web analytics

Black Basta ransomware group’s techniques evolve, as FBI issues new warning in wake of hospital attack – Source: www.exponential-e.com

Rate this post

Source: www.exponential-e.com – Author: Graham Cluley


BLACK-1

Security agencies in the United States have issued a new warning about the Black Basta ransomware group, in the wake of a high-profile attack against the healthcare giant Ascension.

The cyber attack last week forced the Ascension computer systems offline, and caused some hospital emergency departments to turn away ambulances “in order to ensure emergency cases are triaged immediately.”

In a statement, Ascension confirmed that while its hospitals were providing healthcare, the ransomware attack meant that its electronic health records and other systems used to order tests, procedures, and medications were currently unavailable.

Now the FBI, CISA, and other US government agencies have released a joint cybersecurity advisory warning of the Black Basta ransomware that is thought to have impacted over 500 organisations globally since April 2022, including in the United States, UK, India, Canada, Australia, New Zealand, and UAE.

Black Basta, the advisory explains, has encrypted and stolen data from at least 12 of 16 critical infrastructure sectors, including the Healthcare and Public Health (HPH) sector, threatening to release it unless a ransom is paid.

The updated warning comes just as news emerges that Black Basta attacks have adopted a new attack methodology with a social engineering twist.

Security researchers have uncovered that attackers are tricking targeted companies’ users into downloading and installing remote access software using the following cunning technique: 

  • The attackers start by flooding a user’s inbox with spam emails and unwanted newsletters to such an extent that their inboxes become effectively unusable.
  • The attackers call the user, offering to fix the problem.
  • As part of the fix, the targeted employee is duped into installing remote access software, granting the attackers full control of their computer. This gives the attackers the ability to plant malware and steal information.

What probably makes the attack particularly effective is the combined use of both email and phone calls. Many users might naturally be suspicious of emails that arrive in their inbox, but more trusting of phone calls  particularly if they refer to a problem that they really are having with their inbox (namely, a flood of unwanted email that is interrupting their ability to do their job).

Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn’t miss them.

About the author

Graham Cluley is an award-winning cybersecurity public speaker, podcaster, blogger, and analyst. He has been a well-known figure in the cybersecurity industry since the early 1990s when he worked as a programmer, writing the first ever version of Dr Solomon’s Anti-Virus Toolkit for Windows.

Since then he has been employed in senior roles by computer security companies such as Sophos and McAfee.

Graham Cluley has given talks about cybersecurity for some of the world’s largest companies, worked with law enforcement agencies on investigations into hacking groups, and regularly appears on TV and radio explaining computer security threats.

Graham Cluley was inducted into the InfoSecurity Europe Hall of Fame in 2011, and was given an honorary mention in the “10 Greatest Britons in IT History” for his contribution as a leading authority in internet security.

Original Post URL: https://www.exponential-e.com/blog/black-basta-ransomware-groups-techniques-evolve-as-fbi-issues-new-warning-in-wake-of-hospital-attack

Category & Tags: Data loss,Guest blog,Malware,Ransomware,data breach,healthcare,hospital,ransomware,telephone – Data loss,Guest blog,Malware,Ransomware,data breach,healthcare,hospital,ransomware,telephone

Views: 0

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post