Threat group.View on attack.mitre.org
BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.
| Technique | Procedure example |
|---|---|
| T1003 OS Credential Dumping |
BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems. |
| T1012 Query Registry |
BlackByte queried registry values to determine system language settings. |
| T1016 System Network Configuration Discovery |
BlackByte used tools such as Arp to pull system network information and identify connected devices. |
| T1018 Remote System Discovery |
BlackByte used tools such as Arp to identify remotely-connected devices. |
| T1021.001 Remote Desktop Protocol |
BlackByte has used RDP to access other hosts within victim networks. |
| T1021.002 SMB/Windows Admin Shares |
BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations. |
| T1036.008 Masquerade File Type |
BlackByte masqueraded configuration files containing encryption keys as PNG files. |
| T1041 Exfiltration Over C2 Channel |
BlackByte transmitted collected victim host information via HTTP POST to command and control infrastructure. |
| T1046 Network Service Discovery |
BlackByte has used tools such as NetScan to enumerate network services in victim environments. |
| T1047 Windows Management Instrumentation |
BlackByte used WMI to delete Volume Shadow Copies on victim machines. |
| T1053.005 Scheduled Task |
BlackByte created scheduled tasks for payload execution. |
| T1055 Process Injection |
BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions. BlackByte has injected ransomware into `svchost.exe` before encryption. |
| T1055.012 Process Hollowing |
BlackByte used process hollowing for defense evasion purposes. |
| T1059.001 PowerShell |
BlackByte used encoded PowerShell commands during operations. BlackByte has used remote PowerShell commands in victim networks. |
| T1059.003 Windows Command Shell |
BlackByte executed ransomware using the Windows command shell. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.