Malware.View on attack.mitre.org
BlackByte Ransomware is uniquely associated with BlackByte operations. BlackByte Ransomware used a common key for infections, allowing for the creation of a universal decryptor. BlackByte Ransomware was replaced in BlackByte operations by BlackByte 2.0 Ransomware by 2023.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
BlackByte Ransomware enumerates the Registry, specifically the `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options` key. |
| T1021.002 SMB/Windows Admin Shares |
BlackByte Ransomware uses mapped shared folders to transfer ransomware payloads via SMB. |
| T1027.013 Encrypted/Encoded File |
BlackByte Ransomware is distributed as an encrypted payload. |
| T1046 Network Service Discovery |
BlackByte Ransomware identifies remote systems via active directory queries for hostnames prior to launching remote ransomware payloads. |
| T1053.005 Scheduled Task |
BlackByte Ransomware creates a schedule task to execute remotely deployed ransomware payloads. |
| T1059.007 JavaScript |
BlackByte Ransomware is distributed as a JavaScript launcher file. |
| T1082 System Information Discovery |
BlackByte Ransomware gathers victim system information to generate a unique victim identifier. |
| T1106 Native API |
BlackByte Ransomware uses the `SetThreadExecutionState` API to prevent the victim system from entering sleep. |
| T1112 Modify Registry |
BlackByte Ransomware modifies the victim Registry to prevent system recovery. |
| T1135 Network Share Discovery |
BlackByte Ransomware can identify network shares connected to the victim machine. |
| T1140 Deobfuscate/Decode Files or Information |
BlackByte Ransomware is distributed as an obfuscated JavaScript launcher file. |
| T1222.001 Windows Permissions |
BlackByte Ransomware uses the `mountvol.exe` command to mount volume names and leverages the Microsoft Discretionary Access Control List tool, `icacls.exe`, to grant the group to “Everyone” full access to the root of the drive. |
| T1480 Execution Guardrails |
BlackByte Ransomware creates a mutex value with a hard-coded name, and terminates if that mutex already exists on the victim system. BlackByte Ransomware checks the system language to see if it matches one of a list of hard-coded values; if a match is found, the malware will terminate. |
| T1486 Data Encrypted for Impact |
BlackByte Ransomware is ransomware using a shared key across victims for encryption. |
| T1490 Inhibit System Recovery |
BlackByte Ransomware deletes all volume shadow copies and restore points among other actions to inhibit system recovery following ransomware deployment. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.