BlackByte 2.0 is a ransomware variant associated with the BlackByte operation. The provided content states that it injects into a newly created svchost.exe process prior to device encryption and may execute as a service when deployed. When run as a service, it exploits the vulnerable RTCore64.sys driver (CVE-2019-16098) to achieve privilege escalation and defense evasion. It also modifies the Windows Registry to allow elevated execution, modifies the Windows firewall during execution, and alters volume shadow copies in a way that destroys them on the victim machine, inhibiting recovery. For defense evasion and anti-forensics, it can timestomp files, and after encryption it deletes itself. The malware can also identify network shares connected to the victim machine, indicating capability to discover additional accessible storage for impact.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
BlackByte 2.0 Ransomware exploits a vulnerability in the RTCore64.sys driver (CVE-2019-16098) to enable privilege escalation and defense evasion when run as a service.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BlackByte 2.0 Ransomware exploits a vulnerability in the RTCore64.sys driver (CVE-2019-16098) to enable privilege escalation and defense evasion when run as a service.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes adversaries and malware injecting code, shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, wuauclt.exe, lsass.exe, and browser processes.
GuLoader has the ability to inject shellcode into donor processes that is started in a suspended state. Cardinal RAT injects into a newly spawned process created from a native Windows executable. Pandora can start and inject code into a new svchost process. ShadowPad has injected an install module into a newly created process.
The content repeatedly describes adversaries and malware injecting code, shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, wuauclt.exe, lsass.exe, and browser processes.
GuLoader has the ability to inject shellcode into donor processes that is started in a suspended state. Cardinal RAT injects into a newly spawned process created from a native Windows executable. Pandora can start and inject code into a new svchost process. ShadowPad has injected an install module into a newly created process.
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
Multiple ransomware families and actors are described as encrypting victim filesystems/drives for extortion (e.g., Akira, Conti, Ryuk, WannaCry, NotPetya, etc.), often appending new extensions and dropping ransom notes.
Multiple ransomware/wiper families are described as deleting Volume Shadow Copies and other recovery artifacts using built-in Windows tooling (e.g., vssadmin.exe delete shadows /all /quiet, wmic.exe shadowcopy delete, wbadmin.exe delete catalog -quiet) and disabling recovery (e.g., bcdedit /set {default} recoveryenabled no).
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware variant with timestomping capability for defense evasion and anti-forensics.
Ransomware variant that injects into a newly created svchost.exe process before encrypting devices.
Ransomware variant that changes Windows Firewall settings as part of execution.
Ransomware variant that leverages a vulnerable driver (RTCore64.sys) for privilege escalation and defense evasion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.