BlackByte Ransomware is a Windows ransomware family associated with the BlackByte threat group. It is distributed through a JavaScript launcher and supports deployment across compromised networks. It discovers connected network shares, queries Active Directory for remote hostnames, transfers ransomware payloads through mapped SMB shares, and creates scheduled tasks to execute those payloads remotely. It also enables the legacy SMBv1 protocol during execution.
Before full execution, BlackByte identifies installed security products, checks the system language, and enumerates Windows Registry settings associated with application execution options. It uses a hard-coded mutex to prevent simultaneous instances and terminates when the mutex already exists or the system language matches an exclusion list. To impair defenses, it adds JavaScript and executable file extensions to Microsoft Defender exclusions and terminates and removes the Raccine anti-ransomware utility. It also modifies the Windows Registry to prevent system recovery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BlackByte Ransomware looks for security software products prior to full execution.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware cited as an example of downgrade attacks because it enables the legacy SMBv1 protocol during execution.
Ransomware that uses scheduled tasks to execute remotely deployed payloads.
Ransomware that checks for installed security software before full execution.
Ransomware that identifies remote systems through Active Directory hostname queries before launching remote ransomware payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.