Cyber Threat Report: 'Threat Actor Groups, Including Black Basta, are Exploiting Recent ScreenConnect Vulnerabilities'

Report Author Trend Micro
Publication Date 2024-02-27
Original Reporting Source
Related Intrusion Sets Bl00dy Ransomware Gang , Black Basta Ransomware Group
Identified CVEs CVE-2024-1709 , CVE-2024-1708

This blog post gives a detailed analysis of two critical vulnerabilities (CVE-2024-1708 and CVE-2024-1709) affecting ConnectWise ScreenConnect software, which allow attackers to gain unauthorized access and control over affected systems. The page explains the technical details of how the vulnerabilities have been exploited by groups in the wild. As well as Black Basta and Bl00dy activity, Trend Micro report observing exploitation of the vulnerabilities to drop the XWORM malware.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques

ATT&CK ID Title Associated Tactics
T1059.001 PowerShell Execution
T1041 Exfiltration Over C2 Channel Exfiltration
T1486 Data Encrypted for Impact Impact
T1105 Ingress Tool Transfer Command and Control
T1482 Domain Trust Discovery Discovery
T1219 Remote Access Software Command and Control
T1562 Impair Defenses Defense Evasion
T1087 Account Discovery Discovery
T1190 Exploit Public-Facing Application Initial Access