BlackByte Ransomware

MITRE ATT&CK: S1180 View on attack.mitre.org

Aliases: BlackByte Ransomware

Malware type
ransomware
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:23:48

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical financial-services

Context

BlackByte Ransomware is uniquely associated with BlackByte operations. BlackByte Ransomware used a common key for infections, allowing for the creation of a universal decryptor. BlackByte Ransomware was replaced in BlackByte operations by BlackByte 2.0 Ransomware by 2023.

Detection coverage

  • 1 YARA rules
  • 463 Sigma rules

Malware & tools used

  • Network Share Discovery (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Query Registry (attack-pattern)
  • JavaScript (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Downgrade Attack (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Native API (attack-pattern)
  • Windows Permissions (attack-pattern)
  • Modify Registry (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • System Language Discovery (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • System Checks (attack-pattern)

Used by threat actors

Detection rules

  • DITEKSHEN_MALWARE_Win_Blackbytego (yara-rule)

Reports & references

  • Cisco Talos — Blackbyte Blends Tried And True Tradecraft With Newly Disclosed Vulnerabilities To Support Ongoing Attacks (report)
  • ic3.gov — 220211 (report)
  • Microsoft — The Five Day Job A Blackbyte Ransomware Intrusion Case Study (report)
  • MITRE ATT&CK — S1180 (report)
  • trustwave.com — Blackbyte Ransomware Pt 1 In Depth Analysis (report)

External references