« All threats

APT groupMITRE G1043

BlackByte

Also known as: hecamede

BlackByte ransomware was first observed in July 2021 and operates as a Ransomware-as-a-Service (RaaS). It uses a double-extortion model—encrypting victim files while exfiltrating sensitive data for publication on its Tor-based leak site. The ransomware is written in C# and uses AES-256 for file encryption, with keys protected by RSA public-key encryption. Early variants exploited the ProxyShell vulnerability in Microsoft Exchange servers for initial access, but later campaigns have leveraged phishing, malicious attachments, and vulnerable internet-facing systems. BlackByte appends extensions such as .blackbyte or .blackbyte2.0 to encrypted files and leaves ransom notes (BlackByte_restoremyfiles.txt) instructing victims to contact them via Tor. The group has targeted organizations worldwide, including critical infrastructure, manufacturing, and government sectors. In February 2022, the FBI and USSS released a joint advisory warning about BlackByte’s impact and offering detection signatures.

Victims in the last 90 days0

Most affected countries

No data yet.

Most affected sectors

No data yet.

Priority mitigations

MITRE ATT&CK mitigations that cover the most techniques used by this group.

  1. Privileged Account Management (13 techniques covered)
  2. User Account Management (11 techniques covered)
  3. Operating System Configuration (8 techniques covered)
  4. Execution Prevention (8 techniques covered)
  5. Behavior Prevention on Endpoint (8 techniques covered)
  6. Audit (7 techniques covered)
  7. Network Intrusion Prevention (6 techniques covered)
  8. Filter Network Traffic (6 techniques covered)

MITRE ATT&CK techniques

T1082 · System Information DiscoveryT1016 · System Network Configuration DiscoveryT1046 · Network Service DiscoveryT1105 · Ingress Tool TransferT1482 · Domain Trust DiscoveryT1686 · Disable or Modify System FirewallT1036.008 · Masquerade File TypeT1053.005 · Scheduled TaskT1134.003 · Make and Impersonate TokenT1070.004 · File DeletionT1543.003 · Windows ServiceT1021.001 · Remote Desktop ProtocolT1685 · Disable or Modify ToolsT1614.001 · System Language DiscoveryT1560 · Archive Collected DataT1059.003 · Windows Command ShellT1136.002 · Domain AccountT1112 · Modify RegistryT1055.012 · Process HollowingT1491.001 · Internal DefacementT1071.001 · Web ProtocolsT1087.002 · Domain AccountT1570 · Lateral Tool TransferT1583.003 · Virtual Private ServerT1190 · Exploit Public-Facing ApplicationT1608.001 · Upload MalwareT1490 · Inhibit System RecoveryT1012 · Query RegistryT1059.001 · PowerShellT1041 · Exfiltration Over C2 ChannelT1569.002 · Service ExecutionT1135 · Network Share DiscoveryT1140 · Deobfuscate/Decode Files or InformationT1068 · Exploitation for Privilege EscalationT1505.003 · Web ShellT1078 · Valid AccountsT1567 · Exfiltration Over Web ServiceT1055 · Process InjectionT1021.002 · SMB/Windows Admin SharesT1078.002 · Domain AccountsT1547.001 · Registry Run Keys / Startup FolderT1480 · Execution GuardrailsT1486 · Data Encrypted for ImpactT1518.001 · Security Software DiscoveryT1219 · Remote Access ToolsT1047 · Windows Management InstrumentationT1018 · Remote System DiscoveryT1003 · OS Credential Dumping

Recent victims

No data yet.

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.