Back Issues This Week → Current Issue → Popular →

All issuesVolume 327, Issue 2IT Vendor NewsRapid7

Blacksuit Continues Social Engineering Attacks In Wake Of Black Basta's Internal Conflict

Rapid7, Tuesday, June 10th, 2025

There has been a significant decrease in social engineering attacks linked to the Black Basta ransomware group since late December 2024.

This lapse also included the leaked Black Basta chat logs in February 2025, indicating internal conflict within the group. Despite this, Rapid7 has observed sustained social engineering attacks. Evidence now suggests that BlackSuit affiliates have either adopted Black Basta's strategy or absorbed members of the group. The developer(s) of a previously identified Java malware family, distributed during social engineering attacks, have now been assessed as likely initial access brokers, having potentially provided historical access for Black Basta and/or FIN7 affiliates.

more →  ·  More from Rapid7 →