BlackByte

MITRE ATT&CK: G1043 View on attack.mitre.org

Aliases: Hecamede, BlackByte

First seen
2021-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
innovator
Resource level
organization
Actor type
criminal
Related IoCs
21 (21 malicious)
Last IoC activity
2026-08-23 07:12:24
Profile updated
2026-07-07 12:30:49

Targeted industries: energy-and-utilities government-and-public-sector healthcare-and-pharmaceutical financial-services

Targeted regions: country_code:us

Context

BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.

Recent IoC activity

21 malicious indicators in Maltiverse are attributed to BlackByte (G1043). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 2026-08-22_6895fe98f679b832db5290cac595da1b_cobalt-strike_coinminer_luca-stealer 2026-08-23 1
file sample 2026-08-21_2ee713f8c2d1d0c2372ee879fc506a57_cobalt-strike_coinminer_frostygoo... 2026-08-22 1
file sample 2026-08-21_2f868e78c48e50cfb68f54c740d304c5_cobalt-strike_coinminer_frostygoo... 2026-08-21 1
file sample 2026-06-11_fd87766630ca08e71ddadd2c823b88a2_cobalt-strike_coinminer_luca-stealer 2026-07-15 1
file sample 2026-07-08_8c1ad070d625707792d5431e97c1ea9a_coinminer_dosia_frostygoop_ghostl... 2026-07-08 1
file sample asdf.js 2026-05-16 1
file sample 9f9a2488810c28476abd96c0ede7513645d6d1940cd9ff53bbdc7647c5908e7e.bin 2026-05-05 2
file sample 2026-03-24_619829a59cf234eab3c713eaebadcd1f_cobalt-strike_coinminer_hive_luca-stealer 2026-03-24 1
file sample 2026-03-24_071d4f071ef7c41461d329498558c548_cobalt-strike_coinminer_hive_luca-stealer 2026-03-24 1
file sample 2026-03-09_875ef94b136b23ad6789a7f89b895ab4_cobalt-strike_coinminer_hive_luca-stealer 2026-03-09 1
file sample 2026-03-09_7a8eb2642cd0afb28b1e68432da5b9a6_cobalt-strike_coinminer_luca-stealer 2026-03-09 1
file sample 2026-03-09_fa85343f177f1ad4f7a212be529223b0_cobalt-strike_coinminer_hive_luca-stealer 2026-03-09 1
file sample 2026-03-09_dae769cb43a10696673ccb2b2fde7482_cobalt-strike_coinminer_hive_luca-stealer 2026-03-09 1
file sample 2026-03-09_c1052eacdc4bf285fc6263cf4f0b1c62_cobalt-strike_coinminer_luca-stealer 2026-03-09 1
file sample 2026-03-09_b9d8bdebec609333aea1fc93827a266a_cobalt-strike_coinminer_hive_luca-stealer 2026-03-09 1
file sample 2026-03-09_aabed12aad2cc02cecd18b5129164559_cobalt-strike_coinminer_luca-stealer 2026-03-09 1
file sample 2026-03-09_f969a662297d12b5647a81cb279f3bba_cobalt-strike_coinminer_hive_luca-stealer 2026-03-09 1
file sample 2026-03-09_9680edebea4e75f863e98a5f63512ca2_cobalt-strike_coinminer_luca-stealer 2026-03-09 1
file sample 2026-03-09_576bfe562fc355f8cd6dbff6b6ae488f_cobalt-strike_coinminer_hive_luca-stealer 2026-03-09 1
file sample 2026-03-09_113b6637e33e5b0a9979d8536de81b24_cobalt-strike_coinminer_hive_luca-stealer 2026-03-09 1

Detection coverage

  • 154 YARA rules
  • 846 Sigma rules

Malware & tools used

  • System Information Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Domain Trust Discovery (attack-pattern)
  • Disable or Modify System Firewall (attack-pattern)
  • Masquerade File Type (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Make and Impersonate Token (attack-pattern)
  • File Deletion (attack-pattern)
  • Windows Service (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • System Language Discovery (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Domain Account (attack-pattern)
  • Modify Registry (attack-pattern)
  • Process Hollowing (attack-pattern)
  • Internal Defacement (attack-pattern)
  • Web Protocols (attack-pattern)
  • Domain Account (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Virtual Private Server (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)

Reports & references

  • MITRE ATT&CK — G1043 (report)
  • Cisco Talos — Blackbyte Blends Tried And True Tradecraft With Newly Disclosed Vulnerabilities To Support Ongoing Attacks (report)
  • ic3.gov — 220211 (report)
  • Microsoft — The Five Day Job A Blackbyte Ransomware Intrusion Case Study (report)
  • picussecurity.com — Ttps Used By Blackbyte Ransomware Targeting Critical Infrastructure (report)
  • security.com — Blackbyte Exbyte Ransomware (report)

External references