Blackbyte
InactiveBlackByte · Hecamede also known as
Total victims
0
This month
0
Active
—
DayBreach AI intelligence
How it operates
Ransomware. Uses dropper written in JavaScript to deploy a .NET payload.
MITRE ATT&CK profile
G1043
[BlackByte](https://attack.mitre.org/groups/G1043) is a ransomware threat actor operating since at least 2021. [BlackByte](https://attack.mitre.org/groups/G1043) is associated with several versions of ransomware also labeled [BlackByte Ransomware](https://attack.mitre.org/software/S1180). [BlackByte](https://attack.mitre.org/groups/G1043) ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as [BlackByte 2.0 Ransomware](https://attack.mitre.org/software/S1181) use more robust encryption mechanisms. [BlackByte](https://attack.mitre.org/groups/G1043) is notable for operations targeting critical infrastructure entities among other targets across North America.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)
Techniques it uses
System Information Discovery
T1016System Network Configuration Discovery
T1046Network Service Discovery
T1105Ingress Tool Transfer
T1482Domain Trust Discovery
T1686Disable or Modify System Firewall
T1036.008Masquerade File Type
T1053.005Scheduled Task
T1134.003Make and Impersonate Token
T1070.004File Deletion
T1543.003Windows Service
T1021.001Remote Desktop Protocol
T1685Disable or Modify Tools
T1614.001System Language Discovery
T1560Archive Collected Data
T1059.003Windows Command Shell
Associated malware and tools