216.73.216.226

Takes Aim at the Ransomware Throne

· Published 17/04/2026 10:36 · Modified 17/04/2026 11:15

Export JSON

Essential information

Published
17/04/2026 10:36
Modified
17/04/2026 11:15
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
aes encryption blackbasta blackbasta affiliates cactus direct system calls edr evasion microsoft teams payouts king quick assist rsa encryption spam bombing
Tags
2026-04-17 aes encryption blackbasta blackbasta affiliates cactus direct system calls edr evasion microsoft teams payouts king quick assist rsa encryption spam bombing
Related entities
2 indicators, 2 observables, 1 intrusion sets (apt), 20 techniques (mitre), 3 malware

Description

In February 2025, ransomware operations ceased after their internal chat logs were leaked online, leading to disbandment. However, former affiliates continued launching attacks using different ransomware families, including the relatively unknown group that emerged in April 2025. ThreatLabz has observed continued ransomware activity consistent with former initial access brokers since early 2026, utilizing similar tactics including , phishing, and abuse. implements sophisticated evasion techniques including stack-based string obfuscation, API hashing, and to terminate security processes. The ransomware leverages 4,096-bit RSA and 256-bit AES counter mode encryption, selectively encrypting files while targeting security software and employing anti-forensics techniques like shadow copy deletion and event log clearing.

External references