BlackByte

First seen
2021-07-01 00:00:00
Malware type
ransomware, worm
Family
Malware family
Last IoC activity
2026-07-15 02:08:56
Profile updated
2026-07-07 12:45:45

Targeted industries: healthcare-and-pharmaceutical financial-services government-and-public-sector

Context

BlackByte is recently discovered Ransomware with a .NET DLL core payload wrapped in JavaScript. It employs heavy obfuscation both in its JavaScript wrapper and .NET DLL core. Once the JavaScript wrapper is executed, the malware will de-obfuscate the core payload and execute it in memory. The core .DLL is loaded and BlackByte will check the installed operating system language and terminate if an eastern European language is found. It will proceed to check for the presence of several anti-virus and sandbox-related .DLLs, attempt to bypass AMSI, delete system shadow-copies in order to hinder system recovery, and modify several other system services (including Windows Firewall) in order to “prep” the system for encryption. Once the system is “ready” for encryption, it will download a symmetric key-file which will be used to encrypt files on the system. If this file is not found, the malware will terminate. Unlike most Ransomware today, BlackByte uses a single symmetric encryption key, and does not generate a unique encryption key for each victim system, meaning the same key can be used to decrypt all files encrypted by the malware. This makes for substantially easier key-management for the actors behind BlackByte at the cost of a weaker encryption scheme and easier victim system recovery (as there is only a single online point with a single key to maintain). As with most Ransomware today, BlackByte has worming capabilities and can infect additional endpoints on the same network.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Blackbyte_Auto (yara-rule)

Related threat objects

Reports & references

  • deepinstinct.com — Understanding The Windows Javascript Threat Landscape (report)
  • advintel.io — Enter Karakurt Data Extortion Arm Of Prolific Ransomware Group (report)
  • Cisco Talos — Blackbyte Blends Tried And True Tradecraft With Newly Disclosed Vulnerabilities To Support Ongoing Attacks (report)
  • Microsoft — The Five Day Job A Blackbyte Ransomware Intrusion Case Study (report)
  • picussecurity.com — Ttps Used By Blackbyte Ransomware Targeting Critical Infrastructure (report)
  • media.kasperskycontenthub.com — Common Ttps Of The Modern Ransomware Low Res (report)
  • Kaspersky — 106824 (report)
  • advintel.io — Discontinued The End Of Conti S Brand Marks New Chapter For Cybercrime Landscape (report)
  • advintel.io — Hydra With Three Heads Blackbyte The Future Of Ransomware Subsidiary Groups (report)
  • bleepingcomputer.com — Microsoft Exchange Servers Hacked To Deploy Hive Ransomware (report)
  • redcanary.com — Blackbyte Ransomware (report)
  • ic3.gov — 220211 (report)
  • therecord.media — San Francisco 49Ers Confirm Ransomware Attack (report)
  • bleepingcomputer.com — Fbi Blackbyte Ransomware Breached Us Critical Infrastructure (report)
  • trellix.com — Trellix Global Defenders Analysis And Protections For Blackbyte Ransomware (report)
  • zscaler.com — Analysis Blackbyte Ransomwares Go Based Variants (report)
  • Cisco Talos — The Blackbyte Ransomware Group Is (report)
  • research.nccgroup.com — Climbing Mount Everest Black Byte Bytes Back (report)
  • news.sophos.com — Blackbyte Ransomware Returns (report)
  • Cisco Talos — The Blackbyte Ransomware Group Is (report)
  • de.darktrace.com — Detecting The Unknown Revealing Uncategorised Ransomware Using Darktrace (report)
  • trellix.com — Trellix Global Defenders Analysis And Protections For Blackbyte Ransomware (report)
  • Trend Micro — Ransomware Spotlight Blackbyte (report)
  • ransomlook.io — Blackbyte (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Blackbyte (report)

External references