Rodel Mendrez & Lloyd Macrohon. (2021, October 15). BlackByte Ransomware – Pt. 1 In-depth Analysis. Retrieved December 16, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareBlackByte Ransomware | BlackByte Ransomware enumerates the Registry, specifically the `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options` key. |
| T1021.002 SMB/Windows Admin Shares |
MalwareBlackByte Ransomware | BlackByte Ransomware uses mapped shared folders to transfer ransomware payloads via SMB. |
| T1027.013 Encrypted/Encoded File |
MalwareBlackByte Ransomware | BlackByte Ransomware is distributed as an encrypted payload. |
| T1046 Network Service Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware identifies remote systems via active directory queries for hostnames prior to launching remote ransomware payloads. |
| T1053.005 Scheduled Task |
MalwareBlackByte Ransomware | BlackByte Ransomware creates a schedule task to execute remotely deployed ransomware payloads. |
| T1059.007 JavaScript |
MalwareBlackByte Ransomware | BlackByte Ransomware is distributed as a JavaScript launcher file. |
| T1082 System Information Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware gathers victim system information to generate a unique victim identifier. |
| T1106 Native API |
MalwareBlackByte Ransomware | BlackByte Ransomware uses the `SetThreadExecutionState` API to prevent the victim system from entering sleep. |
| T1112 Modify Registry |
MalwareBlackByte Ransomware | BlackByte Ransomware modifies the victim Registry to prevent system recovery. |
| T1135 Network Share Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware can identify network shares connected to the victim machine. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBlackByte Ransomware | BlackByte Ransomware is distributed as an obfuscated JavaScript launcher file. |
| T1222.001 Windows Permissions |
MalwareBlackByte Ransomware | BlackByte Ransomware uses the `mountvol.exe` command to mount volume names and leverages the Microsoft Discretionary Access Control List tool, `icacls.exe`, to grant the group to “Everyone” full access to the root of the drive. |
| T1480 Execution Guardrails |
MalwareBlackByte Ransomware | BlackByte Ransomware creates a mutex value with a hard-coded name, and terminates if that mutex already exists on the victim system. BlackByte Ransomware checks the system language to see if it matches one of a list of hard-coded values; if a match is found, the malware will terminate. |
| T1486 Data Encrypted for Impact |
MalwareBlackByte Ransomware | BlackByte Ransomware is ransomware using a shared key across victims for encryption. |
| T1490 Inhibit System Recovery |
MalwareBlackByte Ransomware | BlackByte Ransomware deletes all volume shadow copies and restore points among other actions to inhibit system recovery following ransomware deployment. |
| T1497.001 System Checks |
MalwareBlackByte Ransomware | BlackByte Ransomware checks for files related to known sandboxes. |
| T1518.001 Security Software Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware looks for security software products prior to full execution. |
| T1570 Lateral Tool Transfer |
MalwareBlackByte Ransomware | BlackByte Ransomware spreads itself laterally by writing the JavaScript launcher file to mapped shared folders. |
| T1614.001 System Language Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware identifies the language on the victim system. |
| T1685 Disable or Modify Tools |
MalwareBlackByte Ransomware | BlackByte Ransomware adds .JS and .EXE extensions to the Microsoft Defender exclusion list. BlackByte Ransomware terminates and removes the Raccine anti-ransomware utility. |
| T1689 Downgrade Attack |
MalwareBlackByte Ransomware | BlackByte Ransomware enables SMBv1 during execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.