Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupBlackByte | BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems. |
| T1016 System Network Configuration Discovery |
GroupBlackByte | BlackByte used tools such as Arp to pull system network information and identify connected devices. |
| T1021.001 Remote Desktop Protocol |
GroupBlackByte | BlackByte has used RDP to access other hosts within victim networks. |
| T1021.002 SMB/Windows Admin Shares |
GroupBlackByte | BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations. |
| T1041 Exfiltration Over C2 Channel |
GroupBlackByte | BlackByte transmitted collected victim host information via HTTP POST to command and control infrastructure. |
| T1046 Network Service Discovery |
GroupBlackByte | BlackByte has used tools such as NetScan to enumerate network services in victim environments. |
| T1055 Process Injection |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware injects into a newly-created `svchost.exe` process prior to device encryption. |
| T1055.012 Process Hollowing |
GroupBlackByte | BlackByte used process hollowing for defense evasion purposes. |
| T1059.001 PowerShell |
GroupBlackByte | BlackByte used encoded PowerShell commands during operations. BlackByte has used remote PowerShell commands in victim networks. |
| T1068 Exploitation for Privilege Escalation |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware exploits a vulnerability in the RTCore64.sys driver (CVE-2019-16098) to enable privilege escalation and defense evasion when run as a service. |
| T1069.001 Local Groups |
MalwareExbyte | Exbyte checks whether the process is running with privileged local access during execution. |
| T1070.004 File Deletion |
GroupBlackByte | BlackByte deleted ransomware executables post-encryption. |
| T1070.004 File Deletion |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware deletes itself following device encryption. |
| T1070.004 File Deletion |
MalwareExbyte | Exbyte will self-delete if a hard-coded configuration file is not found. |
| T1070.006 Timestomp |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware can timestomp files for defense evasion and anti-forensics purposes. |
| T1071.001 Web Protocols |
GroupBlackByte | BlackByte collected victim device information then transmitted this via HTTP POST to command and control infrastructure. |
| T1078.002 Domain Accounts |
GroupBlackByte | BlackByte captured credentials for or impersonated domain administration users. |
| T1082 System Information Discovery |
GroupBlackByte | BlackByte used various system commands and tools to pull system information during operations. |
| T1087.002 Domain Account |
GroupBlackByte | BlackByte has used tools such as AdFind to identify and enumerate domain accounts. |
| T1105 Ingress Tool Transfer |
GroupBlackByte | BlackByte has transferred tools such as Cobalt Strike to victim environments from file sharing and hosting websites. |
| T1106 Native API |
MalwareExbyte | Exbyte calls `ShellExecuteW` with the `IpOperation` parameter `RunAs` to launch `explorer.exe` with elevated privileges. |
| T1112 Modify Registry |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware modifies the victim Registry to allow for elevated execution. |
| T1134.003 Make and Impersonate Token |
GroupBlackByte | BlackByte constructed a valid authentication token following Microsoft Exchange exploitation to allow for follow-on privileged command execution. |
| T1135 Network Share Discovery |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware can identify network shares connected to the victim machine. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareExbyte | Exbyte decodes and decrypts data stored in the configuration file with a key provided on the command line during execution. |
| T1190 Exploit Public-Facing Application |
GroupBlackByte | BlackByte exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments. |
| T1219 Remote Access Tools |
GroupBlackByte | BlackByte has used tools such as AnyDesk in victim environments. |
| T1480 Execution Guardrails |
MalwareExbyte | Exbyte checks for the presence of a configuration file before completing execution. |
| T1482 Domain Trust Discovery |
GroupBlackByte | BlackByte enumerated Active Directory information and trust relationships during operations. |
| T1486 Data Encrypted for Impact |
GroupBlackByte | BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim. |
| T1486 Data Encrypted for Impact |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware is a ransomware variant associated with BlackByte operations. |
| T1489 Service Stop |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware can terminate running services. |
| T1490 Inhibit System Recovery |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware modifies volume shadow copies during execution in a way that destroys them on the victim machine. |
| T1505.003 Web Shell |
GroupBlackByte | BlackByte has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange. |
| T1518.001 Security Software Discovery |
GroupBlackByte | BlackByte enumerated installed security products during operations. |
| T1543.003 Windows Service |
GroupBlackByte | BlackByte modified multiple services on victim machines to enable encryption operations. BlackByte has installed tools such as AnyDesk as a service on victim machines. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupBlackByte | BlackByte has used Registry Run keys for persistence. |
| T1567 Exfiltration Over Web Service |
MalwareExbyte | Exbyte exfiltrates collected data to online file hosting sites such as `Mega.co.nz`. |
| T1569.002 Service Execution |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware executes as a service when deployed. |
| T1608.001 Upload Malware |
GroupBlackByte | BlackByte has staged tools such as Cobalt Strike at public file sharing and hosting sites. |
| T1686.003 Windows Host Firewall |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware modifies the Windows firewall during execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.