Discover how Blackbyte Ransomware operates, its double-extortion techniques, and expert advice on securing your systems against this emerging threat.
ID: 0cdeff13-b1e3-50b7-8503-24fb6a809c93
STIX ID: report--0cdeff13-b1e3-50b7-8503-24fb6a809c93
Feed Name: ReliaQuest Blog
BlackByte is a ransomware-as-a-service operation that employs double-extortion via a public "leaks" site, exploits vulnerabilities in public-facing devices for initial access, and has used Cobalt Strike; earlier versions re-used encryption keys making some files potentially recoverable. The report lists mitigation advice (patching public-facing services, phishing defenses, EDR/AV coverage, backups, MFA), notes use of anonymfiles.com and file.io for data exfiltration, and maps observed behaviors to multiple MITRE ATT&CK techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
