Ransomware Rumble: Black Basta & CACTUS Share the Same Nasty Secret!
Threat actors are using the same BackConnect module for both Black Basta and CACTUS ransomware. Affiliates might have switched loyalties, like changing from Pepsi to Coke. This module grants attackers remote control, allowing them to pilfer sensitive data faster than a raccoon in a dumpster.

Hot Take:
Looks like the ransomware world is playing a game of musical chairs, and Black Basta and CACTUS are sharing the same seat! These cybercriminals are using the same BackConnect module like it’s the latest fashion trend in the dark web. Who knew cybercrime could be so collaborative? Next, they’ll be forming a ransomware boy band—BackSync, anyone?
Key Points:
– Black Basta and CACTUS ransomware families are using the same BackConnect module for persistent control.
– The BC module, also known as QBACKCONNECT, has ties to QakBot loader.
– Black Basta has been using email bombing and IT support scams to deploy malware.
– CACTUS ransomware employs similar tactics but had a hiccup in encrypting a network.
– Chat log leaks reveal Black Basta’s internal workings and shared credentials.