Ransomware

Ransomware Group May Have Exploited Windows Vulnerability as Zero-Day

The Black Basta ransomware gang may have exploited the Windows privilege escalation flaw CVE-2024-26169 before it was patched.

The Black Basta ransomware gang may have exploited the Windows privilege escalation flaw CVE-2024-26169 before it was patched.

A known ransomware group may have exploited a recently patched Windows privilege escalation vulnerability before Microsoft released a fix, Symantec reported on Wednesday.

The flaw in question, tracked as CVE-2024-26169 and classified as ‘important’, has been described as a Windows error reporting service privilege escalation vulnerability that can allow an attacker to obtain System privileges. 

Microsoft’s advisory for CVE-2024-26169, which the tech giant released on March 12 when it patched the vulnerability, indicates that the company is not aware of malicious exploitation. In addition, the security bug has an exploitability assessment of ‘less likely’. 

However, Broadcom’s Symantec says it has found evidence suggesting that the Black Basta ransomware group (aka Cardinal, Storm-1811 and UNC4393) may have actually exploited this vulnerability as a zero-day.

While investigating a ransomware attack, Symantec researchers uncovered a tool that appears to exploit CVE-2024-26169 to start a shell with administrative privileges.

The researchers uncovered two versions of this tool: one with a compilation timestamp of February 27, 2024, and one with a timestamp of December 18, 2023.

Advertisement. Scroll to continue reading.

“Time stamp values in portable executables are modifiable, which means that a time stamp is not conclusive evidence that the attackers were using the exploit as a zero-day,” Symantec explained. “However, in this case there appears to be little motivation for the attackers to change the time stamp to an earlier date.”

Contacted by SecurityWeek, Microsoft stated, “This issue was addressed in March, and customers who apply the fix are protected. Our security software also includes detections to protect against the malware.”

A recent alert authored by multiple US government agencies showed that the Black Basta ransomware group hit more than 500 organizations around the world. 

A report published last year estimated that 90 Black Basta victims paid over $100 million to the cybercriminals. 

*updated with statement from Microsoft

Related: Black Basta, Bl00dy Ransomware Exploiting Recent ScreenConnect Flaws

Related: Windows Zero-Day Exploited in Attacks on Financial Market Traders

Related: Windows Zero-Day Exploited in Nokoyawa Ransomware Attacks

Related Content

Malware & Threats

The attackers deployed a new Go-based backdoor that uses Microsoft Teams servers for command-and-control.

Ransomware

Mackay Sugar was targeted in a cyberattack carried out by a threat group known as The Gentlemen.

Cybercrime

Oleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang.

Ransomware

The authentication bypass vulnerability allows attackers to establish VPN connections without a valid password.

Ransomware

Focusing on hacking law firms in the US, the ransomware group relies on fast flux to hide its C&C infrastructure.

Data Breaches

The non-bank lender discovered a ransomware attack nearly one year ago, but only recently completed its investigation.

Data Breaches

The Nitrogen ransomware group claims to have hacked the company’s systems, stealing 8TB of data, including confidential documents.

Data Breaches

The company took systems offline globally after hackers exfiltrated data and deployed file-encrypting ransomware.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version