Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1055 Process Injection |
GroupBlackByte | BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions. BlackByte has injected ransomware into `svchost.exe` before encryption. |
| T1070.004 File Deletion |
GroupBlackByte | BlackByte deleted ransomware executables post-encryption. |
| T1082 System Information Discovery |
GroupBlackByte | BlackByte used various system commands and tools to pull system information during operations. |
| T1083 File and Directory Discovery |
MalwareExbyte | Exbyte enumerates all document files on an infected machine, then creates a summary of these items including filename and directory location prior to exfiltration to cloud hosting services. |
| T1190 Exploit Public-Facing Application |
GroupBlackByte | BlackByte exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments. |
| T1486 Data Encrypted for Impact |
GroupBlackByte | BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim. |
| T1490 Inhibit System Recovery |
GroupBlackByte | BlackByte resized and deleted volume shadow copy files to prevent system recovery after encryption. |
| T1497.001 System Checks |
MalwareExbyte | Exbyte performs various checks to determine if it is running in a sandboxed environment to prevent analysis. |
| T1518.001 Security Software Discovery |
MalwareExbyte | Exbyte checks for the presence of various security software products during execution. |
| T1543.003 Windows Service |
GroupBlackByte | BlackByte modified multiple services on victim machines to enable encryption operations. BlackByte has installed tools such as AnyDesk as a service on victim machines. |
| T1567 Exfiltration Over Web Service |
MalwareExbyte | Exbyte exfiltrates collected data to online file hosting sites such as `Mega.co.nz`. |
| T1569.002 Service Execution |
GroupBlackByte | BlackByte created malicious services for ransomware execution. |
| T1686 Disable or Modify System Firewall |
GroupBlackByte | BlackByte modified firewall rules on victim machines to enable remote system discovery. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.