Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupBlackByte | BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems. |
| T1012 Query Registry |
GroupBlackByte | BlackByte queried registry values to determine system language settings. |
| T1018 Remote System Discovery |
GroupBlackByte | BlackByte used tools such as Arp to identify remotely-connected devices. |
| T1021.002 SMB/Windows Admin Shares |
GroupBlackByte | BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations. |
| T1053.005 Scheduled Task |
GroupBlackByte | BlackByte created scheduled tasks for payload execution. |
| T1055 Process Injection |
GroupBlackByte | BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions. BlackByte has injected ransomware into `svchost.exe` before encryption. |
| T1070.004 File Deletion |
GroupBlackByte | BlackByte deleted ransomware executables post-encryption. |
| T1112 Modify Registry |
GroupBlackByte | BlackByte performed Registry modifications to escalate privileges and disable security tools. |
| T1140 Deobfuscate/Decode Files or Information |
GroupBlackByte | BlackByte has encoded commands in base64-encoded sections concatenated together in PowerShell. BlackByte uses PowerShell commands to disable Windows Defender. |
| T1190 Exploit Public-Facing Application |
GroupBlackByte | BlackByte exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments. |
| T1219 Remote Access Tools |
GroupBlackByte | BlackByte has used tools such as AnyDesk in victim environments. |
| T1480 Execution Guardrails |
GroupBlackByte | BlackByte stopped execution if identified language settings on victim machines was Russian or one of several language associated with former Soviet republics. BlackByte has used ransomware variants requiring a key passed on the command line for the malware to execute. |
| T1486 Data Encrypted for Impact |
GroupBlackByte | BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim. |
| T1490 Inhibit System Recovery |
GroupBlackByte | BlackByte resized and deleted volume shadow copy files to prevent system recovery after encryption. |
| T1505.003 Web Shell |
GroupBlackByte | BlackByte has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange. |
| T1560 Archive Collected Data |
GroupBlackByte | BlackByte compressed data collected from victim environments prior to exfiltration. |
| T1567 Exfiltration Over Web Service |
GroupBlackByte | BlackByte has used services such as `anonymfiles.com` and `file.io` to exfiltrate victim data. |
| T1570 Lateral Tool Transfer |
GroupBlackByte | BlackByte transfered tools such as Cobalt Strike and the AnyDesk remote access tool during operations using SMB shares. |
| T1614.001 System Language Discovery |
GroupBlackByte | BlackByte identified system language settings to determine follow-on execution. |
| T1685 Disable or Modify Tools |
GroupBlackByte | BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations. |
| T1686 Disable or Modify System Firewall |
GroupBlackByte | BlackByte modified firewall rules on victim machines to enable remote system discovery. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.