{
  "modified": "2025-03-09T15:58:36.918Z",
  "name": "BlackByte",
  "description": "[BlackByte](https://attack.mitre.org/groups/G1043) is a ransomware threat actor operating since at least 2021. [BlackByte](https://attack.mitre.org/groups/G1043) is associated with several versions of ransomware also labeled [BlackByte Ransomware](https://attack.mitre.org/software/S1180). [BlackByte](https://attack.mitre.org/groups/G1043) ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as [BlackByte 2.0 Ransomware](https://attack.mitre.org/software/S1181) use more robust encryption mechanisms. [BlackByte](https://attack.mitre.org/groups/G1043) is notable for operations targeting critical infrastructure entities among other targets across North America.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)",
  "aliases": [
    "BlackByte",
    "Hecamede"
  ],
  "x_mitre_deprecated": false,
  "x_mitre_version": "1.0",
  "x_mitre_contributors": [
    "Kaung Zaw Hein"
  ],
  "type": "intrusion-set",
  "spec_version": "2.1",
  "id": "intrusion-set--02b16bd6-ae88-417a-8a3f-02c5e166175a",
  "created": "2024-12-16T23:19:40.207Z",
  "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
  "revoked": false,
  "external_references": [
    {
      "source_name": "mitre-attack",
      "url": "https://attack.mitre.org/groups/G1043",
      "external_id": "G1043"
    },
    {
      "source_name": "Hecamede",
      "description": "(Citation: Symantec BlackByte 2022)"
    },
    {
      "source_name": "Picus BlackByte 2022",
      "description": "Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.",
      "url": "https://www.picussecurity.com/resource/ttps-used-by-blackbyte-ransomware-targeting-critical-infrastructure"
    },
    {
      "source_name": "Cisco BlackByte 2024",
      "description": "James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.",
      "url": "https://blog.talosintelligence.com/blackbyte-blends-tried-and-true-tradecraft-with-newly-disclosed-vulnerabilities-to-support-ongoing-attacks/"
    },
    {
      "source_name": "Microsoft BlackByte 2023",
      "description": "Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.",
      "url": "https://www.microsoft.com/en-us/security/blog/2023/07/06/the-five-day-job-a-blackbyte-ransomware-intrusion-case-study/"
    },
    {
      "source_name": "Symantec BlackByte 2022",
      "description": "Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.",
      "url": "https://www.security.com/threat-intelligence/blackbyte-exbyte-ransomware"
    },
    {
      "source_name": "FBI BlackByte 2022",
      "description": "US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.",
      "url": "https://www.ic3.gov/CSA/2022/220211.pdf"
    }
  ],
  "object_marking_refs": [
    "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
  ],
  "x_mitre_attack_spec_version": "3.2.0",
  "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
  "x_mitre_domains": [
    "enterprise-attack"
  ]
}