ATT&CKReferencesCisco BlackByte 2024

Cisco BlackByte 2024

James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
GroupBlackByte

BlackByte has used RDP to access other hosts within victim networks.

T1021.002
SMB/Windows Admin Shares
GroupBlackByte

BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations.

T1068
Exploitation for Privilege Escalation
GroupBlackByte

BlackByte has exploited CVE-2024-37085 in VMWare ESXi software for authentication bypass and subsequent privilege escalation.

T1070.004
File Deletion
GroupBlackByte

BlackByte deleted ransomware executables post-encryption.

T1078
Valid Accounts
GroupBlackByte

BlackByte has gained access to victim environments through legitimate VPN credentials.

T1078.002
Domain Accounts
GroupBlackByte

BlackByte captured credentials for or impersonated domain administration users.

T1112
Modify Registry
GroupBlackByte

BlackByte performed Registry modifications to escalate privileges and disable security tools.

T1135
Network Share Discovery
GroupBlackByte

BlackByte enumerated network shares on victim devices.

T1136.002
Domain Account
GroupBlackByte

BlackByte created privileged domain accounts during intrusions.

T1480
Execution Guardrails
GroupBlackByte

BlackByte stopped execution if identified language settings on victim machines was Russian or one of several language associated with former Soviet republics. BlackByte has used ransomware variants requiring a key passed on the command line for the malware to execute.

T1486
Data Encrypted for Impact
GroupBlackByte

BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim.

T1569.002
Service Execution
GroupBlackByte

BlackByte created malicious services for ransomware execution.

T1685
Disable or Modify Tools
GroupBlackByte

BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.