ATT&CKSoftwareBlackByte Ransomware

BlackByte Ransomware

S1180

Malware.View on attack.mitre.org

About this malware

BlackByte Ransomware is uniquely associated with BlackByte operations. BlackByte Ransomware used a common key for infections, allowing for the creation of a universal decryptor. BlackByte Ransomware was replaced in BlackByte operations by BlackByte 2.0 Ransomware by 2023.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1012
Query Registry

BlackByte Ransomware enumerates the Registry, specifically the `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options` key.

T1021.002
SMB/Windows Admin Shares

BlackByte Ransomware uses mapped shared folders to transfer ransomware payloads via SMB.

T1027.013
Encrypted/Encoded File

BlackByte Ransomware is distributed as an encrypted payload.

T1046
Network Service Discovery

BlackByte Ransomware identifies remote systems via active directory queries for hostnames prior to launching remote ransomware payloads.

T1053.005
Scheduled Task

BlackByte Ransomware creates a schedule task to execute remotely deployed ransomware payloads.

T1059.007
JavaScript

BlackByte Ransomware is distributed as a JavaScript launcher file.

T1082
System Information Discovery

BlackByte Ransomware gathers victim system information to generate a unique victim identifier.

T1106
Native API

BlackByte Ransomware uses the `SetThreadExecutionState` API to prevent the victim system from entering sleep.

T1112
Modify Registry

BlackByte Ransomware modifies the victim Registry to prevent system recovery.

T1135
Network Share Discovery

BlackByte Ransomware can identify network shares connected to the victim machine.

T1140
Deobfuscate/Decode Files or Information

BlackByte Ransomware is distributed as an obfuscated JavaScript launcher file.

T1222.001
Windows Permissions

BlackByte Ransomware uses the `mountvol.exe` command to mount volume names and leverages the Microsoft Discretionary Access Control List tool, `icacls.exe`, to grant the group to “Everyone” full access to the root of the drive.

T1480
Execution Guardrails

BlackByte Ransomware creates a mutex value with a hard-coded name, and terminates if that mutex already exists on the victim system. BlackByte Ransomware checks the system language to see if it matches one of a list of hard-coded values; if a match is found, the malware will terminate.

T1486
Data Encrypted for Impact

BlackByte Ransomware is ransomware using a shared key across victims for encryption.

T1490
Inhibit System Recovery

BlackByte Ransomware deletes all volume shadow copies and restore points among other actions to inhibit system recovery following ransomware deployment.

View all 21 procedure examples

Groups that use it1

Campaigns0

None recorded.

References4

  1. Cisco BlackByte 2024 Open source
    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.
  2. FBI BlackByte 2022 Open source
    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.
  3. Microsoft BlackByte 2023 Open source
    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.
  4. Trustwave BlackByte 2021 Open source
    Rodel Mendrez & Lloyd Macrohon. (2021, October 15). BlackByte Ransomware – Pt. 1 In-depth Analysis. Retrieved December 16, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.