BlackByte
Also reported as Hecamede.
Reports per quarter
Techniques seen in the last two years
- T1555.003 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2016-0099 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-3506 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-13374 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-8872
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-11510 KEV ransomware
Show all 91 CVEs Show fewer
- CVE-2019-11634 KEV ransomware
- CVE-2019-16098
- CVE-2019-5591 KEV ransomware
- CVE-2019-6693 KEV ransomware
- CVE-2019-7481 KEV ransomware
- CVE-2020-12271 KEV ransomware
- CVE-2020-12812 KEV ransomware
- CVE-2020-1472 KEV ransomware
- CVE-2020-15782
- CVE-2020-36198
- CVE-2020-5135 KEV ransomware
- CVE-2020-8195 KEV
- CVE-2020-8196 KEV
- CVE-2020-8234
- CVE-2020-8260 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-20016 KEV ransomware
- CVE-2021-20655
- CVE-2021-2198
- CVE-2021-22893 KEV ransomware
- CVE-2021-22941 KEV ransomware
- CVE-2021-22986 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-2701
- CVE-2021-27065 KEV ransomware
- CVE-2021-2710
- CVE-2021-27101 KEV ransomware
- CVE-2021-27102 KEV ransomware
- CVE-2021-27103 KEV ransomware
- CVE-2021-27104 KEV ransomware
- CVE-2021-28799 KEV ransomware
- CVE-2021-31166 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34481
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-36942 KEV ransomware
- CVE-2021-36958
- CVE-2021-38647 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2022-1388 KEV ransomware
- CVE-2022-22954 KEV ransomware
- CVE-2022-22960 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-40684 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-20269 KEV ransomware
- CVE-2023-22515 KEV ransomware
- CVE-2023-22518 KEV ransomware
- CVE-2023-27350 KEV ransomware
- CVE-2023-27351 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-34048 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-40044 KEV ransomware
- CVE-2023-42793 KEV ransomware
- CVE-2023-46604 KEV ransomware
- CVE-2023-47246 KEV ransomware
- CVE-2023-4911 KEV
- CVE-2023-4966 KEV ransomware
- CVE-2023-50164
- CVE-2024-37085 KEV ransomware
- CVE-2024-4577 KEV ransomware
- CVE-2049-16098
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BlackCat (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Clop (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Conti (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor HelloKitty (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor LockBit (Malware Family)
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor watchtower-2023-eoy-report-en
Show all 47 reports Show fewer
-
Back in Black- BlackByte Ransomware returns with its New Technology (NT) version
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Back in Black- BlackByte Ransomware returns with its New Technology (NT) version
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
Exbyte- BlackByte Ransomware Attackers Deploy New Exfiltration Tool
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exbyte- BlackByte Ransomware Attackers Deploy New Exfiltration Tool
-
Remove All The Callbacks – BlackByte Ransomware Disables EDR Via RTCore64.sys Abuse
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Remove All The Callbacks – BlackByte Ransomware Disables EDR Via RTCore64.sys Abuse
-
Climbing Mount Everest- Black-Byte Bytes Back-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Climbing Mount Everest- Black-Byte Bytes Back-
-
Ransomware Spotlight- BlackByte
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Spotlight- BlackByte
-
The hateful eight- Kaspersky’s guide to modern ransomware groups’ TTPs (Download Form)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The hateful eight- Kaspersky’s guide to modern ransomware groups’ TTPs (Download Form)
-
An In-Depth Look At Black Basta Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An In-Depth Look At Black Basta Ransomware
-
DisCONTInued The End of Contis Brand Marks New Chapter For Cybercrime Landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DisCONTInued The End of Contis Brand Marks New Chapter For Cybercrime Landscape
-
The BlackByte ransomware group is striking users all over the globe
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The BlackByte ransomware group is striking users all over the globe
-
Hydra with Three Heads- BlackByte & The Future of Ransomware Subsidiary Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hydra with Three Heads- BlackByte & The Future of Ransomware Subsidiary Groups
-
Analysis of BlackByte Ransomware's Go-Based Variants
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of BlackByte Ransomware's Go-Based Variants
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Threat Report 2022
-
Trellix Global Defenders- Analysis and Protections for BlackByte Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Trellix Global Defenders- Analysis and Protections for BlackByte Ransomware
-
TTPs used by BlackByte Ransomware Targeting Critical Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TTPs used by BlackByte Ransomware Targeting Critical Infrastructure
-
FBI- BlackByte ransomware breached US critical infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FBI- BlackByte ransomware breached US critical infrastructure
-
ProxyShell exploitation leads to BlackByte ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ProxyShell exploitation leads to BlackByte ransomware
-
Understanding the Windows JavaScript Threat Landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Understanding the Windows JavaScript Threat Landscape
-
BlackByte Ransomware – Pt 2. Code Obfuscation Analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BlackByte Ransomware – Pt 2. Code Obfuscation Analysis
-
BlackByte Ransomware – Pt. 1 In-depth Analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BlackByte Ransomware – Pt. 1 In-depth Analysis
Newest first. Details opens the report in Explore.