blackbasta attacks Black Bros. Co.

Incident Date:

May 10, 2022

World map

Overview

Title

blackbasta attacks Black Bros. Co.

Victim

Black Bros. Co.

Attacker

Blackbasta

Location

Mendota, USA

Illinois, USA

First Reported

May 10, 2022

Black Bros. Co. Targeted by Black Basta Ransomware Group

Company Overview

Black Bros. Co., a manufacturer with a rich history since 1882, stands as a leader in the production of high-quality machinery known for its durability and efficiency. The company has established a global presence through its commitment to innovative engineering, comprehensive onsite testing, and exceptional customer service.

Attack Details

The Black Basta ransomware group, a Russian-speaking entity active since early 2022, has recently targeted Black Bros. Co. This group is notorious for its double extortion tactics, which involve encrypting the victim's data and then threatening to release it publicly unless a ransom is paid. Their focus on English-speaking countries hints at a potential political motive behind their operations.

Vulnerabilities

Black Basta's method of gaining entry into an organization's network often begins with phishing emails containing malicious links. Upon gaining initial access, they utilize credentials bought from the Dark Web to navigate through the network, deploying ransomware through various tools and methods such as Qakbot, SystemBC, Mimikatz, CobaltStrike, and Rclone.

Impact

While Black Bros. Co. has not officially disclosed the incident, the Black Basta group has publicly claimed responsibility for the attack on their dark web leak site, detailing the breach and the data compromised.

Mitigation Strategies

To defend against ransomware attacks, organizations are advised to adopt advanced endpoint security solutions, enforce a robust backup strategy, and conduct regular training for employees on recognizing phishing attempts and adhering to security best practices.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.