blackbyte
Group profile
Ransomware. Uses dropper written in JavaScript to deploy a .NET payload.
MITRE ATT&CK TTPs
Initial Access
T1078Valid Accounts
[BlackByte](https://attack.mitre.org/groups/G1043) has gained access to victim environments through legitimate VPN credentials.(Citation: Cisco BlackByte 2024)
T1078.002Valid Accounts: Domain Accounts
[BlackByte](https://attack.mitre.org/groups/G1043) captured credentials for or impersonated domain administration users.(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)
T1190Exploit Public-Facing Application
[BlackByte](https://attack.mitre.org/groups/G1043) exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)(Citation: Microsoft BlackByte 2023)
Execution
T1047Windows Management Instrumentation
[BlackByte](https://attack.mitre.org/groups/G1043) used WMI to delete Volume Shadow Copies on victim machines.(Citation: FBI BlackByte 2022)
T1053.005Scheduled Task/Job: Scheduled Task
[BlackByte](https://attack.mitre.org/groups/G1043) created scheduled tasks for payload execution.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)
T1059.001Command and Scripting Interpreter: PowerShell
[BlackByte](https://attack.mitre.org/groups/G1043) used encoded PowerShell commands during operations.(Citation: FBI BlackByte 2022) [BlackByte](https://attack.mitre.org/groups/G1043) has used remote PowerShell commands in victim networks.(Citation: Microsoft BlackByte 2023)
T1059.003Command and Scripting Interpreter: Windows Command Shell
[BlackByte](https://attack.mitre.org/groups/G1043) executed ransomware using the Windows command shell.(Citation: FBI BlackByte 2022)
T1569.002System Services: Service Execution
[BlackByte](https://attack.mitre.org/groups/G1043) created malicious services for ransomware execution.(Citation: Symantec BlackByte 2022)(Citation: Cisco BlackByte 2024)
Persistence
T1053.005Scheduled Task/Job: Scheduled Task
[BlackByte](https://attack.mitre.org/groups/G1043) created scheduled tasks for payload execution.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)
T1078Valid Accounts
[BlackByte](https://attack.mitre.org/groups/G1043) has gained access to victim environments through legitimate VPN credentials.(Citation: Cisco BlackByte 2024)
T1078.002Valid Accounts: Domain Accounts
[BlackByte](https://attack.mitre.org/groups/G1043) captured credentials for or impersonated domain administration users.(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)
T1112Modify Registry
[BlackByte](https://attack.mitre.org/groups/G1043) performed Registry modifications to escalate privileges and disable security tools.(Citation: Picus BlackByte 2022)(Citation: Cisco BlackByte 2024)
T1136.002Create Account: Domain Account
[BlackByte](https://attack.mitre.org/groups/G1043) created privileged domain accounts during intrusions.(Citation: Cisco BlackByte 2024)
T1505.003Server Software Component: Web Shell
[BlackByte](https://attack.mitre.org/groups/G1043) has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange.(Citation: Picus BlackByte 2022)(Citation: Microsoft BlackByte 2023)
T1543.003Create or Modify System Process: Windows Service
[BlackByte](https://attack.mitre.org/groups/G1043) modified multiple services on victim machines to enable encryption operations.(Citation: Symantec BlackByte 2022) [BlackByte](https://attack.mitre.org/groups/G1043) has installed tools such as AnyDesk as a service on victim machines.(Citation: Microsoft BlackByte 2023)
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
[BlackByte](https://attack.mitre.org/groups/G1043) has used Registry Run keys for persistence.(Citation: Microsoft BlackByte 2023)
Privilege Escalation
T1053.005Scheduled Task/Job: Scheduled Task
[BlackByte](https://attack.mitre.org/groups/G1043) created scheduled tasks for payload execution.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)
T1055Process Injection
[BlackByte](https://attack.mitre.org/groups/G1043) has injected [Cobalt Strike](https://attack.mitre.org/software/S0154) into `wuauclt.exe` during intrusions.(Citation: Picus BlackByte 2022) [BlackByte](https://attack.mitre.org/groups/G1043) has injected ransomware into `svchost.exe` before encryption.(Citation: Symantec BlackByte 2022)
T1055.012Process Injection: Process Hollowing
[BlackByte](https://attack.mitre.org/groups/G1043) used process hollowing for defense evasion purposes.(Citation: Microsoft BlackByte 2023)
T1068Exploitation for Privilege Escalation
[BlackByte](https://attack.mitre.org/groups/G1043) has exploited CVE-2024-37085 in VMWare ESXi software for authentication bypass and subsequent privilege escalation.(Citation: Cisco BlackByte 2024)
T1078Valid Accounts
[BlackByte](https://attack.mitre.org/groups/G1043) has gained access to victim environments through legitimate VPN credentials.(Citation: Cisco BlackByte 2024)
T1078.002Valid Accounts: Domain Accounts
[BlackByte](https://attack.mitre.org/groups/G1043) captured credentials for or impersonated domain administration users.(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)
T1134.003Access Token Manipulation: Make and Impersonate Token
[BlackByte](https://attack.mitre.org/groups/G1043) constructed a valid authentication token following Microsoft Exchange exploitation to allow for follow-on privileged command execution.(Citation: Microsoft BlackByte 2023)
T1543.003Create or Modify System Process: Windows Service
[BlackByte](https://attack.mitre.org/groups/G1043) modified multiple services on victim machines to enable encryption operations.(Citation: Symantec BlackByte 2022) [BlackByte](https://attack.mitre.org/groups/G1043) has installed tools such as AnyDesk as a service on victim machines.(Citation: Microsoft BlackByte 2023)
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
[BlackByte](https://attack.mitre.org/groups/G1043) has used Registry Run keys for persistence.(Citation: Microsoft BlackByte 2023)
Stealth
T1036.008Masquerading: Masquerade File Type
[BlackByte](https://attack.mitre.org/groups/G1043) masqueraded configuration files containing encryption keys as PNG files.(Citation: FBI BlackByte 2022)
T1055Process Injection
[BlackByte](https://attack.mitre.org/groups/G1043) has injected [Cobalt Strike](https://attack.mitre.org/software/S0154) into `wuauclt.exe` during intrusions.(Citation: Picus BlackByte 2022) [BlackByte](https://attack.mitre.org/groups/G1043) has injected ransomware into `svchost.exe` before encryption.(Citation: Symantec BlackByte 2022)
T1055.012Process Injection: Process Hollowing
[BlackByte](https://attack.mitre.org/groups/G1043) used process hollowing for defense evasion purposes.(Citation: Microsoft BlackByte 2023)
T1070.004Indicator Removal: File Deletion
[BlackByte](https://attack.mitre.org/groups/G1043) deleted ransomware executables post-encryption.(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)
T1078Valid Accounts
[BlackByte](https://attack.mitre.org/groups/G1043) has gained access to victim environments through legitimate VPN credentials.(Citation: Cisco BlackByte 2024)
T1078.002Valid Accounts: Domain Accounts
[BlackByte](https://attack.mitre.org/groups/G1043) captured credentials for or impersonated domain administration users.(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)
T1134.003Access Token Manipulation: Make and Impersonate Token
[BlackByte](https://attack.mitre.org/groups/G1043) constructed a valid authentication token following Microsoft Exchange exploitation to allow for follow-on privileged command execution.(Citation: Microsoft BlackByte 2023)
T1140Deobfuscate/Decode Files or Information
[BlackByte](https://attack.mitre.org/groups/G1043) has encoded commands in base64-encoded sections concatenated together in PowerShell.(Citation: FBI BlackByte 2022) [BlackByte](https://attack.mitre.org/groups/G1043) uses PowerShell commands to disable Windows Defender.(Citation: Picus BlackByte 2022)
T1480Execution Guardrails
[BlackByte](https://attack.mitre.org/groups/G1043) stopped execution if identified language settings on victim machines was Russian or one of several language associated with former Soviet republics.(Citation: Picus BlackByte 2022) [BlackByte](https://attack.mitre.org/groups/G1043) has used ransomware variants requiring a key passed on the command line for the malware to execute.(Citation: Cisco BlackByte 2024)
Credential Access
T1003OS Credential Dumping
[BlackByte](https://attack.mitre.org/groups/G1043) used tools such as [Cobalt Strike](https://attack.mitre.org/software/S0154) and [Mimikatz](https://attack.mitre.org/software/S0002) to dump credentials from victim systems.(Citation: Picus BlackByte 2022)(Citation: Microsoft BlackByte 2023)
Discovery
T1012Query Registry
[BlackByte](https://attack.mitre.org/groups/G1043) queried registry values to determine system language settings.(Citation: Picus BlackByte 2022)
T1016System Network Configuration Discovery
[BlackByte](https://attack.mitre.org/groups/G1043) used tools such as [Arp](https://attack.mitre.org/software/S0099) to pull system network information and identify connected devices.(Citation: FBI BlackByte 2022)(Citation: Microsoft BlackByte 2023)
T1018Remote System Discovery
[BlackByte](https://attack.mitre.org/groups/G1043) used tools such as [Arp](https://attack.mitre.org/software/S0099) to identify remotely-connected devices.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)
T1046Network Service Discovery
[BlackByte](https://attack.mitre.org/groups/G1043) has used tools such as NetScan to enumerate network services in victim environments.(Citation: Microsoft BlackByte 2023)
T1082System Information Discovery
[BlackByte](https://attack.mitre.org/groups/G1043) used various system commands and tools to pull system information during operations.(Citation: FBI BlackByte 2022)(Citation: Symantec BlackByte 2022)(Citation: Microsoft BlackByte 2023)
T1087.002Account Discovery: Domain Account
[BlackByte](https://attack.mitre.org/groups/G1043) has used tools such as [AdFind](https://attack.mitre.org/software/S0552) to identify and enumerate domain accounts.(Citation: Microsoft BlackByte 2023)
T1135Network Share Discovery
[BlackByte](https://attack.mitre.org/groups/G1043) enumerated network shares on victim devices.(Citation: Cisco BlackByte 2024)
T1482Domain Trust Discovery
[BlackByte](https://attack.mitre.org/groups/G1043) enumerated Active Directory information and trust relationships during operations.(Citation: FBI BlackByte 2022)(Citation: Microsoft BlackByte 2023)
T1518.001Software Discovery: Security Software Discovery
[BlackByte](https://attack.mitre.org/groups/G1043) enumerated installed security products during operations.(Citation: Microsoft BlackByte 2023)
T1614.001System Location Discovery: System Language Discovery
[BlackByte](https://attack.mitre.org/groups/G1043) identified system language settings to determine follow-on execution.(Citation: Picus BlackByte 2022)
Lateral Movement
T1021.001Remote Services: Remote Desktop Protocol
[BlackByte](https://attack.mitre.org/groups/G1043) has used RDP to access other hosts within victim networks.(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)
T1021.002Remote Services: SMB/Windows Admin Shares
[BlackByte](https://attack.mitre.org/groups/G1043) used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations.(Citation: Picus BlackByte 2022)(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)
T1570Lateral Tool Transfer
[BlackByte](https://attack.mitre.org/groups/G1043) transfered tools such as [Cobalt Strike](https://attack.mitre.org/software/S0154) and the AnyDesk remote access tool during operations using SMB shares.(Citation: Picus BlackByte 2022)
Collection
T1560Archive Collected Data
[BlackByte](https://attack.mitre.org/groups/G1043) compressed data collected from victim environments prior to exfiltration.(Citation: Picus BlackByte 2022)
Exfiltration
T1041Exfiltration Over C2 Channel
[BlackByte](https://attack.mitre.org/groups/G1043) transmitted collected victim host information via HTTP POST to command and control infrastructure.(Citation: Microsoft BlackByte 2023)
T1567Exfiltration Over Web Service
[BlackByte](https://attack.mitre.org/groups/G1043) has used services such as `anonymfiles.com` and `file.io` to exfiltrate victim data.(Citation: Picus BlackByte 2022)
Command and Control
T1071.001Application Layer Protocol: Web Protocols
[BlackByte](https://attack.mitre.org/groups/G1043) collected victim device information then transmitted this via HTTP POST to command and control infrastructure.(Citation: Microsoft BlackByte 2023)
T1105Ingress Tool Transfer
[BlackByte](https://attack.mitre.org/groups/G1043) has transferred tools such as [Cobalt Strike](https://attack.mitre.org/software/S0154) to victim environments from file sharing and hosting websites.(Citation: Microsoft BlackByte 2023)
T1219Remote Access Tools
[BlackByte](https://attack.mitre.org/groups/G1043) has used tools such as AnyDesk in victim environments.(Citation: Picus BlackByte 2022)(Citation: Microsoft BlackByte 2023)
Impact
T1486Data Encrypted for Impact
[BlackByte](https://attack.mitre.org/groups/G1043) has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)
T1490Inhibit System Recovery
[BlackByte](https://attack.mitre.org/groups/G1043) resized and deleted volume shadow copy files to prevent system recovery after encryption.(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)
T1491.001Defacement: Internal Defacement
[BlackByte](https://attack.mitre.org/groups/G1043) left ransom notes in all directories where encryption takes place.(Citation: FBI BlackByte 2022)
Resource Development
T1583.003Acquire Infrastructure: Virtual Private Server
[BlackByte](https://attack.mitre.org/groups/G1043) staged encryption keys on virtual private servers operated by the adversary.(Citation: FBI BlackByte 2022)
T1608.001Stage Capabilities: Upload Malware
[BlackByte](https://attack.mitre.org/groups/G1043) has staged tools such as [Cobalt Strike](https://attack.mitre.org/software/S0154) at public file sharing and hosting sites.(Citation: Microsoft BlackByte 2023)
Defense Impairment
T1112Modify Registry
[BlackByte](https://attack.mitre.org/groups/G1043) performed Registry modifications to escalate privileges and disable security tools.(Citation: Picus BlackByte 2022)(Citation: Cisco BlackByte 2024)
T1685Disable or Modify Tools
[BlackByte](https://attack.mitre.org/groups/G1043) disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)(Citation: Cisco BlackByte 2024)
T1686Disable or Modify System Firewall
[BlackByte](https://attack.mitre.org/groups/G1043) modified firewall rules on victim machines to enable remote system discovery.(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)
Recent victims
showing 50 of 147| Date | Website / victim | Sector | Country |
|---|---|---|---|
| 2025-07-20 | DARA Pharmawww.dara-pharma.com | Manufacturing | ES |
| 2025-07-30 | Lee & Associateswww.lee-associates.com | Professional Services | US |
| 2025-07-30 | Cpat Flexwww.cpatflex.com | Technology | BR |
| 2025-07-30 | Towne Mortgagewww.townemortgage.com | Financial Services | US |
| 2025-07-16 | GreenLight Biosciencesgreenlightbiosciences.com | Technology | US |
| 2025-07-16 | T2 Groupt2group.co.uk | Professional Services | SE |
| 2025-07-16 | Ark Consultancyarkconsultancy.co.uk | Professional Services | GB |
| 2025-07-16 | Allstarmgallstarmg.com | Professional Services | US |
| 2025-07-16 | Helpsonvhelpsonv.org | Professional Services | US |
| 2024-09-30 | TOTVStotvs.com | Technology | BR |
| 2024-07-17 | Modernautomodernauto.com | Retail & E-Commerce | US |
| 2024-07-17 | Modern Automotive Groupmodernauto.com | Manufacturing | US |
| 2024-06-22 | City of Newburghcityofnewburgh-ny.gov/ | Government & Defense | US |
| 2024-06-22 | Cityofnewburgh-ny.govcityofnewburgh-ny.gov | Government & Defense | US |
| 2024-03-06 | E Encinajpa | Not Found | |
| 2024-03-13 | Encina Wastewater Authorityencinajpa.com | Government & Defense | US |
| 2023-10-04 | Meridian Cooperativemeridian.coop/ | Energy & Utilities | |
| 2023-09-18 | Hoteles Xcaretxcaret.com | Hospitality | |
| 2023-09-11 | Alps Alpinealpsalpine.com | Manufacturing | |
| 2023-09-09 | Kirby Riskkirbyrisk.com | Professional Services | IN |
| 2023-09-07 | FOCUS Business Solutionsfocus-solutions.net/ | Professional Services | |
| 2023-09-07 | Chambersburg Area School Districtcasdonline.org/ | Education | |
| 2023-09-06 | Smeadsmead.com | Manufacturing | |
| 2023-08-24 | Ontellusontellus.com | Professional Services | |
| 2023-07-05 | Avalign Technologiesavalign.com | Healthcare | |
| 2023-07-03 | Brett Martinbrettmartin.com | Manufacturing | |
| 2023-06-16 | Kisco Senior Livingkiscoseniorliving.com | Retail & E-Commerce | |
| 2023-06-16 | Multistackmultistack.com | Manufacturing | |
| 2023-06-14 | NEBRASKALANDnebraskaland.com | Agriculture and Food Production | |
| 2023-06-14 | The Texwipetexwipe.com | Manufacturing | |
| 2023-06-14 | YAMAHA CORPORATION OF AMERICAusa.yamaha.com | Manufacturing | |
| 2023-06-14 | Fiege Sp. z o.o.global.fiege.com/nl/country/poland/ | Transportation | PL |
| 2023-05-25 | City of Augustaaugustaga.gov/ | Government & Defense | US |
| 2023-05-17 | Magic-Airemagicaire.com | Manufacturing | |
| 2023-05-12 | Sterling Solutionssterlingsolutions.co.uk/ | Professional Services | GB |
| 2023-05-04 | PRESS-SERVICE Monitoring Mediówpsmm.pl/ | Professional Services | PL |
| 2023-04-25 | Dacotah Paperdacotahpaper.com | Agriculture and Food Production | |
| 2023-04-22 | Easy Automationeasy-automation.com | Agriculture and Food Production | |
| 2023-04-15 | Esperanza Viva Jóvenes de Méxicoevmexico.org/ | Other | |
| 2023-04-15 | Gulliver Internationalglv.co.jp/ | Retail & E-Commerce | JP |
| 2023-04-15 | Saobacdau Technologies Groupsaobacdau.vn/ | Technology | VN |
| 2023-04-09 | Creation Baumanncreationbaumann.com | Retail & E-Commerce | |
| 2023-04-09 | Crown Grinding & Machiningcrowngrinding.com | Manufacturing | |
| 2023-04-09 | Cementos Bio-Biocbb.cl/ | Manufacturing | CL |
| 2023-04-09 | City of Collegedalecollegedaletn.gov/ | Government & Defense | US |
| 2023-03-20 | Kelly Groupkelly.co.uk/ | Technology | GB |
| 2023-03-16 | Etex Communicationsetex.net/ | Technology | |
| 2023-03-09 | Falcon Holdingsfalconholdings.com | Professional Services | |
| 2023-03-08 | Wagner CATwagnerequipment.com | Manufacturing | |
| 2023-02-12 | Inland Groupinlandgroup.aero/ | Transportation | CA |

