HackerFeeds
All ransomware groups

blackbyte

147 tracked victims
·first seen 2021-10-04·last activity 2025-07-30

Group profile

Ransomware. Uses dropper written in JavaScript to deploy a .NET payload.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    [BlackByte](https://attack.mitre.org/groups/G1043) has gained access to victim environments through legitimate VPN credentials.(Citation: Cisco BlackByte 2024)

  • T1078.002Valid Accounts: Domain Accounts

    [BlackByte](https://attack.mitre.org/groups/G1043) captured credentials for or impersonated domain administration users.(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)

  • T1190Exploit Public-Facing Application

    [BlackByte](https://attack.mitre.org/groups/G1043) exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)(Citation: Microsoft BlackByte 2023)

TA0002

Execution

  • T1047Windows Management Instrumentation

    [BlackByte](https://attack.mitre.org/groups/G1043) used WMI to delete Volume Shadow Copies on victim machines.(Citation: FBI BlackByte 2022)

  • T1053.005Scheduled Task/Job: Scheduled Task

    [BlackByte](https://attack.mitre.org/groups/G1043) created scheduled tasks for payload execution.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)

  • T1059.001Command and Scripting Interpreter: PowerShell

    [BlackByte](https://attack.mitre.org/groups/G1043) used encoded PowerShell commands during operations.(Citation: FBI BlackByte 2022) [BlackByte](https://attack.mitre.org/groups/G1043) has used remote PowerShell commands in victim networks.(Citation: Microsoft BlackByte 2023)

  • T1059.003Command and Scripting Interpreter: Windows Command Shell

    [BlackByte](https://attack.mitre.org/groups/G1043) executed ransomware using the Windows command shell.(Citation: FBI BlackByte 2022)

  • T1569.002System Services: Service Execution

    [BlackByte](https://attack.mitre.org/groups/G1043) created malicious services for ransomware execution.(Citation: Symantec BlackByte 2022)(Citation: Cisco BlackByte 2024)

TA0003

Persistence

  • T1053.005Scheduled Task/Job: Scheduled Task

    [BlackByte](https://attack.mitre.org/groups/G1043) created scheduled tasks for payload execution.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)

  • T1078Valid Accounts

    [BlackByte](https://attack.mitre.org/groups/G1043) has gained access to victim environments through legitimate VPN credentials.(Citation: Cisco BlackByte 2024)

  • T1078.002Valid Accounts: Domain Accounts

    [BlackByte](https://attack.mitre.org/groups/G1043) captured credentials for or impersonated domain administration users.(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)

  • T1112Modify Registry

    [BlackByte](https://attack.mitre.org/groups/G1043) performed Registry modifications to escalate privileges and disable security tools.(Citation: Picus BlackByte 2022)(Citation: Cisco BlackByte 2024)

  • T1136.002Create Account: Domain Account

    [BlackByte](https://attack.mitre.org/groups/G1043) created privileged domain accounts during intrusions.(Citation: Cisco BlackByte 2024)

  • T1505.003Server Software Component: Web Shell

    [BlackByte](https://attack.mitre.org/groups/G1043) has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange.(Citation: Picus BlackByte 2022)(Citation: Microsoft BlackByte 2023)

  • T1543.003Create or Modify System Process: Windows Service

    [BlackByte](https://attack.mitre.org/groups/G1043) modified multiple services on victim machines to enable encryption operations.(Citation: Symantec BlackByte 2022) [BlackByte](https://attack.mitre.org/groups/G1043) has installed tools such as AnyDesk as a service on victim machines.(Citation: Microsoft BlackByte 2023)

  • T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

    [BlackByte](https://attack.mitre.org/groups/G1043) has used Registry Run keys for persistence.(Citation: Microsoft BlackByte 2023)

TA0004

Privilege Escalation

  • T1053.005Scheduled Task/Job: Scheduled Task

    [BlackByte](https://attack.mitre.org/groups/G1043) created scheduled tasks for payload execution.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)

  • T1055Process Injection

    [BlackByte](https://attack.mitre.org/groups/G1043) has injected [Cobalt Strike](https://attack.mitre.org/software/S0154) into `wuauclt.exe` during intrusions.(Citation: Picus BlackByte 2022) [BlackByte](https://attack.mitre.org/groups/G1043) has injected ransomware into `svchost.exe` before encryption.(Citation: Symantec BlackByte 2022)

  • T1055.012Process Injection: Process Hollowing

    [BlackByte](https://attack.mitre.org/groups/G1043) used process hollowing for defense evasion purposes.(Citation: Microsoft BlackByte 2023)

  • T1068Exploitation for Privilege Escalation

    [BlackByte](https://attack.mitre.org/groups/G1043) has exploited CVE-2024-37085 in VMWare ESXi software for authentication bypass and subsequent privilege escalation.(Citation: Cisco BlackByte 2024)

  • T1078Valid Accounts

    [BlackByte](https://attack.mitre.org/groups/G1043) has gained access to victim environments through legitimate VPN credentials.(Citation: Cisco BlackByte 2024)

  • T1078.002Valid Accounts: Domain Accounts

    [BlackByte](https://attack.mitre.org/groups/G1043) captured credentials for or impersonated domain administration users.(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)

  • T1134.003Access Token Manipulation: Make and Impersonate Token

    [BlackByte](https://attack.mitre.org/groups/G1043) constructed a valid authentication token following Microsoft Exchange exploitation to allow for follow-on privileged command execution.(Citation: Microsoft BlackByte 2023)

  • T1543.003Create or Modify System Process: Windows Service

    [BlackByte](https://attack.mitre.org/groups/G1043) modified multiple services on victim machines to enable encryption operations.(Citation: Symantec BlackByte 2022) [BlackByte](https://attack.mitre.org/groups/G1043) has installed tools such as AnyDesk as a service on victim machines.(Citation: Microsoft BlackByte 2023)

  • T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

    [BlackByte](https://attack.mitre.org/groups/G1043) has used Registry Run keys for persistence.(Citation: Microsoft BlackByte 2023)

TA0005

Stealth

  • T1036.008Masquerading: Masquerade File Type

    [BlackByte](https://attack.mitre.org/groups/G1043) masqueraded configuration files containing encryption keys as PNG files.(Citation: FBI BlackByte 2022)

  • T1055Process Injection

    [BlackByte](https://attack.mitre.org/groups/G1043) has injected [Cobalt Strike](https://attack.mitre.org/software/S0154) into `wuauclt.exe` during intrusions.(Citation: Picus BlackByte 2022) [BlackByte](https://attack.mitre.org/groups/G1043) has injected ransomware into `svchost.exe` before encryption.(Citation: Symantec BlackByte 2022)

  • T1055.012Process Injection: Process Hollowing

    [BlackByte](https://attack.mitre.org/groups/G1043) used process hollowing for defense evasion purposes.(Citation: Microsoft BlackByte 2023)

  • T1070.004Indicator Removal: File Deletion

    [BlackByte](https://attack.mitre.org/groups/G1043) deleted ransomware executables post-encryption.(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)

  • T1078Valid Accounts

    [BlackByte](https://attack.mitre.org/groups/G1043) has gained access to victim environments through legitimate VPN credentials.(Citation: Cisco BlackByte 2024)

  • T1078.002Valid Accounts: Domain Accounts

    [BlackByte](https://attack.mitre.org/groups/G1043) captured credentials for or impersonated domain administration users.(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)

  • T1134.003Access Token Manipulation: Make and Impersonate Token

    [BlackByte](https://attack.mitre.org/groups/G1043) constructed a valid authentication token following Microsoft Exchange exploitation to allow for follow-on privileged command execution.(Citation: Microsoft BlackByte 2023)

  • T1140Deobfuscate/Decode Files or Information

    [BlackByte](https://attack.mitre.org/groups/G1043) has encoded commands in base64-encoded sections concatenated together in PowerShell.(Citation: FBI BlackByte 2022) [BlackByte](https://attack.mitre.org/groups/G1043) uses PowerShell commands to disable Windows Defender.(Citation: Picus BlackByte 2022)

  • T1480Execution Guardrails

    [BlackByte](https://attack.mitre.org/groups/G1043) stopped execution if identified language settings on victim machines was Russian or one of several language associated with former Soviet republics.(Citation: Picus BlackByte 2022) [BlackByte](https://attack.mitre.org/groups/G1043) has used ransomware variants requiring a key passed on the command line for the malware to execute.(Citation: Cisco BlackByte 2024)

TA0006

Credential Access

  • T1003OS Credential Dumping

    [BlackByte](https://attack.mitre.org/groups/G1043) used tools such as [Cobalt Strike](https://attack.mitre.org/software/S0154) and [Mimikatz](https://attack.mitre.org/software/S0002) to dump credentials from victim systems.(Citation: Picus BlackByte 2022)(Citation: Microsoft BlackByte 2023)

TA0007

Discovery

  • T1012Query Registry

    [BlackByte](https://attack.mitre.org/groups/G1043) queried registry values to determine system language settings.(Citation: Picus BlackByte 2022)

  • T1016System Network Configuration Discovery

    [BlackByte](https://attack.mitre.org/groups/G1043) used tools such as [Arp](https://attack.mitre.org/software/S0099) to pull system network information and identify connected devices.(Citation: FBI BlackByte 2022)(Citation: Microsoft BlackByte 2023)

  • T1018Remote System Discovery

    [BlackByte](https://attack.mitre.org/groups/G1043) used tools such as [Arp](https://attack.mitre.org/software/S0099) to identify remotely-connected devices.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)

  • T1046Network Service Discovery

    [BlackByte](https://attack.mitre.org/groups/G1043) has used tools such as NetScan to enumerate network services in victim environments.(Citation: Microsoft BlackByte 2023)

  • T1082System Information Discovery

    [BlackByte](https://attack.mitre.org/groups/G1043) used various system commands and tools to pull system information during operations.(Citation: FBI BlackByte 2022)(Citation: Symantec BlackByte 2022)(Citation: Microsoft BlackByte 2023)

  • T1087.002Account Discovery: Domain Account

    [BlackByte](https://attack.mitre.org/groups/G1043) has used tools such as [AdFind](https://attack.mitre.org/software/S0552) to identify and enumerate domain accounts.(Citation: Microsoft BlackByte 2023)

  • T1135Network Share Discovery

    [BlackByte](https://attack.mitre.org/groups/G1043) enumerated network shares on victim devices.(Citation: Cisco BlackByte 2024)

  • T1482Domain Trust Discovery

    [BlackByte](https://attack.mitre.org/groups/G1043) enumerated Active Directory information and trust relationships during operations.(Citation: FBI BlackByte 2022)(Citation: Microsoft BlackByte 2023)

  • T1518.001Software Discovery: Security Software Discovery

    [BlackByte](https://attack.mitre.org/groups/G1043) enumerated installed security products during operations.(Citation: Microsoft BlackByte 2023)

  • T1614.001System Location Discovery: System Language Discovery

    [BlackByte](https://attack.mitre.org/groups/G1043) identified system language settings to determine follow-on execution.(Citation: Picus BlackByte 2022)

TA0008

Lateral Movement

  • T1021.001Remote Services: Remote Desktop Protocol

    [BlackByte](https://attack.mitre.org/groups/G1043) has used RDP to access other hosts within victim networks.(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)

  • T1021.002Remote Services: SMB/Windows Admin Shares

    [BlackByte](https://attack.mitre.org/groups/G1043) used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations.(Citation: Picus BlackByte 2022)(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)

  • T1570Lateral Tool Transfer

    [BlackByte](https://attack.mitre.org/groups/G1043) transfered tools such as [Cobalt Strike](https://attack.mitre.org/software/S0154) and the AnyDesk remote access tool during operations using SMB shares.(Citation: Picus BlackByte 2022)

TA0009

Collection

  • T1560Archive Collected Data

    [BlackByte](https://attack.mitre.org/groups/G1043) compressed data collected from victim environments prior to exfiltration.(Citation: Picus BlackByte 2022)

TA0010

Exfiltration

  • T1041Exfiltration Over C2 Channel

    [BlackByte](https://attack.mitre.org/groups/G1043) transmitted collected victim host information via HTTP POST to command and control infrastructure.(Citation: Microsoft BlackByte 2023)

  • T1567Exfiltration Over Web Service

    [BlackByte](https://attack.mitre.org/groups/G1043) has used services such as `anonymfiles.com` and `file.io` to exfiltrate victim data.(Citation: Picus BlackByte 2022)

TA0011

Command and Control

  • T1071.001Application Layer Protocol: Web Protocols

    [BlackByte](https://attack.mitre.org/groups/G1043) collected victim device information then transmitted this via HTTP POST to command and control infrastructure.(Citation: Microsoft BlackByte 2023)

  • T1105Ingress Tool Transfer

    [BlackByte](https://attack.mitre.org/groups/G1043) has transferred tools such as [Cobalt Strike](https://attack.mitre.org/software/S0154) to victim environments from file sharing and hosting websites.(Citation: Microsoft BlackByte 2023)

  • T1219Remote Access Tools

    [BlackByte](https://attack.mitre.org/groups/G1043) has used tools such as AnyDesk in victim environments.(Citation: Picus BlackByte 2022)(Citation: Microsoft BlackByte 2023)

TA0040

Impact

  • T1486Data Encrypted for Impact

    [BlackByte](https://attack.mitre.org/groups/G1043) has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)

  • T1490Inhibit System Recovery

    [BlackByte](https://attack.mitre.org/groups/G1043) resized and deleted volume shadow copy files to prevent system recovery after encryption.(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)

  • T1491.001Defacement: Internal Defacement

    [BlackByte](https://attack.mitre.org/groups/G1043) left ransom notes in all directories where encryption takes place.(Citation: FBI BlackByte 2022)

TA0042

Resource Development

  • T1583.003Acquire Infrastructure: Virtual Private Server

    [BlackByte](https://attack.mitre.org/groups/G1043) staged encryption keys on virtual private servers operated by the adversary.(Citation: FBI BlackByte 2022)

  • T1608.001Stage Capabilities: Upload Malware

    [BlackByte](https://attack.mitre.org/groups/G1043) has staged tools such as [Cobalt Strike](https://attack.mitre.org/software/S0154) at public file sharing and hosting sites.(Citation: Microsoft BlackByte 2023)

TA0112

Defense Impairment

  • T1112Modify Registry

    [BlackByte](https://attack.mitre.org/groups/G1043) performed Registry modifications to escalate privileges and disable security tools.(Citation: Picus BlackByte 2022)(Citation: Cisco BlackByte 2024)

  • T1685Disable or Modify Tools

    [BlackByte](https://attack.mitre.org/groups/G1043) disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)(Citation: Cisco BlackByte 2024)

  • T1686Disable or Modify System Firewall

    [BlackByte](https://attack.mitre.org/groups/G1043) modified firewall rules on victim machines to enable remote system discovery.(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)

Recent victims

showing 50 of 147
DateWebsite / victimSectorCountry
2025-07-20ManufacturingES
2025-07-30
lee-associates.com
Lee & Associateswww.lee-associates.com
Professional ServicesUS
2025-07-30TechnologyBR
2025-07-30Financial ServicesUS
2025-07-16
greenlightbiosciences.com
GreenLight Biosciencesgreenlightbiosciences.com
TechnologyUS
2025-07-16Professional ServicesSE
2025-07-16
arkconsultancy.co.uk
Ark Consultancyarkconsultancy.co.uk
Professional ServicesGB
2025-07-16Professional ServicesUS
2025-07-16Professional ServicesUS
2024-09-30TechnologyBR
2024-07-17
modernauto.com
Modernautomodernauto.com
Retail & E-CommerceUS
2024-07-17
modernauto.com
Modern Automotive Groupmodernauto.com
ManufacturingUS
2024-06-22
cityofnewburgh-ny.gov
City of Newburghcityofnewburgh-ny.gov/
Government & DefenseUS
2024-06-22
cityofnewburgh-ny.gov
Cityofnewburgh-ny.govcityofnewburgh-ny.gov
Government & DefenseUS
2024-03-06
E
Encinajpa
Not Found
2024-03-13
encinajpa.com
Encina Wastewater Authorityencinajpa.com
Government & DefenseUS
2023-10-04
meridian.coop
Meridian Cooperativemeridian.coop/
Energy & Utilities
2023-09-18
xcaret.com
Hoteles Xcaretxcaret.com
Hospitality
2023-09-11
alpsalpine.com
Alps Alpinealpsalpine.com
Manufacturing
2023-09-09
kirbyrisk.com
Kirby Riskkirbyrisk.com
Professional ServicesIN
2023-09-07
focus-solutions.net
FOCUS Business Solutionsfocus-solutions.net/
Professional Services
2023-09-07
casdonline.org
Chambersburg Area School Districtcasdonline.org/
Education
2023-09-06Manufacturing
2023-08-24Professional Services
2023-07-05
avalign.com
Avalign Technologiesavalign.com
Healthcare
2023-07-03
brettmartin.com
Brett Martinbrettmartin.com
Manufacturing
2023-06-16
kiscoseniorliving.com
Kisco Senior Livingkiscoseniorliving.com
Retail & E-Commerce
2023-06-16
multistack.com
Multistackmultistack.com
Manufacturing
2023-06-14
nebraskaland.com
NEBRASKALANDnebraskaland.com
Agriculture and Food Production
2023-06-14
texwipe.com
The Texwipetexwipe.com
Manufacturing
2023-06-14
usa.yamaha.com
YAMAHA CORPORATION OF AMERICAusa.yamaha.com
Manufacturing
2023-06-14TransportationPL
2023-05-25
augustaga.gov
City of Augustaaugustaga.gov/
Government & DefenseUS
2023-05-17
magicaire.com
Magic-Airemagicaire.com
Manufacturing
2023-05-12
sterlingsolutions.co.uk
Sterling Solutionssterlingsolutions.co.uk/
Professional ServicesGB
2023-05-04
psmm.pl
PRESS-SERVICE Monitoring Mediówpsmm.pl/
Professional ServicesPL
2023-04-25
dacotahpaper.com
Dacotah Paperdacotahpaper.com
Agriculture and Food Production
2023-04-22
easy-automation.com
Easy Automationeasy-automation.com
Agriculture and Food Production
2023-04-15
evmexico.org
Esperanza Viva Jóvenes de Méxicoevmexico.org/
Other
2023-04-15
glv.co.jp
Gulliver Internationalglv.co.jp/
Retail & E-CommerceJP
2023-04-15
saobacdau.vn
Saobacdau Technologies Groupsaobacdau.vn/
TechnologyVN
2023-04-09
creationbaumann.com
Creation Baumanncreationbaumann.com
Retail & E-Commerce
2023-04-09
crowngrinding.com
Crown Grinding & Machiningcrowngrinding.com
Manufacturing
2023-04-09
cbb.cl
Cementos Bio-Biocbb.cl/
ManufacturingCL
2023-04-09
collegedaletn.gov
City of Collegedalecollegedaletn.gov/
Government & DefenseUS
2023-03-20
kelly.co.uk
Kelly Groupkelly.co.uk/
TechnologyGB
2023-03-16
etex.net
Etex Communicationsetex.net/
Technology
2023-03-09
falconholdings.com
Falcon Holdingsfalconholdings.com
Professional Services
2023-03-08Manufacturing
2023-02-12
inlandgroup.aero
Inland Groupinlandgroup.aero/
TransportationCA