ATT&CKReferencesMicrosoft BlackByte 2023

Microsoft BlackByte 2023

Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples41

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupBlackByte

BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems.

T1016
System Network Configuration Discovery
GroupBlackByte

BlackByte used tools such as Arp to pull system network information and identify connected devices.

T1021.001
Remote Desktop Protocol
GroupBlackByte

BlackByte has used RDP to access other hosts within victim networks.

T1021.002
SMB/Windows Admin Shares
GroupBlackByte

BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations.

T1041
Exfiltration Over C2 Channel
GroupBlackByte

BlackByte transmitted collected victim host information via HTTP POST to command and control infrastructure.

T1046
Network Service Discovery
GroupBlackByte

BlackByte has used tools such as NetScan to enumerate network services in victim environments.

T1055
Process Injection
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware injects into a newly-created `svchost.exe` process prior to device encryption.

T1055.012
Process Hollowing
GroupBlackByte

BlackByte used process hollowing for defense evasion purposes.

T1059.001
PowerShell
GroupBlackByte

BlackByte used encoded PowerShell commands during operations. BlackByte has used remote PowerShell commands in victim networks.

T1068
Exploitation for Privilege Escalation
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware exploits a vulnerability in the RTCore64.sys driver (CVE-2019-16098) to enable privilege escalation and defense evasion when run as a service.

T1069.001
Local Groups
MalwareExbyte

Exbyte checks whether the process is running with privileged local access during execution.

T1070.004
File Deletion
GroupBlackByte

BlackByte deleted ransomware executables post-encryption.

T1070.004
File Deletion
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware deletes itself following device encryption.

T1070.004
File Deletion
MalwareExbyte

Exbyte will self-delete if a hard-coded configuration file is not found.

T1070.006
Timestomp
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware can timestomp files for defense evasion and anti-forensics purposes.

T1071.001
Web Protocols
GroupBlackByte

BlackByte collected victim device information then transmitted this via HTTP POST to command and control infrastructure.

T1078.002
Domain Accounts
GroupBlackByte

BlackByte captured credentials for or impersonated domain administration users.

T1082
System Information Discovery
GroupBlackByte

BlackByte used various system commands and tools to pull system information during operations.

T1087.002
Domain Account
GroupBlackByte

BlackByte has used tools such as AdFind to identify and enumerate domain accounts.

T1105
Ingress Tool Transfer
GroupBlackByte

BlackByte has transferred tools such as Cobalt Strike to victim environments from file sharing and hosting websites.

T1106
Native API
MalwareExbyte

Exbyte calls `ShellExecuteW` with the `IpOperation` parameter `RunAs` to launch `explorer.exe` with elevated privileges.

T1112
Modify Registry
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware modifies the victim Registry to allow for elevated execution.

T1134.003
Make and Impersonate Token
GroupBlackByte

BlackByte constructed a valid authentication token following Microsoft Exchange exploitation to allow for follow-on privileged command execution.

T1135
Network Share Discovery
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware can identify network shares connected to the victim machine.

T1140
Deobfuscate/Decode Files or Information
MalwareExbyte

Exbyte decodes and decrypts data stored in the configuration file with a key provided on the command line during execution.

T1190
Exploit Public-Facing Application
GroupBlackByte

BlackByte exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments.

T1219
Remote Access Tools
GroupBlackByte

BlackByte has used tools such as AnyDesk in victim environments.

T1480
Execution Guardrails
MalwareExbyte

Exbyte checks for the presence of a configuration file before completing execution.

T1482
Domain Trust Discovery
GroupBlackByte

BlackByte enumerated Active Directory information and trust relationships during operations.

T1486
Data Encrypted for Impact
GroupBlackByte

BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim.

T1486
Data Encrypted for Impact
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware is a ransomware variant associated with BlackByte operations.

T1489
Service Stop
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware can terminate running services.

T1490
Inhibit System Recovery
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware modifies volume shadow copies during execution in a way that destroys them on the victim machine.

T1505.003
Web Shell
GroupBlackByte

BlackByte has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange.

T1518.001
Security Software Discovery
GroupBlackByte

BlackByte enumerated installed security products during operations.

T1543.003
Windows Service
GroupBlackByte

BlackByte modified multiple services on victim machines to enable encryption operations. BlackByte has installed tools such as AnyDesk as a service on victim machines.

T1547.001
Registry Run Keys / Startup Folder
GroupBlackByte

BlackByte has used Registry Run keys for persistence.

T1567
Exfiltration Over Web Service
MalwareExbyte

Exbyte exfiltrates collected data to online file hosting sites such as `Mega.co.nz`.

T1569.002
Service Execution
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware executes as a service when deployed.

T1608.001
Upload Malware
GroupBlackByte

BlackByte has staged tools such as Cobalt Strike at public file sharing and hosting sites.

T1686.003
Windows Host Firewall
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware modifies the Windows firewall during execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.