#BackConnect
This is the guy Coristine worked for.

The PasteBin this reporting came from also listed Webb's address as being in Hamilton, OH.

That's just a short commute from Middletown, OH, where Webb was interning before moving on to BackConnect, then Path and CoinPayments.

www.cbsnews.com/news/lulzsec...
February 7, 2025 at 9:12 PM
Extracting VNC screenshots and keylog data from #Latrodectus 🕷️ BackConnect
netresec.com?b=25Cfd08
Latrodectus BackConnect
I recently learned that the great folks from The DFIR Report have done a writeup covering the Latrodectus backdoor. Their report is titled From a Single Click: How Lunar Spider Enabled a Near Two-Mont...
netresec.com
December 10, 2025 at 1:22 PM
Downloaded a fresh pcap from any.​run to verify that #CapLoader identifies this traffic as ​Socks5Systemz backconnect ✅
app.any.run/tasks/c1b2dc...
December 5, 2024 at 3:35 PM
New research has uncovered further links between the Black Basta and Cactus ransomware gangs, with members of both groups utilizing the same social engineering attacks and the BackConnect proxy malware for post-exploitation access to corporate networks.
Microsoft Teams tactics, malware connect Black Basta, Cactus ransomware
New research has uncovered further links between the Black Basta and Cactus ransomware gangs, with members of both groups utilizing the same social engineering attacks and the BackConnect proxy malware for post-exploitation access to corporate networks.
www.bleepingcomputer.com
March 4, 2025 at 10:47 PM
New research has uncovered further links between the #BlackBasta and #Cactus ransomware gangs, with members of both groups utilizing the same social engineering attacks and the #BackConnect proxy malware for post-exploitation access to corporate networks. #ransomwaregroup
Microsoft Teams tactics, malware connect Black Basta, Cactus ransomware
New research has uncovered further links between the Black Basta and Cactus ransomware gangs, with members of both groups utilizing the same social engineering attacks and the BackConnect proxy malwar...
www.bleepingcomputer.com
March 5, 2025 at 8:24 PM
This infostealer is frequently promoted on underground forums. The affiliates are offered an administration panel application, a backconnect tool for real-time control of bots, and a proxy server application that relays the communication between the bots and the C&C server. 5/6
May 22, 2025 at 8:06 PM
Black Basta and Cactus ransomware groups show strong links: both use BackConnect, similar social engineering (Microsoft Teams), and tactics. This suggests shared members or a rebranding, with Cactus potentially absorbing Black Basta's remnants.#RansomwareConnections
March 4, 2025 at 11:03 PM
New BackConnect malware, linked to QakBot & STAC5777 (Black Basta ties), acts as a standalone backdoor. It enhances remote access and data theft, showcasing a connected cybercrime ecosystem.#BackConnectMalware
January 23, 2025 at 11:03 AM
Novo malware BackConnect usa Microsoft Teams para roubar dados sigilosos
Novo malware BackConnect usa Microsoft Teams para roubar dados sigilosos
canaltech.com.br
March 5, 2025 at 1:56 PM
The DFIR Report presents an intrusion that began with a Lunar Spider linked JavaScript file disguised as a tax form leading to multiple pieces of malware being deployed (Latrodectus, Brute Ratel C4, Cobalt Strike, BackConnect, and a custom .NET backdoor) thedfirreport.com/2025/09/29/f...
October 1, 2025 at 7:52 AM
QakBot-Linked BC Malware Adds Enhanced DNS Tunneling and Remote Access Features

Cybersecurity researchers have disclosed details of a new BackConnect (BC) malware that has been developed by threat actors linked to the infamous QakBot loader. "BackConnect is a common feature or module utilized by…
QakBot-Linked BC Malware Adds Enhanced DNS Tunneling and Remote Access Features
Cybersecurity researchers have disclosed details of a new BackConnect (BC) malware that has been developed by threat actors linked to the infamous QakBot loader. "BackConnect is a common feature or module utilized by threat actors to maintain persistence and perform tasks," Walmart's Cyber Intelligence team told The Hacker News. "The BackConnect(s) in use were 'DarkVNC' alongside the IcedID
shoebhakim.com
January 23, 2025 at 10:26 AM
Oh wait fuck it was the Backconnect guy who hijacked vdos and then 1.3.3.7 for the money team kids
December 24, 2024 at 1:56 PM
ROG Crosshair X870E Hero BTF: Asus listet High-End-Mainboard für AM5 mit Backconnect #asus #rog #asusbtf #x870e
ROG Crosshair X870E Hero BTF: Asus listet High-End-Mainboard für AM5 mit Backconnect
Das BTF-Ökosystem wächst. Mit dem ROG Crosshair X870E Hero BTF listet Asus nun sein zweites AM5-Mainboard mit versteckten Anschlüssen.
www.computerbase.de
August 14, 2025 at 10:28 AM
Black Basta and CACTUS ransomware: shared BackConnect module signals affiliate transition

details here: buff.ly/GvxZBqE
March 5, 2025 at 11:56 AM
IcedID has updated their communications module, BackConnect, to augment post-compromise behaviors like exfiltrating data covertly. Focusing on bank fraud and ransomware delivery, IcedID started off as a banking trojan in 2017. They added a VNC component.
IcedID Malware Adapts and Expands Threat with Updated BackConnect Module
Latest findings reveal that the IcedID malware is getting even more dangerous with updates to its BackConnect module for post-compromise activity.
thehackernews.com
July 28, 2023 at 9:08 PM
Researchers Link CACTUS Ransomware Tactics to Former Black Basta Affiliates
Researchers Link CACTUS Ransomware Tactics to Former Black Basta Affiliates
Black Basta and CACTUS ransomware groups share the BackConnect module, suggesting a shift in affiliations.
thehackernews.com
March 4, 2025 at 5:27 PM
With all the modules being added to stealers, we are coming full circle in cybercrime evolution and maybe back to centralized botnets. Enter GhostSocks which has teamed up with LummaC2 and possibly other stealers. Another great blog from SpyCloud Labs explains this here: spycloud.com/blog/on-the-...
On the Hunt for Ghost(Socks)
SpyCloud Labs uncovers how LummaC2 uses GhostSocks to enable stealthy backconnect proxy access, helping attackers bypass controls and refresh tokens.
spycloud.com
March 26, 2025 at 12:10 AM
#Socks5Systemz backconnect traffic now uses TCP port 2024 (previously 2023)
infosec.exchange/@abuse_ch@io...
December 5, 2024 at 3:35 PM
Notícia da SecurityOnline

"Black Basta and Cactus Ransomware Groups Weaponize BackConnect Malware" #bolhasec
Black Basta and Cactus Ransomware Groups Weaponize BackConnect Malware
Learn about QBACKCONNECT and its role in the tactics of Black Basta and Cactus ransomware groups for cyber threats.
securityonline.info
May 27, 2025 at 2:30 PM
Notícia da BleepingComputer

"Microsoft Teams tactics, malware connect Black Basta, Cactus ransomware" #bolhasec
Microsoft Teams tactics, malware connect Black Basta, Cactus ransomware
New research has uncovered further links between the Black Basta and Cactus ransomware gangs, with members of both groups utilizing the same social engineering attacks and the BackConnect proxy malwar...
www.bleepingcomputer.com
May 24, 2025 at 11:30 PM