Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike

Trend Micro researchers document a QAKBOT-driven intrusion that escalates to Brute Ratel C4 and Cobalt Strike payloads attributed to Black Basta operators, highlighting a shift toward commercial C2/attack emulation tools in real-world ransomware campaigns. The operation employs password-protected ZIPs and ISO containers, TLS/DoH-based C2, and living-off-the-land techniques to evade defenses and enable domain-wide impact. #BruteRatel #BlackBasta #QAKBOT #CobaltStrike

Keypoints

  • The QAKBOT distribution resumed on September 8, 2022 via SmokeLoader, Emotet, and malicious spam with IDs BB and Obama20x.
  • A QAKBOT infection led to Brute Ratel (a C2 framework) as a second-stage payload, marking the first observed Brute Ratel deployment this way; Cobalt Strike was also used for lateral movement.
  • The campaign chain links QAKBOT to Brute Ratel and then to Cobalt Strike, aligning with Black Basta ransomware activity.
  • Brute Ratel/Cobalt Strike blends legitimate red-team tooling with malicious use to evade detection and facilitate persistence and movement.
  • The attackers exploit password-protected ZIPs and ISO files to bypass analysis and “Mark of the Web” (MOTW) defenses.
  • The C2 infrastructure spans multiple countries and uses DoH/HTTPS to hide DNS and traffic patterns.
  • Automated in-environment reconnaissance occurs within minutes of infection, including network, domain, and AD data collection, followed by exfiltration preparation.

MITRE Techniques

  • [T1566.001] Phishing: Spear phishing Attachment – The campaign commences via a SPAM email containing a malicious new URL. The URL landing page presents the recipient with a password for a ZIP file. “…The campaign commences via a SPAM email containing a malicious new URL. The URL landing page presents the recipient with a password for a ZIP file.”
  • [T1566.002] Phishing: Spear phishing Link – “QAKBOT has spread through emails with newly created malicious links.”
  • [T1204.001] User Execution: Malicious Link – “QAKBOT has gained execution through users accessing malicious link.”
  • [T1204.002] User Execution: Malicious Attachment – “QAKBOT has gained execution through users opening malicious attachments.”
  • [T1547.001] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder – “QAKBOT can maintain persistence by creating an auto-run Registry key.”
  • [T1055] Process Injection – “QAKBOT can inject itself into processes like wermgr.exe.”
  • [T1027.006] Obfuscated Files or Information: HTML Smuggling – “HTML Smuggling.”
  • [T1218.010] System Binary Proxy Execution: Regsvr32 – “QAKBOT can use Regsvr32 to execute malicious DLLs; Cobalt Strike can use rundll32.exe to load DLL from the command line.”
  • [T1140] Deobfuscate/Decode Files or Information – “Initial QAKBOT .zip file bypasses some antivirus detections due to password protections.”
  • [T1562.009] Impair Defenses: Safe Boot Mode – “Black Basta uses bcdedit to boot the device in safe mode.”
  • [T1010] Application Window Discovery – “QAKBOT can enumerate windows on a compromised host.”
  • [T1135] Network Share Discovery – “net share to identify network shares for use in lateral movement.”
  • [T1069.001] Permission Groups Discovery: Local Groups – “net localgroup to enable the discovery of local groups.”
  • [T1057] Process Discovery – “check running processes.”
  • [T1018] Remote System Discovery – “net view to identify remote systems.”
  • [T1082] System Information Discovery – “collect system information including the OS version and domain.”
  • [T1016] System Network Configuration Discovery – “net config workstation, arp -a, and ipconfig /all.”
  • [T1049] System Network Connections Discovery – “netstat -nao.”
  • [T1033] System Owner/User Discovery – “identify the username on a compromised system.”
  • [T1021] Remote Services: SMB/Windows Admin Shares – “Cobalt Strike can use Windows admin shares (C$ and ADMIN$) for lateral movement.”
  • [T1071.001] Application Layer Protocol: Web Protocols – “QAKBOT can use HTTP and HTTPS in communication with the C&C servers.”
  • [T1573] Encrypted Channel – “Used by QAKBOT, BRUTEL and Cobalt Strike.”
  • [T1486] Data Encrypted for Impact – “Black Basta uses the ChaCha20 algorithm to encrypt files. The ChaCha20 encryption key is then encrypted with a public RSA-4096 key.”
  • [T1490] Inhibit System Recovery – “Black Basta deletes Volume Shadow Copies using vssadmin tool.”
  • [T1491] Defacement – “Replaces the desktop wallpaper to display the ransom note.”

Indicators of Compromise

  • [SHA-256] Initial infection artifacts – 582a5e2b2652284ebb486bf6a367aaa6bb817c856f08ef54db64c6994c5b91bd, 01fd6e0c8393a5f4112ea19a26bedffb31d6a01f4d3fe5721ca20f479766208f
  • [File Name] Attack artifacts – Accounting#7405.iso, Contract.lnk
  • [Domain] Command and Control domains – symantecuptimehost[.]com, fewifasoc[.]com
  • [IP] Command and Control IPs – 45.153.242.251, 45.153.241.88

Read more: https://www.trendmicro.com/en_us/research/22/j/black-basta-infiltrates-networks-via-qakbot-brute-ratel-and-coba.html