ATT&CKReferencesFBI BlackByte 2022

FBI BlackByte 2022

US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupBlackByte

BlackByte used tools such as Arp to pull system network information and identify connected devices.

T1018
Remote System Discovery
GroupBlackByte

BlackByte used tools such as Arp to identify remotely-connected devices.

T1036.008
Masquerade File Type
GroupBlackByte

BlackByte masqueraded configuration files containing encryption keys as PNG files.

T1047
Windows Management Instrumentation
GroupBlackByte

BlackByte used WMI to delete Volume Shadow Copies on victim machines.

T1053.005
Scheduled Task
GroupBlackByte

BlackByte created scheduled tasks for payload execution.

T1059.001
PowerShell
GroupBlackByte

BlackByte used encoded PowerShell commands during operations. BlackByte has used remote PowerShell commands in victim networks.

T1059.003
Windows Command Shell
GroupBlackByte

BlackByte executed ransomware using the Windows command shell.

T1082
System Information Discovery
GroupBlackByte

BlackByte used various system commands and tools to pull system information during operations.

T1140
Deobfuscate/Decode Files or Information
GroupBlackByte

BlackByte has encoded commands in base64-encoded sections concatenated together in PowerShell. BlackByte uses PowerShell commands to disable Windows Defender.

T1190
Exploit Public-Facing Application
GroupBlackByte

BlackByte exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments.

T1482
Domain Trust Discovery
GroupBlackByte

BlackByte enumerated Active Directory information and trust relationships during operations.

T1486
Data Encrypted for Impact
GroupBlackByte

BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim.

T1491.001
Internal Defacement
GroupBlackByte

BlackByte left ransom notes in all directories where encryption takes place.

T1583.003
Virtual Private Server
GroupBlackByte

BlackByte staged encryption keys on virtual private servers operated by the adversary.

T1685
Disable or Modify Tools
GroupBlackByte

BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.