Feds Warn Healthcare Sector About Targeted Black Basta Ransomware Attacks
A joint cybersecurity advisory has been issued about the Black Basta ransomware group. Black Basta is known to target critical infrastructure entities in the United States, has stepped up attacks on the healthcare and public health sector, and is reportedly behind the recent Ascension ransomware attack. The group conducts high-impact attacks that are designed to disrupt clinical operations and engage in double extortion tactics, stealing data and encrypting files.
The cybersecurity advisory was issued by the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Department of Health and Human Services (HHS), and Multi-State Information Sharing and Analysis Center (MS-ISAC) and shares up-to-date information on the tactics, techniques, and procedures used by the group in its attacks, along with indicators of Compromise identified through FBI investigations and third-party reporting to help network defenders identify and block attacks in progress.
The Black Basta ransomware variant was first detected in April 2022 and is used by a ransomware-as-a-service (RaaS) group that attacks businesses and critical infrastructure entities in North America, Europe, and Australia. The RaaS group is now the second most active group behind LockBit according to ReliaQuest, having conducted 102 attacks in Q1, 2024, with CISA reporting that the group has conducted at least 500 attacks globally.
Black Basta ransomware affiliates primarily use spear phishing for initial access to victims’ networks and often use stolen credentials and exploit vulnerabilities. Since February 2024, the group has been exploiting the ConnectWise vulnerability, CVE-2024-1709. Once access has been gained, the group conducts reconnaissance using tools such as the Soft Perfect network scanner, and BITSAdmin, PsExec, and Remote Desktop Protocol for lateral movement, Mimikatz is used for privilege escalation, RClone to assist with data exfiltration, and PowerShell and Backstab to disable antivirus and endpoint detection solutions. Some affiliates have been observed using tools such as Splashtop, Screen Connect, and Cobalt Strike beacons to assist with remote access and lateral movement.
The authoring agencies make several recommendations for improving defenses against attacks. Baseline security protections include ensuring software, firmware, and operating systems are updated as soon as updates are released, implementing phishing-resistant multifactor authentication, securing remote access software, ensuring backups are made of data, critical systems, and device configurations, and training all users on how to recognize and avoid phishing attempts. Several other recommendations and security best practices are detailed in the alert.