u044b\u0442\u044c&#8221;<\/i> (&#8220;With Trend, everything should be fine on brute&#8221;).<\/span><\/li>\n<li><span class=\"rte-red-bullet\">There is also mention of <b>Trend Micro being a persistent issue in their operations<\/b>, frustrating them when trying to bypass its protections.<\/span><\/li>\n<\/ul>\n<p>Additionally, some of the key members of Black Basta have left the group to join the Cactus Ransomware operation, as observed in the TTPs overlaps between the two groups. Based on that context, Trend assesses that Cactus will remain highly active, and the experienced members of Basta will carry on their attacks under the Cactus operation. The future of Black Basta is unknown at this moment. It might implode because of the leaks, as was the case with Conti.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"49.158937772493\">\n<div readability=\"44.778438367023\">\n<p>Since early October 2024, activity related to the Black Basta ransomware <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/a\/a-look-into-pikabot-spam-wave-campaign.html\" target=\"_blank\" rel=\"noopener\">social engineering<\/a> campaign has surged. First reported in May, the campaign has evolved with <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/b\/threat-actor-groups-including-black-basta-are-exploiting-recent-.html\" target=\"_blank\" rel=\"noopener\">updated tactics<\/a>, improved malware payloads, and the use of Microsoft Teams for lures.<\/p>\n<p>The attacks start with an email bombing campaign, followed by direct contact via Teams, where the attacker impersonates an IT staff. Victims are tricked into installing remote management tools or executing a remote shell, sometimes bypassing multifactor authentication (MFA) via QR codes. Once granted access, additional malware such DarkGate, and custom payloads are deployed to enumerate the environment, extract credentials, and steal VPN configuration files. &nbsp;&nbsp;<\/p>\n<p>Our intelligence indicates that threat actors are using these tactics, techniques, and procedures (TTP) \u2014 vishing, Quick Assist as a remote tool, and BACKCONNECT \u2014 to deploy Black Basta ransomware.<\/p>\n<p>Since January 2025, our Threat Intelligence teams have observed a likely shift in affiliations among certain threat actors associated with Black Basta. Specifically, there is evidence suggesting that members have transitioned from the Black Basta ransomware group to the Cactus ransomware group. This conclusion is drawn from the analysis of similar tactics, techniques, and procedures (TTPs) being utilized by the Cactus group.&#8221;<\/p>\n<p>To mitigate the risk of ransomware and similar attacks, organizations should consider the following key measures:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Restrict remote assistance tools. <\/b>Disable unauthorized usage of remote access tools. Implement strict policies for remote assistance usage, requiring approval or verification. Layering access control, monitoring, and authentication measures helps reduce the risks associated with remote assistance tools.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Train employees on social engineering<\/b>. Regularly educate users about phishing scams and fake remote assistance attempts, reinforcing verification of all unsolicited requests. Companies should actively test, measure, and improve user response rates through behavior-driven training programs to enhance employee resilience against evolving social engineering tactics.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Apply Microsoft\u2019s security<\/b> <a href=\"https:\/\/learn.microsoft.com\/en-gb\/MicrosoftTeams\/teams-security-best-practices-for-safer-messaging?ocid=magicti_ta_learndoc\" target=\"_blank\" rel=\"noopener\">best practices for Microsoft Teams<\/a> to safeguard Teams users. Companies should also treat Teams as a critical enterprise communication tool that requires the same level of security monitoring as email. Apply security to third-party integrations and external communications to prevent impersonation attacks.<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div readability=\"33.61821086262\">\n<div readability=\"13.642172523962\">\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/one-platform.html\" title=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/one-platform.html\" target=\"_blank\" rel=\"noopener\">Trend Vision One<\/a>\u2122&nbsp;is&nbsp;an enterprise cybersecurity platform that simplifies security and helps enterprises detect and stop threats faster by consolidating multiple security capabilities, enabling greater command of the enterprise\u2019s attack surface, and providing complete visibility into its cyber risk posture.&nbsp;The cloud-based platform leverages AI and threat intelligence from 250 million sensors and 16 threat research centers around the globe to provide comprehensive risk insights, earlier threat detection, and automated risk and threat response options in a single solution.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"33.989349112426\">\n<div readability=\"19.422485207101\">\n<p><span class=\"body-subhead-title\">Trend Vision One Threat Intelligence<\/span><\/p>\n<p>To stay ahead of evolving threats,\u202f<a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/one-platform.html\" target=\"_blank\" rel=\"noopener\">Trend Vision One&nbsp;<\/a>customers can access a range of Intelligence Reports and Threat Insights within Vision One. Threat Insights helps customers stay ahead of cyber threats before they happen and allows them to prepare for emerging threats by offering comprehensive information on threat actors, their malicious activities, and their techniques. By leveraging this intelligence, customers can take proactive steps to protect their environments, mitigate risks, and effectively respond to threats.<\/p>\n<p><b>Trend Vision One Intelligence Reports App [IOC Sweeping]<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal<\/span><\/li>\n<\/ul>\n<p><b>Trend Vision One Threat Insights App<\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"34.5\">\n<div readability=\"14\">\n<p><b>Trend Vision One Search App<\/b><\/p>\n<p>Trend Vision One customers can use the Search App to match or hunt the malicious indicators mentioned in this blog post using data within their environment. <b>Note that this can also be triggered by normal activity.<\/b><\/p>\n<p><b>Detection of DLL side-loading involves identifying modified DLLs that replace legitimate ones to execute unauthorized code.<\/b><\/p>\n<ul>\n<li><span class=\"blockquote\">eventSubId: 603 AND (request:filters*.s3.us-east-2.amazonaws.com OR request:sfu*.s3.us-east-2.amazonaws.com) AND objectFilePath:kb*.bpx<\/span><\/li>\n<li><span class=\"blockquote\">service: MicrosoftTeams AND principalName:\u202f*.onmicrosoft.com AND actionName:(ChatCreated OR MessageSent)<\/span><\/li>\n<li>&nbsp;<\/li>\n<\/ul>\n<ul>\n<li><span class=\"rte-red-bullet\">tags:<\/span>\n<\/li>\n<li><span class=\"rte-circle-bullet\">XSAE.F8809&nbsp;(QuickAssist&nbsp;Remote&nbsp;Session&nbsp;Established)<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">XSAE.F11212&nbsp;(TitanPlus&nbsp;Installation)<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">XSAE.F11530&nbsp;(Anomalous&nbsp;Connection&nbsp;from&nbsp;OneDrive&nbsp;Binary)<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">XSAE.F11531&nbsp;(Cabinet&nbsp;File&nbsp;Expanded&nbsp;via&nbsp;Lolbin)<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">XSAE.F11532&nbsp;(Cabinet&nbsp;File&nbsp;Expansion&nbsp;via&nbsp;Lolbin)<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">XSAE.F11534&nbsp;(TitanPlus&nbsp;Installation&nbsp;&#8211;&nbsp;Process&nbsp;Create)<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div readability=\"31\">\n<div readability=\"7\">\n<p>Here are other BACKCONNECT-related IPs based on Trend Micro Threat Intelligence:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">5.181.159[.]48<\/span><\/li>\n<li><span class=\"rte-red-bullet\">45.128.149[.]32<\/span><\/li>\n<li><span class=\"rte-red-bullet\">207.90.238[.]46<\/span><\/li>\n<li><span class=\"rte-red-bullet\">45.8.157[.]158<\/span><\/li>\n<li><span class=\"rte-red-bullet\">195.123.233[.]19<\/span><\/li>\n<li><span class=\"rte-red-bullet\">178.236.247[.]173<\/span><\/li>\n<li><span class=\"rte-red-bullet\">195.123.241[.]24<\/span><\/li>\n<li><span class=\"rte-red-bullet\">20.187.1[.]254<\/span><\/li>\n<li><span class=\"rte-red-bullet\">5.78.41[.]255<\/span><\/li>\n<li><span class=\"rte-red-bullet\">38.180.192[.]243<\/span><\/li>\n<li><span class=\"rte-red-bullet\">207.90.238[.]52<\/span><\/li>\n<li><span class=\"rte-red-bullet\">89.185.80[.]251<\/span><\/li>\n<li><span class=\"rte-red-bullet\">91.90.195[.]91<\/span><\/li>\n<li><span class=\"rte-red-bullet\">45.8.157[.]162<\/span><\/li>\n<li><span class=\"rte-red-bullet\">20.82.136[.]218<\/span><\/li>\n<li><span class=\"rte-red-bullet\">45.8.157[.]146<\/span><\/li>\n<li><span class=\"rte-red-bullet\">5.181.3[.]164<\/span><\/li>\n<li><span class=\"rte-red-bullet\">195.123.233[.]148<\/span><\/li>\n<li><span class=\"rte-red-bullet\">45.8.157[.]199<\/span><\/li>\n<li><span class=\"rte-red-bullet\">89.185.80[.]86<\/span><\/li>\n<li><span class=\"rte-red-bullet\">195.211.96[.]135<\/span><\/li>\n<li><span class=\"rte-red-bullet\">38.180.25[.]3<\/span><\/li>\n<li><span class=\"rte-red-bullet\">38.180.135[.]232<\/span><\/li>\n<li><span class=\"rte-red-bullet\">185.190.251[.]16<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<p>Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/25\/b\/black-basta-cactus-ransomware-backconnect.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this blog entry, we discuss how the Black Basta and Cactus ransomware groups utilized the BackConnect malware to maintain persistent control and exfiltrate sensitive data from compromised machines. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":58234,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9534,9513,9539,9509],"class_list":["post-58233","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-latest-news","tag-trend-micro-research-malware","tag-trend-micro-research-ransomware","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2025-03-03T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/QBackConnect-thumbnail:Large?qlt=80\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal\",\"datePublished\":\"2025-03-03T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\\\/\"},\"wordCount\":2195,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal.png\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Latest News\",\"Trend Micro Research : Malware\",\"Trend Micro Research : Ransomware\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\\\/\",\"name\":\"Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal.png\",\"datePublished\":\"2025-03-03T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal.png\",\"width\":976,\"height\":533},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/","og_locale":"en_US","og_type":"article","og_title":"Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2025-03-03T00:00:00+00:00","og_image":[{"url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/QBackConnect-thumbnail:Large?qlt=80","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal","datePublished":"2025-03-03T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/"},"wordCount":2195,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/03\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal.png","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Latest News","Trend Micro Research : Malware","Trend Micro Research : Ransomware","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/","url":"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/","name":"Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/03\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal.png","datePublished":"2025-03-03T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/03\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/03\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal.png","width":976,"height":533},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/black-basta-and-cactus-ransomware-groups-add-backconnect-malware-to-their-arsenal\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Black Basta and Cactus Ransomware Groups Add BackConnect Malware to Their Arsenal"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58233","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=58233"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/58233\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/58234"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=58233"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=58233"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=58233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}