Skip to content

BlackByte

BlackByte is a ransomware family and ransomware-as-a-service operation active since 2021 that has targeted enterprise environments, including Windows and VMware ESXi systems.

Profile source: Mallory opens in a new tab

BlackByte

Family profile

BlackByte is a ransomware family and ransomware-as-a-service operation active since 2021 that has targeted enterprise environments, including Windows and VMware ESXi systems. It is associated with double-extortion activity in which operators encrypt victim data and steal information for leverage, and mature affiliates have used a dedicated exfiltration utility known as Exbyte to support data theft.

Observed BlackByte intrusions show operators gaining access through exploitation of exposed services and vulnerabilities, including Microsoft Exchange ProxyShell flaws and, more recently, VMware ESXi authentication-bypass vulnerabilities. After initial compromise, operators have used Cobalt Strike, credential dumping, remote access software, and administrative shares to expand access across the environment. BlackByte activity has included reconnaissance of hosts and Active Directory, lateral movement, registry modification to facilitate propagation and remote administration, firewall rule changes, deletion of shadow copies, and disabling or impairing security controls.

BlackByte is also notable for aggressive defense-evasion tradecraft. Reported cases include process injection into legitimate Windows processes prior to encryption and abuse of vulnerable or signed drivers to disable endpoint protections, including campaigns described as BYOVD. Some reporting also links BlackByte operations with multivector extortion tactics that incorporate DDoS pressure alongside ransomware deployment.

The malware has been observed encrypting from injected processes, staging encryption material on adversary-controlled virtual private servers, and deploying ransom notes across compromised systems. BlackByte has affected mid-market and large organizations and has been discussed alongside other major enterprise-focused ransomware operations.

Capabilities

  • Byovd
  • Credential Theft
  • Ddos
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Lateral Movement
  • Persistence
  • Privilege Escalation
  • Process Injection
  • Reconnaissance
  • Scanning

Operational record

1
YARA rules
4
Ransom notes
9
Leak sites
0 available

Defense Evasion

  • Dell Client driver (BYOVD)
  • GIGABYTE Motherboard driver (BYOVD)
  • MSI Afterburner driver (BYOVD)
  • Zemana Anti-Rootkit driver

Discovery Enum

  • PowerView
  • SoftPerfect NetScan

Offsec

  • Cobalt Strike
  • PowerShell Empire

RMM Tools

  • AnyDesk

Reported operators

Threat actors

1 named in public reporting
BlackByte

Le groupe de ransomware BlackByte exploite activement la vulnérabilité « CVE-2024-37085 » de contournement d'authentification récemment corrigée dans les hyperviseurs VMware ESXi pour déployer des ransomwares et obtenir un accès administratif complet aux réseaux des victimes.

Exploited software

Vulnerabilities linked to BlackByte

11 CVEs

MITRE ATT&CK

BlackByte in ATT&CK

59 distinct techniques

Techniques

59 techniques
T1486 Data Encrypted for Impact T1078 Valid Accounts T1190 Exploit Public-Facing Application T1498 Network Denial of Service T1055 Process Injection T1574.011 Services Registry Permissions Weakness T1505.003 Web Shell T1562.004 Disable or Modify System Firewall T1053.005 Scheduled Task T1112 Modify Registry T1562.001 Disable or Modify Tools T1070.004 File Deletion T1027.002 Software Packing T1490 Inhibit System Recovery T1016 System Network Configuration Discovery T1018 Remote System Discovery T1059.001 PowerShell T1587.001 Malware T1553.002 Code Signing T1562 Impair Defenses T1068 Exploitation for Privilege Escalation T1548 Abuse Elevation Control Mechanism T1614.001 System Language Discovery T1027 Obfuscated Files or Information T1543.003 Windows Service T1036 Masquerading T1036.008 Masquerade File Type T1041 Exfiltration Over C2 Channel T1078.002 Valid Accounts: Domain Accounts T1047 Windows Management Instrumentation T1059.003 Command and Scripting Interpreter: Windows Command Shell T1569.002 System Services: Service Execution T1136.002 Create Account: Domain Account T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1055.012 Process Injection: Process Hollowing T1134.003 Access Token Manipulation: Make and Impersonate Token T1140 Deobfuscate/Decode Files or Information T1480 Execution Guardrails T1003 OS Credential Dumping T1012 Query Registry T1046 Network Service Discovery T1082 System Information Discovery T1087.002 Account Discovery: Domain Account T1135 Network Share Discovery T1482 Domain Trust Discovery T1518.001 Software Discovery: Security Software Discovery T1021.001 Remote Services: Remote Desktop Protocol T1021.002 Remote Services: SMB/Windows Admin Shares T1570 Lateral Tool Transfer T1560 Archive Collected Data T1567 Exfiltration Over Web Service T1071.001 Application Layer Protocol: Web Protocols T1105 Ingress Tool Transfer T1219 Remote Access Tools T1491.001 Defacement: Internal Defacement T1583.003 Acquire Infrastructure: Virtual Private Server T1608.001 Stage Capabilities: Upload Malware T1685 Disable or Modify Tools T1686 Disable or Modify System Firewall

Reporting

Research mentioning BlackByte

Aug 3
Securelist

Incident response statistics and cases at educational institutions in Brazil | Securelist

Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.

Mar 9
Mitre Attack Website

Compromise Accounts, Technique T1586 - Enterprise | MITRE ATT&CK®

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.