LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1043: BlackByte

BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.[1][2][3][4][5]

EnterpriseG1043GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

BlackByte is an ATT&CK-documented ransomware group, also known as Hecamede, operating since at least 2021 and associated with BlackByte ransomware variants and the Exbyte exfiltration tool. For leaders, the practical issue is not just malware encryption; the related behaviors show a ransomware intrusion pattern involving credential theft, discovery, lateral movement, remote execution, exfiltration, and eventual encryption. MITRE notes targeting of critical infrastructure entities among other North American targets, making this relevant to business continuity and operational resilience planning.

Executive priority

Treat this as a ransomware readiness use case: can the organization detect and contain credential compromise, lateral movement over RDP/SMB/WMI/PsExec, data exfiltration, and ransomware execution before recovery becomes the primary option? Priority decisions should focus on identity hardening, endpoint visibility, remote administration controls, vulnerability management for privilege escalation, segmentation, and tested incident response and recovery evidence. Because ATT&CK provides no official detection text for this group, executives should ask for proof of coverage against the related techniques and tools rather than a simple claim of “BlackByte detection.”

Technical view

The relationship set is heavily centered on Windows tradecraft: Mimikatz, PsExec, AdFind, BlackByte ransomware variants, Exbyte, PowerShell, Windows Command Shell, WMI, Scheduled Task, RDP, SMB/Admin Shares, Registry Query, credential dumping, process injection/process hollowing, discovery, exfiltration over C2, and exploitation for privilege escalation. SOC and IR teams should validate chained detections that connect credential access, Active Directory discovery, remote execution, lateral movement, outbound exfiltration behavior, and mass file modification/encryption activity. Because PsExec, AdFind, PowerShell, WMI, RDP, SMB, and scheduled tasks can be legitimate administration activity, detections should be tuned around abnormal users, hosts, timing, command lines, remote targets, privilege context, and sequence of events.

Likely telemetry

  • Endpoint process creation and command-line telemetry for PowerShell, cmd.exe, WMI, schtasks, PsExec-like execution, AdFind, registry queries, and discovery commands
  • Windows authentication, logon, RDP, SMB/admin share, and remote service activity logs
  • EDR signals for credential dumping, LSASS access, process injection, and process hollowing behavior
  • Active Directory query and enumeration activity associated with tools such as AdFind
  • Network flow, proxy, DNS, and egress logs for command-and-control and possible exfiltration to online file sharing or hosting services

Detection direction

  • Build behavior-chain analytics rather than relying only on malware names: credential dumping followed by discovery, remote execution, lateral movement, exfiltration, and encryption is higher fidelity than any single event.
  • Baseline legitimate administrative use of PsExec, WMI, PowerShell, RDP, SMB, scheduled tasks, and AdFind; alert on rare hosts, unusual operators, abnormal hours, or execution from non-admin workstations.
  • Correlate outbound data movement with prior discovery or file staging, especially where Exbyte-like behavior or transfers to file sharing/hosting services are plausible.
  • Validate visibility on remote execution and lateral movement paths; blind spots commonly occur where endpoint telemetry is missing on servers, RDP gateways, domain controllers, or file servers.
  • Use ATT&CK relationships to test coverage for T1003, T1021.001, T1021.002, T1047, T1053.005, T1059.001, T1059.003, T1041, T1068, T1055, and discovery techniques rather than claiming generic ransomware coverage.

Mitigation priorities

  • Prioritize identity controls: reduce standing privilege, protect credential material, monitor privileged logons, and restrict where administrative accounts can authenticate.
  • Restrict and monitor remote administration paths including RDP, SMB/admin shares, WMI, PsExec-style execution, PowerShell, and scheduled tasks.
  • Maintain vulnerability management focus on privilege escalation paths and newly disclosed vulnerabilities referenced in the source material, using exposure and asset criticality to prioritize remediation.
  • Segment critical servers, file shares, and operationally important systems to limit lateral movement and ransomware blast radius.
  • Prepare ransomware response evidence: tested backups, restore procedures, isolation playbooks, exfiltration triage, and executive decision paths for business continuity.
Additional notes and limits

This take is based on the ATT&CK group object for BlackByte G1043 and the supplied relationship context. The strongest defensive value comes from mapping the group to related tools and techniques: Mimikatz, PsExec, AdFind, Exbyte, BlackByte ransomware variants, credential dumping, discovery, lateral movement, remote execution, exfiltration, and ransomware behavior. The group object itself does not specify platforms or tactics, but many related software and techniques are Windows-focused.

MITRE provides no official detection guidance for this group object, and the supplied group fields do not specify platforms or tactics. Local conclusions require environment-specific telemetry, asset exposure, identity architecture, remote administration practices, and incident history. This summary does not assert current exploitation, customer exposure, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

BlackByte

BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.[1][2][3][4][5]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

48 rows
DomainIDNameRelationship / procedure
EnterpriseT1082System Information Discovery

BlackByte used various system commands and tools to pull system information during operations.[1][3][4]

EnterpriseT1016System Network Configuration Discovery

BlackByte used tools such as Arp to pull system network information and identify connected devices.[1][4]

EnterpriseT1046Network Service Discovery

BlackByte has used tools such as NetScan to enumerate network services in victim environments.[4]

EnterpriseT1105Ingress Tool Transfer

BlackByte has transferred tools such as Cobalt Strike to victim environments from file sharing and hosting websites.[4]

EnterpriseT1482Domain Trust Discovery

BlackByte enumerated Active Directory information and trust relationships during operations.[1][4]

EnterpriseT1686Disable or Modify System Firewall

BlackByte modified firewall rules on victim machines to enable remote system discovery.[2][3]

EnterpriseT1036.008Masquerade File TypeSub-technique

BlackByte masqueraded configuration files containing encryption keys as PNG files.[1]

EnterpriseT1053.005Scheduled TaskSub-technique

BlackByte created scheduled tasks for payload execution.[1][2]

EnterpriseT1134.003Make and Impersonate TokenSub-technique

BlackByte constructed a valid authentication token following Microsoft Exchange exploitation to allow for follow-on privileged command execution.[4]

EnterpriseT1070.004File DeletionSub-technique

BlackByte deleted ransomware executables post-encryption.[2][3][4][5]

EnterpriseT1543.003Windows ServiceSub-technique

BlackByte modified multiple services on victim machines to enable encryption operations.[3] BlackByte has installed tools such as AnyDesk as a service on victim machines.[4]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

BlackByte has used RDP to access other hosts within victim networks.[4][5]

EnterpriseT1685Disable or Modify Tools

BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.[1][2][5]

EnterpriseT1614.001System Language DiscoverySub-technique

BlackByte identified system language settings to determine follow-on execution.[2]

EnterpriseT1560Archive Collected Data

BlackByte compressed data collected from victim environments prior to exfiltration.[2]

EnterpriseT1059.003Windows Command ShellSub-technique

BlackByte executed ransomware using the Windows command shell.[1]

EnterpriseT1136.002Domain AccountSub-technique

BlackByte created privileged domain accounts during intrusions.[5]

EnterpriseT1112Modify Registry

BlackByte performed Registry modifications to escalate privileges and disable security tools.[2][5]

EnterpriseT1055.012Process HollowingSub-technique

BlackByte used process hollowing for defense evasion purposes.[4]

EnterpriseT1491.001Internal DefacementSub-technique

BlackByte left ransom notes in all directories where encryption takes place.[1]

EnterpriseT1071.001Web ProtocolsSub-technique

BlackByte collected victim device information then transmitted this via HTTP POST to command and control infrastructure.[4]

EnterpriseT1087.002Domain AccountSub-technique

BlackByte has used tools such as AdFind to identify and enumerate domain accounts.[4]

EnterpriseT1570Lateral Tool Transfer

BlackByte transfered tools such as Cobalt Strike and the AnyDesk remote access tool during operations using SMB shares.[2]

EnterpriseT1583.003Virtual Private ServerSub-technique

BlackByte staged encryption keys on virtual private servers operated by the adversary.[1]

EnterpriseT1190Exploit Public-Facing Application

BlackByte exploited vulnerabilities such as ProxyLogon and ProxyShell for initial access to victim environments.[1][2][3][4]

EnterpriseT1608.001Upload MalwareSub-technique

BlackByte has staged tools such as Cobalt Strike at public file sharing and hosting sites.[4]

EnterpriseT1490Inhibit System Recovery

BlackByte resized and deleted volume shadow copy files to prevent system recovery after encryption.[2][3]

EnterpriseT1012Query Registry

BlackByte queried registry values to determine system language settings.[2]

EnterpriseT1059.001PowerShellSub-technique

BlackByte used encoded PowerShell commands during operations.[1] BlackByte has used remote PowerShell commands in victim networks.[4]

EnterpriseT1041Exfiltration Over C2 Channel

BlackByte transmitted collected victim host information via HTTP POST to command and control infrastructure.[4]

EnterpriseT1003OS Credential Dumping

BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems.[2][4]

EnterpriseT1569.002Service ExecutionSub-technique

BlackByte created malicious services for ransomware execution.[3][5]

EnterpriseT1135Network Share Discovery

BlackByte enumerated network shares on victim devices.[5]

EnterpriseT1140Deobfuscate/Decode Files or Information

BlackByte has encoded commands in base64-encoded sections concatenated together in PowerShell.[1] BlackByte uses PowerShell commands to disable Windows Defender.[2]

EnterpriseT1068Exploitation for Privilege Escalation

BlackByte has exploited CVE-2024-37085 in VMWare ESXi software for authentication bypass and subsequent privilege escalation.[5]

EnterpriseT1505.003Web ShellSub-technique

BlackByte has used ASPX web shells following exploitation of vulnerabilities in services such as Microsoft Exchange.[2][4]

EnterpriseT1078Valid Accounts

BlackByte has gained access to victim environments through legitimate VPN credentials.[5]

EnterpriseT1567Exfiltration Over Web Service

BlackByte has used services such as `anonymfiles.com` and `file.io` to exfiltrate victim data.[2]

EnterpriseT1055Process Injection

BlackByte has injected Cobalt Strike into `wuauclt.exe` during intrusions.[2] BlackByte has injected ransomware into `svchost.exe` before encryption.[3]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations.[2][4][5]

EnterpriseT1078.002Domain AccountsSub-technique

BlackByte captured credentials for or impersonated domain administration users.[4][5]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

BlackByte has used Registry Run keys for persistence.[4]

EnterpriseT1480Execution Guardrails

BlackByte stopped execution if identified language settings on victim machines was Russian or one of several language associated with former Soviet republics.[2] BlackByte has used ransomware variants requiring a key passed on the command line for the malware to execute.[5]

EnterpriseT1486Data Encrypted for Impact

BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim.[1][2][3][4][5]

EnterpriseT1518.001Security Software DiscoverySub-technique

BlackByte enumerated installed security products during operations.[4]

EnterpriseT1219Remote Access Tools

BlackByte has used tools such as AnyDesk in victim environments.[2][4]

EnterpriseT1047Windows Management Instrumentation

BlackByte used WMI to delete Volume Shadow Copies on victim machines.[1]

EnterpriseT1018Remote System Discovery

BlackByte used tools such as Arp to identify remotely-connected devices.[1][2]

Associated objects

Groups, software, and campaigns

MalwareEnterprise

S1179: Exbyte

Exbyte is an exfiltration tool written in Go that is uniquely associated with BlackByte operations. Observed since 2022, Exbyte transfers collected files to online file sharing and hosting services.[1]

Windows
ToolEnterprise

S0099: Arp

Arp displays and modifies information about a system's Address Resolution Protocol (ARP) cache. [1]

LinuxWindowsmacOS
ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
MalwareEnterprise

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

LinuxmacOSWindows
ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
5c1d7978260475db...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle5c1d79782604…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  2. [2]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  3. [3]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  4. [4]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  5. [5]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  6. [6]
    Trustwave BlackByte 2021

    Rodel Mendrez & Lloyd Macrohon. (2021, October 15). BlackByte Ransomware – Pt. 1 In-depth Analysis. Retrieved December 16, 2024.

    Open source URL
  7. [7]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  8. [8]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  9. [9]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  10. [10]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  11. [11]
    Hecamede

    (Citation: Symantec BlackByte 2022)

  12. [12]
    Hecamede

    (Citation: Symantec BlackByte 2022)

  13. [13]
    Hecamede

    (Citation: Symantec BlackByte 2022)

  14. [14]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  15. [15]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  16. [16]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  17. [17]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  18. [18]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  19. [19]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  20. [20]
    mitre-attackG1043
    Open source URL
  21. [21]
    mitre-attackG1043
    Open source URL
  22. [22]
    mitre-attackG1043
    Open source URL
  23. [23]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  24. [24]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  25. [25]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  26. [26]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  27. [27]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  28. [28]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  29. [29]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  30. [30]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  31. [31]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  32. [32]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  33. [33]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  34. [34]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  35. [35]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  36. [36]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  37. [37]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  38. [38]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  39. [39]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  40. [40]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  41. [41]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  42. [42]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  43. [43]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  44. [44]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  45. [45]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  46. [46]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  47. [47]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  48. [48]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  49. [49]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  50. [50]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  51. [51]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  52. [52]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  53. [53]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  54. [54]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  55. [55]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  56. [56]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  57. [57]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  58. [58]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  59. [59]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  60. [60]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  61. [61]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  62. [62]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  63. [63]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  64. [64]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  65. [65]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  66. [66]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  67. [67]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  68. [68]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  69. [69]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  70. [70]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  71. [71]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  72. [72]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  73. [73]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  74. [74]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  75. [75]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  76. [76]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  77. [77]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  78. [78]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  79. [79]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  80. [80]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  81. [81]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  82. [82]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  83. [83]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  84. [84]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  85. [85]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  86. [86]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  87. [87]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  88. [88]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  89. [89]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  90. [90]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  91. [91]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  92. [92]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  93. [93]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  94. [94]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  95. [95]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  96. [96]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  97. [97]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  98. [98]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  99. [99]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  100. [100]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  101. [101]
    Trustwave BlackByte 2021

    Rodel Mendrez & Lloyd Macrohon. (2021, October 15). BlackByte Ransomware – Pt. 1 In-depth Analysis. Retrieved December 16, 2024.

    Open source URL
  102. [102]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  103. [103]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  104. [104]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  105. [105]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  106. [106]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  107. [107]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  108. [108]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  109. [109]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  110. [110]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  111. [111]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  112. [112]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  113. [113]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  114. [114]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  115. [115]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  116. [116]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  117. [117]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  118. [118]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  119. [119]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  120. [120]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  121. [121]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  122. [122]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  123. [123]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  124. [124]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  125. [125]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  126. [126]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  127. [127]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  128. [128]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  129. [129]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  130. [130]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  131. [131]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  132. [132]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  133. [133]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  134. [134]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  135. [135]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  136. [136]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  137. [137]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  138. [138]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  139. [139]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  140. [140]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  141. [141]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  142. [142]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  143. [143]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  144. [144]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  145. [145]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  146. [146]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  147. [147]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  148. [148]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  149. [149]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  150. [150]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  151. [151]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  152. [152]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  153. [153]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  154. [154]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  155. [155]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  156. [156]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  157. [157]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  158. [158]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  159. [159]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  160. [160]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  161. [161]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  162. [162]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  163. [163]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  164. [164]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  165. [165]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  166. [166]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  167. [167]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  168. [168]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  169. [169]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  170. [170]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  171. [171]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  172. [172]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  173. [173]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  174. [174]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  175. [175]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  176. [176]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  177. [177]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  178. [178]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  179. [179]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  180. [180]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  181. [181]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  182. [182]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  183. [183]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  184. [184]
    Cisco BlackByte 2024

    James Nutland, Craig Jackson, Terryn Valikodath, & Brennan Evans. (2024, August 28). BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks. Retrieved December 16, 2024.

    Open source URL
  185. [185]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  186. [186]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  187. [187]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  188. [188]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  189. [189]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  190. [190]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  191. [191]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  192. [192]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  193. [193]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  194. [194]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  195. [195]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.