Desk live·
ForensicPost
Ransomware/Identity/File 25-0220

Black Basta's Email-Bombing and Teams Impersonation Outlived the Group

Email bombing followed by a help-desk impersonation over Teams was Black Basta’s signature. After the group dissolved, the same sequence kept arriving — and got faster.

Constructed geometry · not a chart of case data
TargetEnterprise staff
ActorBlack Basta and successors
D. Kennedy13 min readConfidence: medium4 sources reviewed

The sequence is two moves. Flood a chosen employee’s mailbox with benign subscription traffic until it is unusable. Then message them on Teams as the help desk, offering to fix the problem you created.

The second move works because the first one is real. The employee has a genuine problem, and somebody who appears to be internal IT has arrived unprompted to solve it. The remote-access tool follows.

This Is The Identity Route, In Its Purest Form

This corpus has filed the identity-led intrusion repeatedly: the phone call replaced the exploit, and the service desk is the control. At 25-0724 the argument was that an unsophisticated technique which works is worse than a sophisticated one, because it is available to far more people.

Email bombing is not sophisticated. It is a subscription script. The sophistication is entirely in the timing of the second message.

The Speed Reported Is The Part Defenders Should Read Twice

Research covering later campaigns using the same sequence reports movement from first chat contact to execution of a malicious script in as little as twelve minutes, with senior staff preferentially targeted for their privilege.

Twelve minutes is shorter than most escalation paths. The corpus records very few incidents that end the way 25-0807 does — detected, isolated, contained — and every one of them turns on somebody noticing early. Here the attacker has arranged for there to be nothing to notice until the script runs.

And The Brand Was Never The Thing To Track

The group that pioneered this stopped existing in early 2025. Campaigns using the same sequence continued and were still being reported well afterwards, attributed to former affiliates rather than to a named successor.

The corpus filed at 25-0218 that what collapsed was a name, a leak site and some servers. This is the evidence for that claim: the asset that survived was a two-step social sequence any affiliate could carry to any operation.

What The Defence Actually Is

Not user training about the second message. The available control is structural: restrict who can initiate a Teams conversation from outside the tenant, and give employees one verified channel for help-desk contact that the help desk never deviates from.

This desk notes that the same recommendation appears in every write-up of this technique and has appeared since 2024, which tells you how much of the exposure is a configuration decision nobody owns.

How we reported this

Compiled from vendor research and reporting on the email-bombing and Teams help-desk impersonation sequence, listed below. Attribution of later campaigns to former Black Basta affiliates is a research assessment based on tradecraft resemblance, not an identification of individuals, and no arrest or charge is associated with it. The twelve-minute interval is reported by one research team from its own casework and has not been independently reproduced. Graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. ReliaQuest uncovers new Black Basta social engineering techniqueReliaQuest
  2. Threat spotlight: are former Black Basta affiliates automating executive targeting?ReliaQuest
  3. Black Basta’s playbook lives on as former affiliates launch fast-scale intrusion campaignCyberScoop
  4. Detecting Teams chat phishing attacksNVISO Labs
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary