ATT&CKReferencesCheck Point Black Basta October 2022

Check Point Black Basta October 2022

Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1018
Remote System Discovery
MalwareBlack Basta

Black Basta can use LDAP queries to connect to AD and iterate over connected workstations.

T1027.001
Binary Padding
MalwareBlack Basta

Black Basta had added data prior to the Portable Executable (PE) header to prevent automatic scanners from identifying the payload.

T1036.005
Match Legitimate Resource Name or Location
MalwareBlack Basta

The Black Basta dropper has mimicked an application for creating USB bootable drivers.

T1083
File and Directory Discovery
MalwareBlack Basta

Black Basta can enumerate specific files for encryption.

T1106
Native API
MalwareBlack Basta

Black Basta has the ability to use native APIs for numerous functions including discovery and defense evasion.

T1486
Data Encrypted for Impact
MalwareBlack Basta

Black Basta can encrypt files with the ChaCha20 cypher and using a multithreaded process to increase speed. Black Basta has also encrypted files while the victim system is in safe mode, appending `.basta` upon completion.

T1490
Inhibit System Recovery
MalwareBlack Basta

Black Basta can delete shadow copies using vssadmin.exe.

T1491.001
Internal Defacement
MalwareBlack Basta

Black Basta has set the desktop wallpaper on victims' machines to display a ransom note.

T1497
Virtualization/Sandbox Evasion
MalwareBlack Basta

Black Basta can make a random number of calls to the `kernel32.beep` function to hinder log analysis.

T1497.001
System Checks
MalwareBlack Basta

Black Basta can check system flags and libraries, process timing, and API's to detect code emulation or sandboxing.

T1553.002
Code Signing
MalwareBlack Basta

The Black Basta dropper has been digitally signed with a certificate issued by Akeo Consulting for legitimate executables used for creating bootable USB drives.

T1622
Debugger Evasion
MalwareBlack Basta

The Black Basta dropper can check system flags, CPU registers, CPU instructions, process timing, system libraries, and APIs to determine if a debugger is present.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.