BlackByte
MITRE ATT&CK: G1043 View on attack.mitre.org
Aliases: Hecamede, BlackByte
- First seen
- 2021-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- innovator
- Resource level
- organization
- Actor type
- criminal
- Related IoCs
- 21 (21 malicious)
- Last IoC activity
- 2026-08-23 07:12:24
- Profile updated
- 2026-07-07 12:30:49
Targeted industries: energy-and-utilities government-and-public-sector healthcare-and-pharmaceutical financial-services
Targeted regions: country_code:us
Context
BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.
Recent IoC activity
21 malicious indicators in Maltiverse are attributed to BlackByte (G1043). The 20 most recently updated:
Detection coverage
- 154 YARA rules
- 846 Sigma rules
Malware & tools used
- System Information Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Network Service Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Domain Trust Discovery (attack-pattern)
- Disable or Modify System Firewall (attack-pattern)
- Masquerade File Type (attack-pattern)
- Scheduled Task (attack-pattern)
- Make and Impersonate Token (attack-pattern)
- File Deletion (attack-pattern)
- Windows Service (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- System Language Discovery (attack-pattern)
- Archive Collected Data (attack-pattern)
- Windows Command Shell (attack-pattern)
- Domain Account (attack-pattern)
- Modify Registry (attack-pattern)
- Process Hollowing (attack-pattern)
- Internal Defacement (attack-pattern)
- Web Protocols (attack-pattern)
- Domain Account (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Virtual Private Server (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
Reports & references
- MITRE ATT&CK — G1043 (report)
- Cisco Talos — Blackbyte Blends Tried And True Tradecraft With Newly Disclosed Vulnerabilities To Support Ongoing Attacks (report)
- ic3.gov — 220211 (report)
- Microsoft — The Five Day Job A Blackbyte Ransomware Intrusion Case Study (report)
- picussecurity.com — Ttps Used By Blackbyte Ransomware Targeting Critical Infrastructure (report)
- security.com — Blackbyte Exbyte Ransomware (report)