Çeteler
B

Blackbyte

Pasif

BlackByte · Hecamede olarak da bilinir

Toplam kurban

0

Bu ay

0

Aktif

—

DayBreach AI istihbaratı

Çete profili ve güncel haberler · web kaynaklı

Yükleniyor…

Nasıl çalışıyor

Ransomware. Uses dropper written in JavaScript to deploy a .NET payload.

T1082 · System Information DiscoveryT1016 · System Network Configuration DiscoveryT1046 · Network Service DiscoveryT1105 · Ingress Tool TransferT1482 · Domain Trust DiscoveryT1686 · Disable or Modify System FirewallT1036.008 · Masquerade File TypeT1053.005 · Scheduled TaskT1134.003 · Make and Impersonate TokenT1070.004 · File DeletionT1543.003 · Windows ServiceT1021.001 · Remote Desktop ProtocolT1685 · Disable or Modify ToolsT1614.001 · System Language DiscoveryT1560 · Archive Collected DataT1059.003 · Windows Command ShellT1136.002 · Domain AccountT1112 · Modify RegistryT1055.012 · Process HollowingT1491.001 · Internal DefacementT1071.001 · Web ProtocolsT1087.002 · Domain AccountT1570 · Lateral Tool TransferT1583.003 · Virtual Private ServerT1190 · Exploit Public-Facing ApplicationT1608.001 · Upload MalwareT1490 · Inhibit System RecoveryT1012 · Query RegistryT1059.001 · PowerShellT1041 · Exfiltration Over C2 ChannelT1003 · OS Credential DumpingT1569.002 · Service ExecutionT1135 · Network Share DiscoveryT1140 · Deobfuscate/Decode Files or InformationT1068 · Exploitation for Privilege EscalationT1505.003 · Web ShellT1078 · Valid AccountsT1567 · Exfiltration Over Web ServiceT1055 · Process InjectionT1021.002 · SMB/Windows Admin Shares

MITRE ATT&CK profili

G1043

[BlackByte](https://attack.mitre.org/groups/G1043) is a ransomware threat actor operating since at least 2021. [BlackByte](https://attack.mitre.org/groups/G1043) is associated with several versions of ransomware also labeled [BlackByte Ransomware](https://attack.mitre.org/software/S1180). [BlackByte](https://attack.mitre.org/groups/G1043) ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as [BlackByte 2.0 Ransomware](https://attack.mitre.org/software/S1181) use more robust encryption mechanisms. [BlackByte](https://attack.mitre.org/groups/G1043) is notable for operations targeting critical infrastructure entities among other targets across North America.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)

MITRE

İlişkili zararlı yazılımlar ve araçlar

AdFindBlackByte RansomwareExbyteArpBlackByte 2.0 RansomwarePsExecCobalt StrikeMimikatz