Security News > 2025 > March > Researchers Link CACTUS Ransomware Tactics to Former Black Basta Affiliates

2025-03-04 16:21
Threat actors deploying the Black Basta and CACTUS ransomware families have been found to rely on the same BackConnect (BC) module for maintaining persistent control over infected hosts, a sign that affiliates previously associated with Black Basta may have transitioned to CACTUS. "Once infiltrated, it grants attackers a wide range of remote control capabilities, allowing them to execute
News URL
https://thehackernews.com/2025/03/researchers-link-cactus-ransomware.html
Related news
- Black Basta ransomware gang's internal chat logs leak online (source)
- Leaked Black Basta Ransomware Chat Logs Reveal Inner Workings and Internal Conflicts (source)
- Southern Water says Black Basta ransomware attack cost £4.5M in expenses (source)
- Microsoft Teams tactics, malware connect Black Basta, Cactus ransomware (source)