216.73.217.22

DNS Early Detection - Breaking the Black Basta Ransomware Kill Chain

· Published 02/08/2024 08:43 · Modified 02/08/2024 09:03

Export JSON

Essential information

Published
02/08/2024 08:43
Modified
02/08/2024 09:03
Tags
2024-08-02 black basta dns ransomware threat intelligence
Related entities
1 vulnerabilities (cve), 1 observables, 1 intrusion sets (apt), 8 techniques (mitre), 1 malware, 2 others

Description

This intelligence analysis examines the campaign, which has significantly impacted businesses and critical infrastructure across North America, Europe, and Australia. The report highlights Infoblox's ability to identify and block over 78% of the malicious domains associated with , on average 59.5 days prior to their availability in open-source intelligence (OSINT) sources. Infoblox's Early Detection capability enabled the proactive blocking of these malicious domains, potentially preventing data theft, legal implications, and other consequences for affected organizations.

External references