BlackByte
G10431 reportsAnalyst assessment — key judgments
- Signature techniques: T1590.005 (IP Addresses), T1059.007 (JavaScript), T1588.006 (Vulnerabilities).
- Primary targeting: US, KR, PK, CN.
- Activity declining: 0 report(s) in last 30d vs 1 prior (-100%).
- Hunt coverage 80% of 5 observed techniques (1 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
Movement — last 30 days
Vulnerabilities in this actor's reporting · 3
- CVE-2026-33825KEV1 rpt
- CVE-2026-50751KEV1 rpt
- CVE-2026-507521 rpt
Overview
BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)
ATT&CK technique matrix
- T1590.005 · IP Addressesconf 601
- T1059.007 · JavaScriptconf 601
- T1588.006 · Vulnerabilitiesconf 601
- T1195 · Supply Chain Compromiseconf 601
- T1176.002 · IDE Extensionsconf 601
Threat catalogue · engineering roadmap
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
Relationships
Activity
| Title | Source | Severity | Collected |
|---|