Analyzing BlackByte Ransomware's Go-Based Variants
ID: 55f690a1-bba4-5db2-a67e-fd0fc3f4842b
STIX ID: report--55f690a1-bba4-5db2-a67e-fd0fc3f4842b
Feed Name: Zscaler Security Research Blog
**Executive summary:** This Zscaler ThreatLabz report analyzes the BlackByte ransomware family (Go-based v1 and v2), detailing its installation, persistence, lateral propagation, privilege escalation, anti-analysis/anti-forensics techniques, and file-encryption implementations (v1: RSA/AES; v2: Curve25519/ChaCha). The actors perform data exfiltration and double extortion, maintain TOR-based ransom portals, use polymorphic string obfuscation and modified packers to evade detection, and provide multiple IOCs and sample hashes for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
