Blackbyte

Compare
blackbyte logo blackbyte logo
Parsing: enabled Known RaaS

View crypto

Description

BlackByte ransomware was first observed in July 2021 and operates as a Ransomware-as-a-Service (RaaS). It uses a double-extortion model—encrypting victim files while exfiltrating sensitive data for publication on its Tor-based leak site. The ransomware is written in C# and uses AES-256 for file encryption, with keys protected by RSA public-key encryption. Early variants exploited the ProxyShell vulnerability in Microsoft Exchange servers for initial access, but later campaigns have leveraged phishing, malicious attachments, and vulnerable internet-facing systems. BlackByte appends extensions such as .blackbyte or .blackbyte2.0 to encrypted files and leaves ransom notes (BlackByte_restoremyfiles.txt) instructing victims to contact them via Tor. The group has targeted organizations worldwide, including critical infrastructure, manufacturing, and government sectors. In February 2022, the FBI and USSS released a joint advisory warning about BlackByte’s impact and offering detection signatures.

External Analysis18
External Analysis
https://blog.talosintelligence.com/2022/05/the-blackbyte-ransomware-group-is.html
https://de.darktrace.com/blog/detecting-the-unknown-revealing-uncategorised-ransomware-using-darktrace
https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2022/06/23093553/Common-TTPs-of-the-modern-ransomware_low-res.pdf
https://redcanary.com/blog/blackbyte-ransomware/
https://research.nccgroup.com/2022/07/13/climbing-mount-everest-black-byte-bytes-back/
https://securelist.com/modern-ransomware-groups-ttps/106824/
https://therecord.media/san-francisco-49ers-confirm-ransomware-attack/
https://www.advintel.io/post/discontinued-the-end-of-conti-s-brand-marks-new-chapter-for-cybercrime-landscape
https://www.advintel.io/post/enter-karakurt-data-extortion-arm-of-prolific-ransomware-group
https://www.advintel.io/post/hydra-with-three-heads-blackbyte-the-future-of-ransomware-subsidiary-groups
https://www.bleepingcomputer.com/news/security/fbi-blackbyte-ransomware-breached-us-critical-infrastructure/
https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-hacked-to-deploy-hive-ransomware/
https://www.deepinstinct.com/blog/understanding-the-windows-javascript-threat-landscape
https://www.ic3.gov/Media/News/2022/220211.pdf
https://www.picussecurity.com/resource/ttps-used-by-blackbyte-ransomware-targeting-critical-infrastructure
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/trellix-global-defenders-analysis-and-protections-for-blackbyte-ransomware.html
https://www.trendmicro.com/vinfo/my/security/news/ransomware-spotlight/ransomware-spotlight-blackbyte
https://www.zscaler.com/blogs/security-research/analysis-blackbyte-ransomwares-go-based-variants
Ransom notes4
Mail1
Mail
BlackBCruxSupport@onionmail.org
Urls7
Url
Status
Screen
Uptime 30d
Health
http://6iaj3efye3q62xjgfxyegrufhewxew7yt4scxjd45tlfafyja6q4ctqd.onion Down
http://f5uzduboq4fa2xkjloprmctk7ve3dm46ff7aniis66cbekakvksxgeqd.onion Down
http://dlyo7r3n4qy5fzv4645nddjwarj7wjdd6wzckomcyc7akskkxp4glcad.onion Down
http://fl3xpz5bmgzxy4fmebhgsbycgnz24uosp3u4g33oiln627qq3gyw37ad.onion Down
http://jbeg2dct2zhku6c2vwnpxtm2psnjo2xnqvvpoiiwr5hxnc6wrp3uhnad.onion/ Down Screen
http://53d5skw4ypzku4bfq2tk2mr3xh5yqrzss25sooiubmjz67lb3gdivcad.onion/ Down Screen
0%
http://ce6roic2ykdjunyzazsxmjpz5wsar4pflpoqzntyww5c2eskcp7dq4yd.onion/ Down
0%
File servers2
Url
Status
Screen
Uptime 30d
Health
http://tj3ty2q5jm5au3bmd2embtjscd3qjt7nfio2o7cr6moyy5kgil5pieqd.onion Down Screen
http://kpfj3bmo77bwpy2f5zzwj4knatueuv7t3ldlpp4tlrmv2buiziw2tdyd.onion Down
Chat servers4
Url
Status
Screen
Uptime 30d
Health
http://a2dbso6dijaqsmut36r6y4nps4cwivmfog5bpzf6uojovce6f3gl36id.onion:81 Down
http://vzzf6yg67cffqndnwg56e4psw45rup45f2mis7bwblg5fs7e5voagsqd.onion:81 Down
http://inbukcc4xk67uzbgkzufdqq3q3ikhwtebqxza5zlfbtzwm2g6usxidqd.onion:81 Down
http://p5quu5ujzzswxv4nxyuhgg3fjj2vy2a3zmtcowalkip2temdfadanlyd.onion/ Down
Activity (interactive) 131
Activity charts
Posts131
Date Title Description Screen
DARA Pharma Dara Pharmaceutical designs, develops, and manufactures packaging equipment for washing, sterilizing, filling, freeze-drying, and closing machines for vials, bottles, syringes, cartridges, and IV Bags to process liquid, semi-solid products, and powders in sterile conditions.
Lee & Associates In 1979, Bill Lees vision became reality when he opened the first office of Lee & Associates in Orange County, California. Every Lee office is owned and operated by the real estate professionals, all of whom benefit from the sharing of real-time market intelligence that is vital to the delivery of superior commercial real estate services. The unique service platform has attracted some of the most experienced and talented real estate professionals in the industry, all of whom share Bills original vision of superior service through teamwork. Our offices offer a broad array of real estate services tailored to meet the needs of the companys clients in each of the markets it serves. They include commercial real estate brokerage, property management, valuation, asset management and finance. Now the largest firm of its kind in North America, the companys reach extends across the United States and Canada.
GreenLight Biosciences Founded in 2008, GreenLight Bioscience is a pre-commercial stage synthetic biology company with a proprietary cell-free ribonucleic acid (RNA) production platform for the discovery, development and commercialization of high-performing products. The company is based in Medford, Massachusetts.
T2 Group We are people that value the journey towards excellence, actively seeking individuals who share this commitment — both within our team and among our clients. In collaboration, we operate as a unified force, sharing the ambition to achieve remarkable results that outshine the competition, redefine industries, and make meaningful impact.
Ark Consultancy ARK Consultancy Limited is a leading management and technical consultancy specializing in social housing, dedicated to supporting local authorities and housing associations throughout the UK. They offer a wide range of services that include asset management, decarbonization, resident engagement, and strategic governance.
Allstarmg Founded in 1999, Allstar Marketing Group is a Performance Marketing company that has been directly responsible for some of the most successful consumer products in history. Allstar works with brands who are on the precipice of becoming a household name, but are unable to market and distribute to retail at a larger scale.
Helpsonv HELP of Southern Nevada provides assistance to families and individuals in overcoming barriers to self-sufficiency through various direct services, training, and referrals to community resources. Their offerings include adult and family housing programs, behavioral health services, and a diaper bank, among others.
TOTVS
Modernauto
City of Newburgh
Encina Wastewater Authority
Meridian Cooperative
Hoteles Xcaret
Alps Alpine
Kirby Risk
FOCUS Business Solutions
Chambersburg Area School District
Smead
Ontellus
Avalign Technologies
Brett Martin
Kisco Senior Living
Multistack
Fiege Sp. z o.o.
NEBRASKALAND
The Texwipe
YAMAHA CORPORATION OF AMERICA
City of Augusta
Magic-Aire
Sterling Solutions
PRESS-SERVICE Monitoring Mediów
Dacotah Paper
Easy Automation
Esperanza Viva Jóvenes de México
Gulliver International
Saobacdau Technologies Group
City of Collegedale
Creation Baumann
Crown Grinding & Machining
Cementos Bio-Bio
Kelly Group
Etex Communications
Falcon Holdings
Wagner CAT
Inland Group
Penn Power Group
ARC
K2 Sports
Kansas City Homes
Ellison Technologies
Hayward
CAPMC
CPTM
lapiamontesa
ALTEK
PETERSON & HANSON
Broto Legal
Asahi Group
CCLint
Municipio de Chihuahua
UNE
Pitman Family Farms
Swiss American
Almoayed ICT
Biggest News
South Pacific Inc
Davin Industries Ltd
TIB Development Bank
Speed-Buster
Alan Smith
GMX
Torin Drive
Grande Stevens
Apex Capital Corp
Bud Griffin and Associates
Petrolimex
Rector Hayden Realtors
Taylor and Martin
Argonaut Gold
Prince Jewellery & Watch Co., Ltd.
Aeronamic
Venture Machine & Tool, Inc.
San Francisco 49ers
INVIMA
Diamond Pet Foods
MZ Architects
GEBE
Autumn Transport
h1{
Visage Imaging
Williams & Rowe Company, Inc.
P&R ENTERPRISES
Kangean Energy Indonesia
Dental Health Products
P&R ENTERPRISES
Unique Home Solutions
Quanticate
Bemis Associates
Karges-Faulconbridge, Inc.
MOTOR VEHICLE ACCIDENT FUND PENSION FUND
Koltepatil
Goodwill of Central and Coastal Virginia, Inc.
INOXPA
Canada West Land
Emery Jensen Distribution
Purifoy Chevrolet Co.
Williams & Rowe Company, Inc.
Visage Imaging
ASPECT STUDIOS ASIA PTY LTD
The Glass House
Statcomm
Regence Footwear
Napili Kai Foundation Gallery
H Hotels Collection
MINT Investments
DiGioia Gray & Associates, LLC
GENERALE PREFABBRICATI SPA
Goss Dodge Chrysler Ram Jeep
Medical Designs
Statcomm
Distribuidora de Industrias Nacionales
Tom Lange Company, Inc.
Farmers Cooperative Elevator
Aluflexpack
Clay County Clerk
AZA chili
BOSCA S.p.A
The Plastic Forming Company
GEO-Alpinbau
Goss Dodge Chrysler Ram Jeep
Matic Transport
Note