blackbyte logo

blackbyte

2 incidentes 0 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: Hecamede
Ver en IntelTracker → APTTrail →
BlackByte is a financially motivated ransomware-as-a-service (RaaS) operation that first emerged in July 2021, evolving rapidly from initial C# implementations to more sophisticated variants written in Go, .NET, and C++. The group is assessed with high confidence to be of Russian origin, given its observed avoidance of systems configured with Russian and certain Eastern European languages. BlackByte initially used a simple symmetric encryption key that allowed security researchers to develop a public decryptor, prompting the group to significantly update its encryption methods and implement a more robust BlackByte 2.0. This group distinguishes itself by continually incorporating newly disclosed vulnerabilities into its attack chains and offering unique, flexible extortion options to victims, such as paying to delay data publication or to download and destroy stolen information, beyond the standard double extortion model of data encryption and exfiltration. BlackByte is not known to ope
Malware asociado
Mimikatz
Tecnicas MITRE
T1518.001, T1036.008, T1543.003, T1505.003, T1543, T1140

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

United Arab EmiratesAnguillaArgentinaAustriaAustraliaBahrainBrazilBotswanaCanadaSwitzerland

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central BankRail TransportationSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodation

URLs nuevas detectadas en IntelTracker

github.com ransomware.anggipradana.com

Victimas (1)

Ransom Notes: blackbyte (4 notes from ThreatLabz)18 Jun 2026
Report
blackbyte - Ransom NotesEste grupo de ransomware tiene 4 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de res…