Defense Evasion
- Dell Client driver (BYOVD)
- GIGABYTE Motherboard driver (BYOVD)
- MSI Afterburner driver (BYOVD)
- Zemana Anti-Rootkit driver
BlackByte is a ransomware family and ransomware-as-a-service operation active since 2021 that has targeted enterprise environments, including Windows and VMware ESXi systems.
Profile source: Mallory opens in a new tabBlackByte
BlackByte is a ransomware family and ransomware-as-a-service operation active since 2021 that has targeted enterprise environments, including Windows and VMware ESXi systems. It is associated with double-extortion activity in which operators encrypt victim data and steal information for leverage, and mature affiliates have used a dedicated exfiltration utility known as Exbyte to support data theft.
Observed BlackByte intrusions show operators gaining access through exploitation of exposed services and vulnerabilities, including Microsoft Exchange ProxyShell flaws and, more recently, VMware ESXi authentication-bypass vulnerabilities. After initial compromise, operators have used Cobalt Strike, credential dumping, remote access software, and administrative shares to expand access across the environment. BlackByte activity has included reconnaissance of hosts and Active Directory, lateral movement, registry modification to facilitate propagation and remote administration, firewall rule changes, deletion of shadow copies, and disabling or impairing security controls.
BlackByte is also notable for aggressive defense-evasion tradecraft. Reported cases include process injection into legitimate Windows processes prior to encryption and abuse of vulnerable or signed drivers to disable endpoint protections, including campaigns described as BYOVD. Some reporting also links BlackByte operations with multivector extortion tactics that incorporate DDoS pressure alongside ransomware deployment.
The malware has been observed encrypting from injected processes, staging encryption material on adversary-controlled virtual private servers, and deploying ransom notes across compromised systems. BlackByte has affected mid-market and large organizations and has been discussed alongside other major enterprise-focused ransomware operations.
Reported operators
Le groupe de ransomware BlackByte exploite activement la vulnérabilité « CVE-2024-37085 » de contournement d'authentification récemment corrigée dans les hyperviseurs VMware ESXi pour déployer des ransomwares et obtenir un accès administratif complet aux réseaux des victimes.
Exploited software
MITRE ATT&CK
Reporting
Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.