Skip to content
NetarxImpact Database
Vishing (Voice Phishing)No AI reportedConfirmedCampaign

Storm-1811 email-bombs targets then poses as IT support to deploy Black Basta

Multiple organisations (campaign) · Other · Multiple · May 15, 2024

What happened

Microsoft published research in May 2024 on Storm-1811, a financially motivated group that flooded targets' inboxes with subscription confirmations, then telephoned the overwhelmed user posing as their IT help desk offering to fix the problem. Victims were talked into granting remote control through Windows Quick Assist, after which the attackers deployed remote monitoring tools, Qakbot, Cobalt Strike and ultimately Black Basta ransomware. By late May 2024 the group had extended the same approach to Microsoft Teams.

How the deception worked

The operators first signed a target's email address up to large numbers of mailing lists and subscription services, producing an inbox flood that created genuine urgency. They then called the user, or messaged and called through Microsoft Teams using externally-federated tenants with help-desk-styled display names, and offered to resolve the email problem. They instructed the user to open Quick Assist and share the security code, giving the attacker interactive control of the desktop. From there they ran scripted commands to download ScreenConnect, NetSupport Manager, Cobalt Strike and SystemBC, harvested domain credentials, moved laterally, and used PsExec to push Black Basta across the estate.

AI involvement · No AI reported

Microsoft reported live human callers, not synthetic voice.

The control that would have caught it· our reading, not a claim from the sources

Restrict or block Quick Assist and unsolicited external Teams contact, and give staff a single verified internal channel for IT support so an inbound call offering help is by definition suspect.

Sources (3)

  1. Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
    Microsoft Security Blog·microsoft.comOpen ↗
  2. Sophos MDR tracks two ransomware campaigns using email bombing and Microsoft Teams vishing
    Sophos·sophos.comOpen ↗
  3. Windows Quick Assist Anchors Black Basta Ransomware Gambit
    Dark Reading·darkreading.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.