Ex-Black Basta Hackers Weaponize Microsoft Teams and Python to Breach Corporate Networks


# Black Basta Affiliates Evolve Tactics with Python Scripts and Teams Phishing

Former members of the Black Basta ransomware group are adapting their attack methods, combining traditional email bombing with Microsoft Teams phishing and new Python script execution techniques to infiltrate corporate networks.

## New Attack Methods Emerge

Security firm ReliaQuest reports that attackers now use cURL requests to fetch and deploy malicious payloads through Python scripts, marking an evolution in their tactics. Despite Black Basta’s decline following the February leak of internal chat logs, its former affiliates continue operations with refined techniques.

Between February and May 2025, half of observed Teams phishing attacks originated from onmicrosoft.com domains, while 42% came from compromised legitimate domains—making detection significantly harder. Attackers impersonate help desk personnel to target finance, insurance, and construction sectors.

## Affiliate Migration Patterns

The shutdown of Black Basta’s data-leak site suggests former members have either joined existing ransomware-as-a-service (RaaS) groups or formed new ones. Evidence points to possible migration to:

– **CACTUS RaaS**: Leaked chats reveal a $500-600K payment reference to CACTUS
– **BlackLock**: Potentially collaborating with the DragonForce ransomware cartel
– **BlackSuit**: Adopting similar social engineering strategies

## Technical Evolution

The attack chain now includes:
1. Initial access via Teams phishing
2. Remote desktop sessions through Quick Assist and AnyDesk
3. Python script deployment for command-and-control communications
4. Updated Java-based RAT variants that abuse Google Drive and Microsoft OneDrive for proxying commands

The malware’s enhanced capabilities include SOCKS5 proxy tunneling, credential theft, fake Windows login prompts, and in-memory execution of downloaded Java classes.

## Broader Ransomware Landscape

Several significant developments are reshaping the ransomware ecosystem:

**Scattered Spider** targets managed service providers using a “one-to-many” approach, exploiting compromised Tata Consultancy Services accounts and SimpleHelp vulnerabilities. The group uses Evilginx phishing kits to bypass multi-factor authentication.

**Qilin ransomware** launched coordinated attacks exploiting Fortinet FortiGate vulnerabilities (CVE-2024-21762, CVE-2024-55591) between May and June 2025.

**Play ransomware** has compromised approximately 900 entities since mid-2022, recently targeting U.S. organizations through SimpleHelp vulnerabilities.

**VanHelsing ransomware** experienced internal collapse, with administrators leaking the group’s entire source code, including TOR keys, admin panels, and databases on the RAMP forum.

**Interlock ransomware** deployed NodeSnake, a JavaScript remote access trojan, against UK government and educational institutions through phishing campaigns.

## Security Implications

These evolving tactics demonstrate ransomware groups’ adaptability and persistence. The shift toward Python scripts and cloud service abuse represents a sophisticated evolution in attack methodologies. Organizations must enhance their security posture against Teams-based phishing and monitor for unusual Python script executions and cloud service connections.

The fragmentation and regrouping of ransomware affiliates create a dynamic threat landscape where tactics, techniques, and procedures rapidly spread across different groups, making attribution and defense increasingly challenging.

Share This Article