ATT&CKGroupsBlackByte

BlackByte

G1043

Threat group.View on attack.mitre.org

About this group

BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.

Techniques used48

Procedure examples48

TechniqueProcedure example
T1003
OS Credential Dumping

BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems.

T1012
Query Registry

BlackByte queried registry values to determine system language settings.

T1016
System Network Configuration Discovery

BlackByte used tools such as Arp to pull system network information and identify connected devices.

T1018
Remote System Discovery

BlackByte used tools such as Arp to identify remotely-connected devices.

T1021.001
Remote Desktop Protocol

BlackByte has used RDP to access other hosts within victim networks.

T1021.002
SMB/Windows Admin Shares

BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations.

T1036.008
Masquerade File Type

BlackByte masqueraded configuration files containing encryption keys as PNG files.

T1041
Exfiltration Over C2 Channel

BlackByte transmitted collected victim host information via HTTP POST to command and control infrastructure.

T1046
Network Service Discovery

BlackByte has used tools such as NetScan to enumerate network services in victim environments.

T1047
Windows Management Instrumentation

BlackByte used WMI to delete Volume Shadow Copies on victim machines.

T1053.005
Scheduled Task

BlackByte created scheduled tasks for payload execution.

T1055
Process Injection

BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions. BlackByte has injected ransomware into `svchost.exe` before encryption.

T1055.012
Process Hollowing

BlackByte used process hollowing for defense evasion purposes.

T1059.001
PowerShell

BlackByte used encoded PowerShell commands during operations. BlackByte has used remote PowerShell commands in victim networks.

T1059.003
Windows Command Shell

BlackByte executed ransomware using the Windows command shell.

View all 48 procedure examples

Software8

Campaigns0

None recorded.

References5

  1. Cisco BlackByte 2024 Open source
    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.
  2. FBI BlackByte 2022 Open source
    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.
  3. Microsoft BlackByte 2023 Open source
    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.
  4. Picus BlackByte 2022 Open source
    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.
  5. Symantec BlackByte 2022 Open source
    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.