BlackByte emerged as a ransomware-as-a-service operation targeting Windows environments across critical infrastructure and other sectors, with victims reported in government facilities, finance, food and agriculture, and broad industry verticals worldwide. U.S. authorities said some intrusions began with exploitation of a Microsoft Exchange vulnerability, while other reporting tied initial access to phishing and ProxyShell activity. Once inside, BlackByte operators and affiliates used lateral movement, privilege escalation, scheduled tasks, remote execution, and data theft before encrypting systems and threatening publication on leak sites, with activity concentrated heavily in North America and Europe and notable interest in Latin American targets.
Technical analyses show the group rapidly improved its malware after early versions exposed a major weakness: some samples fetched a disguised forest.png key file from hardcoded infrastructure and reused the same symmetric key across victims, enabling decryption in certain cases. Later BlackByte variants shifted from C# to Go, strengthened cryptography from earlier AES/RSA-based approaches to Curve25519 and ChaCha20, and expanded capabilities including process and service termination, shadow-copy deletion, Defender exclusion changes, AMSI evasion, worm-like propagation through Active Directory and SMB, process injection, and so-called print bombing. Researchers and government agencies also documented use of tools such as AnyDesk, WinRAR, certutil, vssadmin, and network scanners, underscoring BlackByte’s progression into a more resilient and operationally mature extortion platform.

TTPs, infrastructure, and targeting history in one profile.
12 events from the most recent confirmed update back to the earliest known activity.
On October 21, 2022, Symantec reported that at least one BlackByte affiliate was deploying a custom Go-based exfiltration tool named Exbyte to steal victim documents and upload them to Mega.co.nz. The report also detailed recent BlackByte 2.0 intrusion tradecraft, including Exchange ProxyShell and ProxyLogon exploitation, anti-analysis checks, and EDR-evasion behavior.
On May 18, 2022, Cisco Talos reported that BlackByte had been active globally, with attacks observed since March and victims across North America, Colombia, the Netherlands, China, Mexico, and Vietnam. The report detailed initial access via phishing, SonicWall VPNs, and Exchange ProxyShell, along with use of AnyDesk, PsExec, netscanold, defense-disabling behavior, and delayed ransomware deployment ending with the BlackByteRestore.txt note.
Reports in May 2022 indicated BlackByte was among ransomware operations targeting Latin American governments, and operators reportedly claimed a compromise of a Peruvian government entity.
In May 2022, Trend Micro observed a sharp increase in BlackByte detections affecting the government sector compared with earlier telemetry trends.
Trend Micro telemetry showed a drastic increase in BlackByte detections in May 2022 after relatively consistent activity from October 2021 through March 2022.
On February 11, 2022, the FBI and U.S. Secret Service released a joint advisory describing BlackByte tradecraft, victim sectors, indicators of compromise, and mitigation guidance.
A more feature-rich Go-based BlackByte v2 appeared around February 2022, introducing updated encryption including Curve25519 and ChaCha20.
As of November 2021, BlackByte had compromised multiple U.S. and foreign businesses, including victims in the government facilities, financial, and food and agriculture sectors.
On October 15, 2021, Trustwave SpiderLabs published an in-depth analysis of BlackByte and released a GitHub decryptor based on a key-reuse flaw involving the downloaded "forest.png" file.
BlackByte was redeveloped from an earlier C# implementation into a Go-based variant observed around September 2021, marking a notable evolution in the malware family.
BlackByte first emerged around July 2021 as a ransomware operation, later described as operating under a ransomware-as-a-service model.
On October 19, 2021, SpiderLabs updated its BlackByte decryptor repository to add a compiled executable and a sample encrypted file for testing.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 45 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourcezscaler.com
Open sourceadvintel.io
Open sourcesymantec-enterprise-blogs.security.com
Open sourceblog.talosintelligence.com
Open sourcebleepingcomputer.com
Open sourcetrustwave.com
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.