logo

BlackBit Ransomware: A Hidden Threat Linked To LokiLocker

ID: 8486eb60-4c1e-53d1-868f-1adcb14f7486

STIX ID: report--8486eb60-4c1e-53d1-868f-1adcb14f7486

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-04-22

Date Updated: 2026-07-20

...
...

BlackBit is a LokiLocker-derived ransomware discovered in September 2022 that implements persistence (copies to ProgramData and Startup, Task Scheduler entry), defense evasion (disables Windows Defender, firewall, Task Manager; deletes shadow copies and backups), process/service termination, and file encryption (excluding .exe/.dll/.sys) while appending a .BlackBit extension and continuing to monitor and encrypt newly created files; the report contains sample hashes, registry artifacts, ransomware behavior including a Persian-language kill-switch, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.