Skip to content

BlackByte

BlackByte is a ransomware family and ransomware-as-a-service operation first observed in 2021 that has targeted organizations worldwide, including U.S.

Profile source: Mallory opens in a new tab

BlackByte

Family profile

BlackByte is a ransomware family and ransomware-as-a-service operation first observed in 2021 that has targeted organizations worldwide, including U.S. critical infrastructure sectors such as government facilities, financial services, and food and agriculture. It is primarily a Windows-focused threat that encrypts files on compromised physical and virtual systems and is associated with double-extortion operations in which attackers steal data before encryption and threaten public release through leak-site infrastructure if victims do not pay.

BlackByte evolved from early C# implementations to later Go-based variants, including more feature-rich versions introduced in 2022. Reported behavior includes shadow copy deletion, disabling or terminating security products and business-critical services, partial or full file encryption, ransom-note deployment, and post-encryption extortion via victim portals and negotiation channels. The malware has also been observed using process hollowing and process injection for defense evasion, including injection into legitimate Windows processes, and some variants delete their on-disk binary after execution. Additional anti-analysis and anti-defense measures include string obfuscation, packing, sandbox and debugger checks, firewall and Defender tampering, and attempts to interfere with recovery tooling.

Operationally, BlackByte intrusions have been linked to exploitation of unpatched internet-facing systems, especially Microsoft Exchange vulnerabilities including ProxyShell and ProxyLogon, as well as phishing-based access. After initial compromise, operators and affiliates have used legitimate administrative tools and commodity utilities for reconnaissance, privilege escalation, persistence, lateral movement, and remote execution. Observed tradecraft includes host and Active Directory enumeration, enabling network discovery and file sharing, copying payloads to remote systems, scheduled-task execution, and targeting administrative shares and backup repositories. Multiple reports also describe data exfiltration preceding ransomware deployment, and at least one affiliate used a custom Go-based exfiltration tool to accelerate theft of victim documents.

BlackByte has been described as a mature and evolving criminal operation whose tooling changed after weaknesses in early encryption implementations enabled public decryption. Later variants adopted stronger cryptographic schemes and expanded functionality, reinforcing its position as a significant enterprise ransomware threat.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Reconnaissance

Operational record

1
YARA rules
4
Ransom notes
9
Leak sites
0 available

Defense Evasion

  • Dell Client driver (BYOVD)
  • GIGABYTE Motherboard driver (BYOVD)
  • MSI Afterburner driver (BYOVD)
  • Zemana Anti-Rootkit driver

Discovery Enum

  • PowerView
  • SoftPerfect NetScan

Offsec

  • Cobalt Strike
  • PowerShell Empire

RMM Tools

  • AnyDesk

Reported operators

Threat actors

1 named in public reporting
BlackByte

Symantec’s Threat Hunter Team has discovered that at least one affiliate of the BlackByte ransomware (Ransom.Blackbyte) operation has begun using a custom data exfiltration tool during their attacks.

Exploited software

Vulnerabilities linked to BlackByte

13 CVEs

MITRE ATT&CK

BlackByte in ATT&CK

67 distinct techniques

Techniques

67 techniques
T1562 Impair Defenses T1569.002 Service Execution T1027.002 Software Packing T1070.004 File Deletion T1570 Lateral Tool Transfer T1112 Modify Registry T1657 Financial Theft T1486 Data Encrypted for Impact T1489 Service Stop T1046 Network Service Discovery T1057 Process Discovery T1027 Obfuscated Files or Information T1018 Remote System Discovery T1497 Virtualization/Sandbox Evasion T1021.002 SMB/Windows Admin Shares T1120 Peripheral Device Discovery T1053.005 Scheduled Task T1082 System Information Discovery T1490 Inhibit System Recovery T1055 Process Injection T1548.002 Bypass User Account Control T1614.001 System Language Discovery T1567.002 Exfiltration to Cloud Storage T1562.004 Disable or Modify System Firewall T1543.003 Windows Service T1190 Exploit Public-Facing Application T1105 Ingress Tool Transfer T1070.006 Timestomp T1078 Valid Accounts T1498 Network Denial of Service T1574.011 Services Registry Permissions Weakness T1505.003 Web Shell T1562.001 Disable or Modify Tools T1016 System Network Configuration Discovery T1059.001 PowerShell T1587.001 Malware T1553.002 Code Signing T1068 Exploitation for Privilege Escalation T1548 Abuse Elevation Control Mechanism T1036 Masquerading T1036.008 Masquerade File Type T1041 Exfiltration Over C2 Channel T1078.002 Valid Accounts: Domain Accounts T1047 Windows Management Instrumentation T1059.003 Command and Scripting Interpreter: Windows Command Shell T1136.002 Create Account: Domain Account T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1055.012 Process Injection: Process Hollowing T1134.003 Access Token Manipulation: Make and Impersonate Token T1140 Deobfuscate/Decode Files or Information T1480 Execution Guardrails T1003 OS Credential Dumping T1012 Query Registry T1087.002 Account Discovery: Domain Account T1135 Network Share Discovery T1482 Domain Trust Discovery T1518.001 Software Discovery: Security Software Discovery T1021.001 Remote Services: Remote Desktop Protocol T1560 Archive Collected Data T1567 Exfiltration Over Web Service T1071.001 Application Layer Protocol: Web Protocols T1219 Remote Access Tools T1491.001 Defacement: Internal Defacement T1583.003 Acquire Infrastructure: Virtual Private Server T1608.001 Stage Capabilities: Upload Malware T1685 Disable or Modify Tools T1686 Disable or Modify System Firewall

Reporting

Research mentioning BlackByte

Aug 3
Securelist

Incident response statistics and cases at educational institutions in Brazil | Securelist

Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.

Mar 22
Sentinelone Labs Subdomain

Multi-Platform SMAUG RaaS Aims To See Off Competitors - SentinelLabs

SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.

Jan 23
Trend Micro Research

Kasseika Ransomware Deploys BYOVD Attacks Abuses PsExec and Exploits Martini Driver | Trend Micro (US)

Trend Micro reported that the Kasseika ransomware used a bring-your-own-vulnerable-driver (BYOVD) technique to compromise Windows environments, disable security tools, and encrypt victim files. In the investigated intrusion, the attackers reportedly gained initial access through targeted phishing, then used remote administration tools and PsExec for execution and lateral movement. The malware abused the signed but vulnerable Martini.sys driver from TG Soft’s VirIT Agent System to terminate antivirus and analysis processes, allowing the ransomware to run with reduced interference. The operation also employed anti-analysis checks, cleared Windows event logs, and deleted shadow copies before encrypting files with ChaCha20 and RSA through CryptoPP. After encryption, Kasseika dropped ransom notes and changed the victim’s desktop wallpaper. Researchers said the malware shares multiple code and behavioral traits with BlackMatter, including ransom note naming conventions and apparent source-code overlap, indicating the operators may have obtained or reused parts of BlackMatter’s codebase.

Feb 15
Varonis

Hive Ransomware Analysis

Hive ransomware affiliates used multiple intrusion paths to compromise enterprise networks, including unpatched Microsoft Exchange ProxyShell vulnerabilities and fake software installers delivered through malicious Google Ads and typosquatted download sites. Incident reports describe attackers planting web shells on Exchange servers, launching PowerShell payloads and Cobalt Strike beacons, stealing credentials with tools such as Mimikatz and LSASS dumping, and moving laterally through RDP, PsExec, and pass-the-hash. In several cases, the actors also conducted broad internal reconnaissance, exfiltrated data with tools including Rclone and WinSCP, and created new administrator accounts before deploying Hive’s Golang encryptor and dropping the ransom note HOW_TO_DECRYPT.txt. Researchers also documented unusually aggressive defense-evasion and deployment tactics designed to maximize disruption. Rapid7 observed Hive operators using BITSAdmin, Active Directory Group Policy changes, and PsExec to distribute payloads, then forcing hosts into Safe Mode with minimal services via BCDEdit, enabling auto-logon for a local administrator account, and replacing the Windows shell with a malicious batch file so encryption could run after reboot with security tools disabled. Across the reported intrusions, the ransomware deleted shadow copies and other recovery artifacts, disabled or weakened endpoint defenses, cleared logs, encrypted local and network-accessible files, and used Tor-based negotiation and leak sites to pressure victims into paying.

Feb 2
Kroll

Hive Ransomware Analysis | Kroll

Jan 11
Rapid7

HIVE Ransomware Attack Research & Analysis | Rapid7 Blog

Apr 20
Bleeping Computer

Microsoft Exchange servers hacked to deploy Hive ransomware

Dec 1
Virusbulletin

Virus Bulletin :: Collector-stealer: a Russian origin credential and information extractor

Collector Stealer—also marketed as COLLECTOR Project, CollectorGoomba, and formerly Memory Project—was sold as a Russian-language spyware service and used to steal saved browser credentials, cookies, personal data, screenshots, Telegram and Steam data, and cryptocurrency wallet information from infected Windows systems. Researchers said the malware was spread through phishing portals, fake software downloads, and bundled crack or riskware tools such as KMSAuto, often disguised as miners, game utilities, or activation packages. On infected hosts, it gathered data from browsers and applications, captured screenshots, scanned directories, extracted SQLite-stored information, and staged the loot in ZIP or RAR archives before sending it to attacker-controlled panels over HTTP POST. Analysis of the malware’s infrastructure showed that some builds fetched their command-and-control destination from a text file hosted on GitHub, with a fallback to a hard-coded justns.ru subdomain if retrieval failed. After the malicious GitHub repository was reported and removed, affected samples attempted to exfiltrate to an invalid 404: Not Found.ru destination and crashed, temporarily disrupting those variants. Operators later updated newer samples to use upaste[.]me for C2 redirection instead, indicating the stealer remained under active development and continued to evolve its exfiltration workflow and delivery ecosystem.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.