Gone But Not Forgotten: Black Basta’s Enduring Legacy

The ransomware group Black Basta disbanded after internal chat leaks, but its tactics, especially mass email spam and Microsoft Teams phishing, continue to be used by former members and new groups. Emerging attack methods now include Python script execution with cURL for payload delivery, emphasizing the need for strong user education and vigilant defense strategies. #BlackBasta #MicrosoftTeamsPhishing #CactusRaaS

Read More
A Brief History of DanaBot, Longtime Ecrime Juggernaut Disrupted by Operation Endgame

DanaBot, originally identified as a banking trojan in 2018, has evolved into a multifunction malware-as-a-service used by various cybercrime groups and recently resurfaced in 2024 with targeted campaigns in logistics and hospitality sectors. Law enforcement disrupted DanaBot’s infrastructure in May 2025 as part of Operation Endgame, highlighting the malware’s intersection with…

Read More
Operation Endgame 2.0: DanaBusted

Operation Endgame recently targeted DanaBot, a modular malware used for banking fraud, espionage, and deploying additional malware payloads such as ransomware. DanaBot operates on a Malware-as-a-Service model and has been involved in both criminal and nation-state activities, including DDoS attacks against Ukrainian government servers. #DanaBot #OperationEndgame #ZscalerThreatLabz

Read More