logo

Analyzing BlackByte Ransomware's Go-Based Variants

ID: 55f690a1-bba4-5db2-a67e-fd0fc3f4842b

STIX ID: report--55f690a1-bba4-5db2-a67e-fd0fc3f4842b

Feed Name: Zscaler Security Research Blog

Threat Score
80/100

Date Published: 2025-07-03

Date Updated: 2026-05-01

...
...

**Executive summary:** This Zscaler ThreatLabz report analyzes the BlackByte ransomware family (Go-based v1 and v2), detailing its installation, persistence, lateral propagation, privilege escalation, anti-analysis/anti-forensics techniques, and file-encryption implementations (v1: RSA/AES; v2: Curve25519/ChaCha). The actors perform data exfiltration and double extortion, maintain TOR-based ransom portals, use polymorphic string obfuscation and modified packers to evade detection, and provide multiple IOCs and sample hashes for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.