logo

Cisco: BlackByte ransomware gang only posting 20% to 30% of successful attacks

ID: e3371b57-f775-5553-a429-a51e890de5d8

STIX ID: report--e3371b57-f775-5553-a429-a51e890de5d8

Feed Name: The Record from Recorded Future News

Threat Score
78/100

Date Published: 2024-08-28

Date Updated: 2026-05-01

...
...

BlackByte, an apparent offshoot of Conti operating as ransomware-as-a-service, remains highly active and has quickly incorporated newly disclosed vulnerabilities—most notably CVE-2024-37085 against VMware ESXi—into attacks against high-value targets such as local governments and major organizations; researchers note the group only publishes a small fraction of successful intrusions on its leak site, and its focus on ESXi and public-facing vulnerabilities increases the potential impact to enterprise infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.