BlackByte 2.0 Ransomware

MITRE ATT&CK: S1181 View on attack.mitre.org

Aliases: BlackByte 2.0 Ransomware

First seen
2022-10-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:23:53

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Context

BlackByte 2.0 Ransomware is a replacement for BlackByte Ransomware. Unlike BlackByte Ransomware, BlackByte 2.0 Ransomware does not have a common key for victim decryption. BlackByte 2.0 Ransomware remains uniquely associated with BlackByte operations.

Detection coverage

  • 248 Sigma rules

Malware & tools used

  • Timestomp (attack-pattern)
  • Modify Registry (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Service Stop (attack-pattern)
  • File Deletion (attack-pattern)
  • Service Execution (attack-pattern)
  • Process Injection (attack-pattern)
  • Windows Host Firewall (attack-pattern)

Used by threat actors

Reports & references

  • Microsoft — The Five Day Job A Blackbyte Ransomware Intrusion Case Study (report)
  • MITRE ATT&CK — S1181 (report)

External references