ATT&CKReferencesPicus BlackByte 2022

Picus BlackByte 2022

Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupBlackByte

BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems.

T1012
Query Registry
GroupBlackByte

BlackByte queried registry values to determine system language settings.

T1018
Remote System Discovery
GroupBlackByte

BlackByte used tools such as Arp to identify remotely-connected devices.

T1021.002
SMB/Windows Admin Shares
GroupBlackByte

BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations.

T1053.005
Scheduled Task
GroupBlackByte

BlackByte created scheduled tasks for payload execution.

T1055
Process Injection
GroupBlackByte

BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions. BlackByte has injected ransomware into `svchost.exe` before encryption.

T1070.004
File Deletion
GroupBlackByte

BlackByte deleted ransomware executables post-encryption.

T1112
Modify Registry
GroupBlackByte

BlackByte performed Registry modifications to escalate privileges and disable security tools.

T1140
Deobfuscate/Decode Files or Information
GroupBlackByte

BlackByte has encoded commands in base64-encoded sections concatenated together in PowerShell. BlackByte uses PowerShell commands to disable Windows Defender.

T1190
Exploit Public-Facing Application
GroupBlackByte

BlackByte exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments.

T1219
Remote Access Tools
GroupBlackByte

BlackByte has used tools such as AnyDesk in victim environments.

T1480
Execution Guardrails
GroupBlackByte

BlackByte stopped execution if identified language settings on victim machines was Russian or one of several language associated with former Soviet republics. BlackByte has used ransomware variants requiring a key passed on the command line for the malware to execute.

T1486
Data Encrypted for Impact
GroupBlackByte

BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim.

T1490
Inhibit System Recovery
GroupBlackByte

BlackByte resized and deleted volume shadow copy files to prevent system recovery after encryption.

T1505.003
Web Shell
GroupBlackByte

BlackByte has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange.

T1560
Archive Collected Data
GroupBlackByte

BlackByte compressed data collected from victim environments prior to exfiltration.

T1567
Exfiltration Over Web Service
GroupBlackByte

BlackByte has used services such as `anonymfiles.com` and `file.io` to exfiltrate victim data.

T1570
Lateral Tool Transfer
GroupBlackByte

BlackByte transfered tools such as Cobalt Strike and the AnyDesk remote access tool during operations using SMB shares.

T1614.001
System Language Discovery
GroupBlackByte

BlackByte identified system language settings to determine follow-on execution.

T1685
Disable or Modify Tools
GroupBlackByte

BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.

T1686
Disable or Modify System Firewall
GroupBlackByte

BlackByte modified firewall rules on victim machines to enable remote system discovery.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.