Defense Evasion
- Dell Client driver (BYOVD)
- GIGABYTE Motherboard driver (BYOVD)
- MSI Afterburner driver (BYOVD)
- Zemana Anti-Rootkit driver
BlackByte is a ransomware family and ransomware-as-a-service operation first observed in 2021 that has targeted organizations worldwide, including U.S.
Profile source: Mallory opens in a new tabBlackByte
BlackByte is a ransomware family and ransomware-as-a-service operation first observed in 2021 that has targeted organizations worldwide, including U.S. critical infrastructure sectors such as government facilities, financial services, and food and agriculture. It is primarily a Windows-focused threat that encrypts files on compromised physical and virtual systems and is associated with double-extortion operations in which attackers steal data before encryption and threaten public release through leak-site infrastructure if victims do not pay.
BlackByte evolved from early C# implementations to later Go-based variants, including more feature-rich versions introduced in 2022. Reported behavior includes shadow copy deletion, disabling or terminating security products and business-critical services, partial or full file encryption, ransom-note deployment, and post-encryption extortion via victim portals and negotiation channels. The malware has also been observed using process hollowing and process injection for defense evasion, including injection into legitimate Windows processes, and some variants delete their on-disk binary after execution. Additional anti-analysis and anti-defense measures include string obfuscation, packing, sandbox and debugger checks, firewall and Defender tampering, and attempts to interfere with recovery tooling.
Operationally, BlackByte intrusions have been linked to exploitation of unpatched internet-facing systems, especially Microsoft Exchange vulnerabilities including ProxyShell and ProxyLogon, as well as phishing-based access. After initial compromise, operators and affiliates have used legitimate administrative tools and commodity utilities for reconnaissance, privilege escalation, persistence, lateral movement, and remote execution. Observed tradecraft includes host and Active Directory enumeration, enabling network discovery and file sharing, copying payloads to remote systems, scheduled-task execution, and targeting administrative shares and backup repositories. Multiple reports also describe data exfiltration preceding ransomware deployment, and at least one affiliate used a custom Go-based exfiltration tool to accelerate theft of victim documents.
BlackByte has been described as a mature and evolving criminal operation whose tooling changed after weaknesses in early encryption implementations enabled public decryption. Later variants adopted stronger cryptographic schemes and expanded functionality, reinforcing its position as a significant enterprise ransomware threat.
Reported operators
Symantec’s Threat Hunter Team has discovered that at least one affiliate of the BlackByte ransomware (Ransom.Blackbyte) operation has begun using a custom data exfiltration tool during their attacks.
Exploited software
MITRE ATT&CK
Reporting
Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.
SMAUG is a ransomware-as-a-service (RaaS) operation that advertises 64-bit payloads for Windows, Linux, and macOS, positioning itself as a multi-platform option for affiliates. The service reportedly charges a 20% affiliate fee plus a 0.2 BTC registration fee, and provides a web-based campaign builder, customizable ransom demands, offline encryption, and a "Company Mode" that allows a single decryption key to unlock multiple systems inside one targeted organization. Victims are directed to a Tor-based payment portal, while operators reportedly offer automated support for both affiliates and victims and bar attacks against CIS countries. On Windows, SMAUG uses obfuscated Go binaries that gather system details and stored browser credentials, establish persistence through Registry Run Keys consistent with MITRE ATT&CK T1547.001, and then encrypt files for impact using AES-256 with keys protected by RSA-2048, aligning with T1486 Data Encrypted for Impact tradecraft. The combination of credential collection, registry-based autostart, and hybrid cryptography reflects a mature ransomware model designed to support repeatable intrusions and broad enterprise targeting across multiple operating systems.
Trend Micro reported that the Kasseika ransomware used a bring-your-own-vulnerable-driver (BYOVD) technique to compromise Windows environments, disable security tools, and encrypt victim files. In the investigated intrusion, the attackers reportedly gained initial access through targeted phishing, then used remote administration tools and PsExec for execution and lateral movement. The malware abused the signed but vulnerable Martini.sys driver from TG Soft’s VirIT Agent System to terminate antivirus and analysis processes, allowing the ransomware to run with reduced interference. The operation also employed anti-analysis checks, cleared Windows event logs, and deleted shadow copies before encrypting files with ChaCha20 and RSA through CryptoPP. After encryption, Kasseika dropped ransom notes and changed the victim’s desktop wallpaper. Researchers said the malware shares multiple code and behavioral traits with BlackMatter, including ransom note naming conventions and apparent source-code overlap, indicating the operators may have obtained or reused parts of BlackMatter’s codebase.
Hive ransomware affiliates used multiple intrusion paths to compromise enterprise networks, including unpatched Microsoft Exchange ProxyShell vulnerabilities and fake software installers delivered through malicious Google Ads and typosquatted download sites. Incident reports describe attackers planting web shells on Exchange servers, launching PowerShell payloads and Cobalt Strike beacons, stealing credentials with tools such as Mimikatz and LSASS dumping, and moving laterally through RDP, PsExec, and pass-the-hash. In several cases, the actors also conducted broad internal reconnaissance, exfiltrated data with tools including Rclone and WinSCP, and created new administrator accounts before deploying Hive’s Golang encryptor and dropping the ransom note HOW_TO_DECRYPT.txt. Researchers also documented unusually aggressive defense-evasion and deployment tactics designed to maximize disruption. Rapid7 observed Hive operators using BITSAdmin, Active Directory Group Policy changes, and PsExec to distribute payloads, then forcing hosts into Safe Mode with minimal services via BCDEdit, enabling auto-logon for a local administrator account, and replacing the Windows shell with a malicious batch file so encryption could run after reboot with security tools disabled. Across the reported intrusions, the ransomware deleted shadow copies and other recovery artifacts, disabled or weakened endpoint defenses, cleared logs, encrypted local and network-accessible files, and used Tor-based negotiation and leak sites to pressure victims into paying.
Collector Stealer—also marketed as COLLECTOR Project, CollectorGoomba, and formerly Memory Project—was sold as a Russian-language spyware service and used to steal saved browser credentials, cookies, personal data, screenshots, Telegram and Steam data, and cryptocurrency wallet information from infected Windows systems. Researchers said the malware was spread through phishing portals, fake software downloads, and bundled crack or riskware tools such as KMSAuto, often disguised as miners, game utilities, or activation packages. On infected hosts, it gathered data from browsers and applications, captured screenshots, scanned directories, extracted SQLite-stored information, and staged the loot in ZIP or RAR archives before sending it to attacker-controlled panels over HTTP POST. Analysis of the malware’s infrastructure showed that some builds fetched their command-and-control destination from a text file hosted on GitHub, with a fallback to a hard-coded justns.ru subdomain if retrieval failed. After the malicious GitHub repository was reported and removed, affected samples attempted to exfiltrate to an invalid 404: Not Found.ru destination and crashed, temporarily disrupting those variants. Operators later updated newer samples to use upaste[.]me for C2 redirection instead, indicating the stealer remained under active development and continued to evolve its exfiltration workflow and delivery ecosystem.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.