Back to Resources

SentinelOne Vs. Black Basta – Prevention and Detection

Watch how SentinelOne prevents and detects Black Basta Ransomware. Black Basta is a relatively new, multi-pronged extortion group, meaning they exfiltrates all desired data prior to encrypting devices. Victims are then extorted into paying the ransom in order to A) prevent leakage and B) decrypt their data. The group hosts a TOR-based blog where they publish victim data.

Upon infection, victims are instructed to visit Black Basta’s ‘support’ portal via TOR. Infected hosts experience altered wallpaper, and very rapid encryption of files. Black Basta will attempt to inhibit system recovery by removing Volume Shadow Copies (vssadmin).

#cybersecurity #blackbasta #ransomware

지금 읽기

세계에서 가장 앞선 사이버 보안 플랫폼 경험하기

지능적인 자율형 사이버 보안 플랫폼이 현재와 미래의 조직을 어떻게 보호할 수 있는지 알아보세요.