Cyber Resilience

Threat actor · all actors

BlackByteG1043 criminal

aka BlackByte, Hecamede

Last updated: 2026-08-20

3attributed CVEs
66ATT&CK techniques
12.9IDF score (tooling uniqueness)
3exclusive CVEs
2019–2026years active

About this actor

BlackByte is recently discovered Ransomware with a .NET DLL core payload wrapped in JavaScript. It employs heavy obfuscation both in its JavaScript wrapper and .NET DLL core. Once the JavaScript wrapper is executed, the malware will de-obfuscate the core payload and execute it in memory. The core .DLL is loaded and BlackByte will check the installed operating system language and terminate if an eastern European language is found. It will proceed to check for the presence of several anti-virus and sandbox-related .DLLs, attempt to bypass AMSI, delete system shadow-copies in order to hinder system recovery, and modify several other system services (including Windows Firewall) in order to “prep” the system for encryption. Once the system is “ready” for encryption, it will download a symmetric key-file which will be used to encrypt files on the system. If this file is not found, the malware will terminate. Unlike most Ransomware today, BlackByte uses a single symmetric encryption key, and does not generate a unique encryption key for each victim system, meaning the same key can be used to decrypt all files encrypted by the malware. This makes for substantially easier key-management for the actors behind BlackByte at the cost of a weaker encryption scheme and easier victim system recovery (as there is only a single online point with a single key to maintain). As with most Ransomware today, BlackByte has worming capabilities and can infect additional endpoints on the same network.

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G1043

Unclassifiedno scheme matched

BlackByteHecamede

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 66 ATT&CK techniques on file.
Named victims
None on file.

See how actor data is built for the full pipeline.

Activity timeline

Profile

CVERiskCVSSEPSSPublishedProducts
CVE-2019-16098 8.47.80.77762019-09-11see CVE
CVE-2026-4368 5.57.70.03622026-03-23see CVE
CVE-2049-16098 0.00.00.0000see CVE

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-444 / 6667%
CM-639 / 6659%
AC-637 / 6656%
AC-336 / 6655%
AC-233 / 6650%
CM-233 / 6650%
CM-732 / 6648%
SI-330 / 6645%
AC-526 / 6639%
CM-524 / 6636%
IA-224 / 6636%
SI-723 / 6635%
CA-721 / 6632%
SC-720 / 6630%
AC-416 / 6624%

Co-occurring actors

None.

Similar actors

Same category