Malware.View on attack.mitre.org
BlackByte 2.0 Ransomware is a replacement for BlackByte Ransomware. Unlike BlackByte Ransomware, BlackByte 2.0 Ransomware does not have a common key for victim decryption. BlackByte 2.0 Ransomware remains uniquely associated with BlackByte operations.
| Technique | Procedure example |
|---|---|
| T1055 Process Injection |
BlackByte 2.0 Ransomware injects into a newly-created `svchost.exe` process prior to device encryption. |
| T1068 Exploitation for Privilege Escalation |
BlackByte 2.0 Ransomware exploits a vulnerability in the RTCore64.sys driver (CVE-2019-16098) to enable privilege escalation and defense evasion when run as a service. |
| T1070.004 File Deletion |
BlackByte 2.0 Ransomware deletes itself following device encryption. |
| T1070.006 Timestomp |
BlackByte 2.0 Ransomware can timestomp files for defense evasion and anti-forensics purposes. |
| T1112 Modify Registry |
BlackByte 2.0 Ransomware modifies the victim Registry to allow for elevated execution. |
| T1135 Network Share Discovery |
BlackByte 2.0 Ransomware can identify network shares connected to the victim machine. |
| T1486 Data Encrypted for Impact |
BlackByte 2.0 Ransomware is a ransomware variant associated with BlackByte operations. |
| T1489 Service Stop |
BlackByte 2.0 Ransomware can terminate running services. |
| T1490 Inhibit System Recovery |
BlackByte 2.0 Ransomware modifies volume shadow copies during execution in a way that destroys them on the victim machine. |
| T1569.002 Service Execution |
BlackByte 2.0 Ransomware executes as a service when deployed. |
| T1686.003 Windows Host Firewall |
BlackByte 2.0 Ransomware modifies the Windows firewall during execution. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.