216.73.216.6

Fake Zoom Ends in BlackSuit Ransomware

· Published 31/03/2025 05:40 · Modified 31/03/2025 15:56

Export JSON

Essential information

Published
31/03/2025 05:40
Modified
31/03/2025 15:56
Tags
2025-03-31 blacksuit brute ratel cobalt strike d3f@ckloader exfiltration lateral movement proxy qdoor ransomware sectoprat
Related entities
32 techniques (mitre), 6 malware

Description

A malicious website mimicking Zoom led to the installation of a trojanized installer, initiating a multi-stage attack. The initial payload, , downloaded additional components, including . After nine days, the threat actor deployed and beacons for . They used various techniques for discovery and credential access, including LSASS memory dumping. The attacker employed for proxying RDP connections, facilitating data collection and via the cloud service Bublup. The intrusion culminated in the deployment of across multiple systems using PsExec, with a total time to of 194 hours over nine days.

External references