About this actor
BlackByte is recently discovered Ransomware with a .NET DLL core payload wrapped in JavaScript. It employs heavy obfuscation both in its JavaScript wrapper and .NET DLL core. Once the JavaScript wrapper is executed, the malware will de-obfuscate the core payload and execute it in memory. The core .DLL is loaded and BlackByte will check the installed operating system language and terminate if an eastern European language is found. It will proceed to check for the presence of several anti-virus and sandbox-related .DLLs, attempt to bypass AMSI, delete system shadow-copies in order to hinder system recovery, and modify several other system services (including Windows Firewall) in order to “prep” the system for encryption. Once the system is “ready” for encryption, it will download a symmetric key-file which will be used to encrypt files on the system. If this file is not found, the malware will terminate. Unlike most Ransomware today, BlackByte uses a single symmetric encryption key, and does not generate a unique encryption key for each victim system, meaning the same key can be used to decrypt all files encrypted by the malware. This makes for substantially easier key-management for the actors behind BlackByte at the cost of a weaker encryption scheme and easier victim system recovery (as there is only a single online point with a single key to maintain). As with most Ransomware today, BlackByte has worming capabilities and can infect additional endpoints on the same network.
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 66 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 1 CVE published
- 2019 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2019-16098 | 8.4 | 7.8 | 0.7776 | 2019-09-11 | see CVE |
CVE-2026-4368 | 5.5 | 7.7 | 0.0362 | 2026-03-23 | see CVE |
CVE-2049-16098 | 0.0 | 0.0 | 0.0000 | see CVE |
T1003OS Credential Dumping ↗T1012Query Registry ↗T1016System Network Configuration Discovery ↗T1018Remote System Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1021.002SMB/Windows Admin Shares ↗T1036Masquerading ↗T1036.008Masquerade File Type ↗T1041Exfiltration Over C2 Channel ↗T1046Network Service Discovery ↗T1047Windows Management Instrumentation ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1055Process Injection ↗T1055.012Process Hollowing ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1068Exploitation for Privilege Escalation ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1078Valid Accounts ↗T1078.002Domain Accounts ↗T1082System Information Discovery ↗T1087Account Discovery ↗T1087.002Domain Account ↗T1105Ingress Tool Transfer ↗T1112Modify Registry ↗T1134Access Token Manipulation ↗T1134.003Make and Impersonate Token ↗T1135Network Share Discovery ↗T1136Create Account ↗T1136.002Domain Account ↗T1140Deobfuscate/Decode Files or Information ↗T1190Exploit Public-Facing Application ↗T1219Remote Access Tools ↗T1480Execution Guardrails ↗T1482Domain Trust Discovery ↗T1486Data Encrypted for Impact ↗T1490Inhibit System Recovery ↗T1491Defacement ↗T1491.001Internal Defacement ↗T1505Server Software Component ↗T1505.003Web Shell ↗T1518Software Discovery ↗T1518.001Security Software Discovery ↗T1543Create or Modify System Process ↗T1543.003Windows Service ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1560Archive Collected Data ↗T1567Exfiltration Over Web Service ↗T1569System Services ↗T1569.002Service Execution ↗T1570Lateral Tool Transfer ↗T1583Acquire Infrastructure ↗T1583.003Virtual Private Server ↗T1608Stage Capabilities ↗T1608.001Upload Malware ↗T1614System Location Discovery ↗T1614.001System Language Discovery ↗T1685Disable or Modify Tools ↗T1686Disable or Modify System Firewall ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 44 / 66 | 67% |
CM-6 | 39 / 66 | 59% |
AC-6 | 37 / 66 | 56% |
AC-3 | 36 / 66 | 55% |
AC-2 | 33 / 66 | 50% |
CM-2 | 33 / 66 | 50% |
CM-7 | 32 / 66 | 48% |
SI-3 | 30 / 66 | 45% |
AC-5 | 26 / 66 | 39% |
CM-5 | 24 / 66 | 36% |
IA-2 | 24 / 66 | 36% |
SI-7 | 23 / 66 | 35% |
CA-7 | 21 / 66 | 32% |
SC-7 | 20 / 66 | 30% |
AC-4 | 16 / 66 | 24% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Medusa Group 0.37
- Wizard Spider 0.36
- Operation Wocao 0.33
- Threat Group-3390 0.32
- APT32 0.31
Active in same years
- Tonto Team 2.00
- Operation Dream Job 1.00
- SolarWinds Compromise 1.00
- C0027 1.00
- SharePoint ToolShell Exploitation 1.00
Same category
- LAPSUS$ 1.00
- Akira 1.00
- INC Ransom 1.00
- Play 1.00
- ShinyHunters 1.00