US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupBlackByte | BlackByte used tools such as Arp to pull system network information and identify connected devices. |
| T1018 Remote System Discovery |
GroupBlackByte | BlackByte used tools such as Arp to identify remotely-connected devices. |
| T1036.008 Masquerade File Type |
GroupBlackByte | BlackByte masqueraded configuration files containing encryption keys as PNG files. |
| T1047 Windows Management Instrumentation |
GroupBlackByte | BlackByte used WMI to delete Volume Shadow Copies on victim machines. |
| T1053.005 Scheduled Task |
GroupBlackByte | BlackByte created scheduled tasks for payload execution. |
| T1059.001 PowerShell |
GroupBlackByte | BlackByte used encoded PowerShell commands during operations. BlackByte has used remote PowerShell commands in victim networks. |
| T1059.003 Windows Command Shell |
GroupBlackByte | BlackByte executed ransomware using the Windows command shell. |
| T1082 System Information Discovery |
GroupBlackByte | BlackByte used various system commands and tools to pull system information during operations. |
| T1140 Deobfuscate/Decode Files or Information |
GroupBlackByte | BlackByte has encoded commands in base64-encoded sections concatenated together in PowerShell. BlackByte uses PowerShell commands to disable Windows Defender. |
| T1190 Exploit Public-Facing Application |
GroupBlackByte | BlackByte exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments. |
| T1482 Domain Trust Discovery |
GroupBlackByte | BlackByte enumerated Active Directory information and trust relationships during operations. |
| T1486 Data Encrypted for Impact |
GroupBlackByte | BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim. |
| T1491.001 Internal Defacement |
GroupBlackByte | BlackByte left ransom notes in all directories where encryption takes place. |
| T1583.003 Virtual Private Server |
GroupBlackByte | BlackByte staged encryption keys on virtual private servers operated by the adversary. |
| T1685 Disable or Modify Tools |
GroupBlackByte | BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.