Skip to content

2024-05-15 (disclosed) · US

Storm-1811 email bombing and fake IT support calls, 2024

Disclosed by the affected organisation.

From mid-April 2024 Microsoft observed Storm-1811, a group known to deploy Black Basta ransomware, flooding targets' inboxes by signing them up to many subscriptions, then phoning as IT support to fix the spam. Callers talked users into opening Quick Assist and entering a code, then installed tools leading to Black Basta. From late May the group also used Microsoft Teams accounts named as help desk. CISA and the FBI later added the email bombing and Teams tactics to their Black Basta advisory.

Timeline

  1. 2024-04-15 From mid-April 2024 Microsoft observes Storm-1811 misusing Quick Assist in social engineering attacks.
  2. 2024-05-10 CISA, the FBI and partners publish their joint advisory on Black Basta, which they say had affected over 500 organisations.
  3. 2024-05-15 Microsoft publishes its analysis of the Storm-1811 campaign.
  4. 2024-06-01 Microsoft's June 2024 update reports the group using Teams messages and calls from tenants named as help desk from the end of May.
  5. 2024-11-08 CISA updates the Black Basta advisory to describe email bombing followed by fake technical support over calls and Teams.

Lessons

Scam types: Email bombing followed by fake IT support · Techniques: Voice phishing (vishing)

Sources

  1. CISA and FBI: #StopRansomware: Black Basta (AA24-131A) (Law enforcement, primary, accessed 2026-09-24)
  2. Microsoft Threat Intelligence: Threat actors misusing Quick Assist in social engineering attacks leading to ransomware (Vendor research, secondary, accessed 2026-09-24)