{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-storm-1811-email-bombs-targets-then-poses-as-it-support-to-deploy-black"},"incident":{"title":"Storm-1811 email-bombs targets then poses as IT support to deploy Black Basta","date":"2024-05-15","date_precision":"day","victim_org":"Multiple organisations (campaign)","sector":"Other","country":"Multiple","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation","Tech Support Scam","Callback Phishing (TOAD)"],"ai_involvement":"No AI reported","ai_notes":"Microsoft reported live human callers, not synthetic voice.","outcomes":["Ransomware Deployment","Extortion","Data Breach","Service Disruption"],"loss_usd":null,"loss_note":"No aggregate loss figure published for the campaign.","records_affected":null,"threat_actor":"Storm-1811, deploying Black Basta ransomware","summary":"Microsoft published research in May 2024 on Storm-1811, a financially motivated group that flooded targets' inboxes with subscription confirmations, then telephoned the overwhelmed user posing as their IT help desk offering to fix the problem. Victims were talked into granting remote control through Windows Quick Assist, after which the attackers deployed remote monitoring tools, Qakbot, Cobalt Strike and ultimately Black Basta ransomware. By late May 2024 the group had extended the same approach to Microsoft Teams.","how_it_worked":"The operators first signed a target's email address up to large numbers of mailing lists and subscription services, producing an inbox flood that created genuine urgency. They then called the user, or messaged and called through Microsoft Teams using externally-federated tenants with help-desk-styled display names, and offered to resolve the email problem. They instructed the user to open Quick Assist and share the security code, giving the attacker interactive control of the desktop. From there they ran scripted commands to download ScreenConnect, NetSupport Manager, Cobalt Strike and SystemBC, harvested domain credentials, moved laterally, and used PsExec to push Black Basta across the estate.","lessons":"Restrict or block Quick Assist and unsolicited external Teams contact, and give staff a single verified internal channel for IT support so an inbound call offering help is by definition suspect.","confidence":"Confirmed","sources":[{"title":"Threat actors misusing Quick Assist in social engineering attacks leading to ransomware","url":"https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/","publisher":"Microsoft Security Blog"},{"title":"Sophos MDR tracks two ransomware campaigns using email bombing and Microsoft Teams vishing","url":"https://www.sophos.com/en-us/blog/sophos-mdr-tracks-two-ransomware-campaigns-using-email-bombing-microsoft-teams-vishing","publisher":"Sophos"},{"title":"Windows Quick Assist Anchors Black Basta Ransomware Gambit","url":"https://www.darkreading.com/threat-intelligence/windows-quick-assist-anchors-black-basta-ransomware","publisher":"Dark Reading"}],"entry_type":"campaign","slug":"2024-storm-1811-email-bombs-targets-then-poses-as-it-support-to-deploy-black","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-storm-1811-email-bombs-targets-then-poses-as-it-support-to-deploy-black"}}