James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
GroupBlackByte | BlackByte has used RDP to access other hosts within victim networks. |
| T1021.002 SMB/Windows Admin Shares |
GroupBlackByte | BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations. |
| T1068 Exploitation for Privilege Escalation |
GroupBlackByte | BlackByte has exploited CVE-2024-37085 in VMWare ESXi software for authentication bypass and subsequent privilege escalation. |
| T1070.004 File Deletion |
GroupBlackByte | BlackByte deleted ransomware executables post-encryption. |
| T1078 Valid Accounts |
GroupBlackByte | BlackByte has gained access to victim environments through legitimate VPN credentials. |
| T1078.002 Domain Accounts |
GroupBlackByte | BlackByte captured credentials for or impersonated domain administration users. |
| T1112 Modify Registry |
GroupBlackByte | BlackByte performed Registry modifications to escalate privileges and disable security tools. |
| T1135 Network Share Discovery |
GroupBlackByte | BlackByte enumerated network shares on victim devices. |
| T1136.002 Domain Account |
GroupBlackByte | BlackByte created privileged domain accounts during intrusions. |
| T1480 Execution Guardrails |
GroupBlackByte | BlackByte stopped execution if identified language settings on victim machines was Russian or one of several language associated with former Soviet republics. BlackByte has used ransomware variants requiring a key passed on the command line for the malware to execute. |
| T1486 Data Encrypted for Impact |
GroupBlackByte | BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim. |
| T1569.002 Service Execution |
GroupBlackByte | BlackByte created malicious services for ransomware execution. |
| T1685 Disable or Modify Tools |
GroupBlackByte | BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.