ATT&CKReferencesSymantec BlackByte 2022

Symantec BlackByte 2022

Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1055
Process Injection
GroupBlackByte

BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions. BlackByte has injected ransomware into `svchost.exe` before encryption.

T1070.004
File Deletion
GroupBlackByte

BlackByte deleted ransomware executables post-encryption.

T1082
System Information Discovery
GroupBlackByte

BlackByte used various system commands and tools to pull system information during operations.

T1083
File and Directory Discovery
MalwareExbyte

Exbyte enumerates all document files on an infected machine, then creates a summary of these items including filename and directory location prior to exfiltration to cloud hosting services.

T1190
Exploit Public-Facing Application
GroupBlackByte

BlackByte exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments.

T1486
Data Encrypted for Impact
GroupBlackByte

BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim.

T1490
Inhibit System Recovery
GroupBlackByte

BlackByte resized and deleted volume shadow copy files to prevent system recovery after encryption.

T1497.001
System Checks
MalwareExbyte

Exbyte performs various checks to determine if it is running in a sandboxed environment to prevent analysis.

T1518.001
Security Software Discovery
MalwareExbyte

Exbyte checks for the presence of various security software products during execution.

T1543.003
Windows Service
GroupBlackByte

BlackByte modified multiple services on victim machines to enable encryption operations. BlackByte has installed tools such as AnyDesk as a service on victim machines.

T1567
Exfiltration Over Web Service
MalwareExbyte

Exbyte exfiltrates collected data to online file hosting sites such as `Mega.co.nz`.

T1569.002
Service Execution
GroupBlackByte

BlackByte created malicious services for ransomware execution.

T1686
Disable or Modify System Firewall
GroupBlackByte

BlackByte modified firewall rules on victim machines to enable remote system discovery.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.