BlackByte is a Windows ransomware family and ransomware-as-a-service operation first publicly identified in 2021. It has been associated with enterprise-focused intrusions that combine data theft and file encryption, and multiple variants have been observed over time. BlackByte operators and affiliates have used double-extortion tactics, including exfiltrating victim data prior to encryption and threatening publication on leak infrastructure. More mature activity linked to the ecosystem has also included use of a custom exfiltration utility known as Exbyte.
Observed BlackByte intrusions show hands-on-keyboard tradecraft after initial compromise. In documented cases, operators gained access by exploiting Microsoft Exchange ProxyShell vulnerabilities, deployed web shells, used Cobalt Strike for command and control, dumped credentials, installed remote access software, and moved laterally over SMB and administrative shares before launching the ransomware. BlackByte has also been linked to campaigns using valid accounts and remote access pathways such as RDP in broader ransomware activity.
The malware and its operators have demonstrated extensive post-compromise behavior intended to maximize impact and hinder recovery. Reported actions include process injection, privilege-enabling system changes, Active Directory and network reconnaissance, enabling file-sharing-related firewall rules, deleting shadow copies, disabling or tampering with security tools, and modifying Windows Registry settings associated with lateral movement and execution. BlackByte has been observed injecting Cobalt Strike into legitimate Windows processes during intrusions and injecting the ransomware into another legitimate process prior to encryption. Some reporting also links BlackByte activity to bring-your-own-vulnerable-driver tradecraft through abuse of a vulnerable graphics-related driver to impair defenses.
BlackByte primarily targets Windows enterprise environments. Victimology in available reporting is consistent with opportunistic financially motivated ransomware operations affecting organizations rather than consumers, including mid-market and larger enterprises. The operation is notable for combining conventional ransomware deployment with defense evasion, credential abuse, lateral movement, and exfiltration, making it representative of modern multi-stage ransomware intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The following analytic detects when su runs from a page-cache-corrupted binary... This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access... CVE CVE-2026-31431 ... References ... copy-fail-CVE-2026-31431
BlackByte operators gained initial access by exploiting the ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) present on the customer’s Microsoft Exchange server... ProxyShell exploitation allows an adversary to gain pre-authentication remote code execution. | BlackByte ransomware was first publicly identified in a July 2021 BleepingComputer forum post from a user seeking help decrypting their encrypted files.
BlackByte operators gained initial access by exploiting the ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) present on the customer’s Microsoft Exchange server. | BlackByte ransomware was first publicly identified in a July 2021 BleepingComputer forum post from a user seeking help decrypting their encrypted files.
BlackByte operators gained initial access by exploiting the ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) present on the customer’s Microsoft Exchange server. | BlackByte ransomware was first publicly identified in a July 2021 BleepingComputer forum post from a user seeking help decrypting their encrypted files.
These events may indicate attempts to exploit the VMware ESXi Active Directory Integration Authentication Bypass vulnerability (CVE-2024-37085).
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
Associated Analytic Story BlackByte Ransomware ... Citrix ShareFile RCE CVE-2023-24489 ...
The following analytic detects attempts to exploit the Baron Samedit vulnerability (CVE-2021-3156) by identifying the use of the "sudoedit -s \" command.
The following analytic identifies remote code execution (RCE) attempts targeting F5 BIG-IP, BIG-IQ, and Traffix SDC devices, specifically exploiting CVE-2020-5902.
The following analytic detects suspicious process access by spoolsv.exe, potentially indicating exploitation of the PrintNightmare vulnerability (CVE-2021-34527).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BlackByte queried registry values to determine system language settings.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Further analysis revealed that Fox Tempest expanded its offerings earlier this year by providing customers with pre-configured virtual machines hosted through Cloudzy infrastructure. Users could upload malware to these systems and receive digitally signed binaries generated through certificates controlled by the group.
BlackByte ... sets a scheduled task to perform a print bombing technique, which causes all connected printers to physically print ransom notes upon execution of the task (T1053.005 Scheduled Task/Job: Scheduled Task).
BlackByte ... sets a scheduled task to perform a print bombing technique, which causes all connected printers to physically print ransom notes upon execution of the task (T1053.005 Scheduled Task/Job: Scheduled Task).
BlackByte set three different registry values to escalate privileges and begin setting the stage for lateral movement and encryption ... (T1112 Modify Registry).
The adversary remotely created a draft email with an attachment saved in the user’s Drafts folder... exported the entire mailbox to a PST file format, with an ASPX extension... writing an ASPX file to the folder ...\owa\auth\current\themes (T1505.003 Server Software Component: Web Shell).
“Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer… replaced the ImagePath registry value of a Windows service with a new backdoor binary… [multiple groups/malware] creating a service / installing as a service / modifying service configurations for persistence.”
BlackByte ... sets a scheduled task to perform a print bombing technique, which causes all connected printers to physically print ransom notes upon execution of the task (T1053.005 Scheduled Task/Job: Scheduled Task).
Annotations ID Technique Tactic T1055 Process Injection Privilege Escalation
BYOVD (Bring Your Own Vulnerable Driver) is a class of attack in which threat actors drop known vulnerable drivers on a compromised machine and then exploit the bug(s) to gain kernel-level privileges.
“Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer… replaced the ImagePath registry value of a Windows service with a new backdoor binary… [multiple groups/malware] creating a service / installing as a service / modifying service configurations for persistence.”
"...compiled code is obfuscated... prior to delivery..." / "...Base64 obfuscated scripts and commands." / "...distributed as an obfuscated JavaScript launcher file."
The sample was UPX-packed ... (T1027.002 Obfuscated Files or Information: Software Packing).
During the 2016 Ukraine Electric Power Attack, Sandworm Team masqueraded executables as .txt files.
Kapeka masquerades as a Microsoft Word Add-In file, with the extension .wll, but is a malicious DLL file.
Annotations ID Technique Tactic T1055 Process Injection Privilege Escalation
BlackByte set three different registry values to escalate privileges and begin setting the stage for lateral movement and encryption ... (T1112 Modify Registry).
Microsoft has announced the disruption of a large-scale malware-signing-as-a-service (MSaaS) operation that exploited its Azure Artifact Signing platform to generate fraudulent code-signing certificates... The group allegedly abused Microsoft's Artifact Signing service to create short-lived digital certificates that allowed malware to appear legitimate to both users and operating systems.
BlackByte executed hundreds of reconnaissance and system discovery commands including net view and arp -a (T1018 Remote System Discovery, T1016 System Network Configuration Discovery).
BlackByte executed hundreds of reconnaissance and system discovery commands including net view and arp -a (T1018 Remote System Discovery, T1016 System Network Configuration Discovery).
Multiple malware families (e.g., Avaddon, Bazar, Clop, Ryuk, REvil, LockBit, Zeus Panda) check OS language/keyboard layout/locale and terminate or alter execution if the system matches excluded languages (commonly Russian/CIS) or does not match desired target languages (e.g., Spanish/Portuguese, Arabic, Persian).
Several other ransomware variants use the print bombing technique... For more detailed information about the encryption process... (T1486 Data Encrypted for Impact).
At this level of access, attackers can accomplish a lot: hide malware, dump credentials, and, crucially, attempt to disable EDR solutions.
BlackByte deletes Task Manager (taskmgr) and Resource Monitor (resmon), and issues an obfuscated PowerShell command to stop the Windows Defender service (WinDefend) (T1562.001 Impair Defenses: Disable or Modify Tools)... Next, BlackByte issued commands to delete the scheduled task “Raccine Rules Updater” disable the SQLTELEMETRY service (T1562.001 Impair Defenses: Disable or Modify Tools).
BlackByte then conducted network reconnaissance and system preparation prior to lateral movement within the environment. BlackByte executed two netsh advfirewall firewall commands to enable the “Network Discovery” and “File and Printer Sharing” rule groups (T1562.004 Impair Defenses: Disable or Modify System Firewall).
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
110 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family mentioned as an example of malware associated with multivector attacks where DDoS is used as a smokescreen.
Annotations ID Technique Tactic T1055 Process Injection Privilege Escalation APT37 APT38 APT41 APT5 AppleJeus BlackByte Cobalt Group Gamaredon Group Kimsuky PLATINUM Sandworm Team Silence TA2541 Turla UNC3886 Velvet Ant Wizard Spider
Annotations ID Technique Tactic T1055 Process Injection Privilege Escalation APT37 APT38 APT41 APT5 AppleJeus BlackByte Cobalt Group...
Annotations ID Technique Tactic T1055 Process Injection Privilege Escalation APT37 APT38 APT41 APT5 AppleJeus BlackByte Cobalt Group ...
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.