logo

Discover how Blackbyte Ransomware operates, its double-extortion techniques, and expert advice on securing your systems against this emerging threat.

ID: 0cdeff13-b1e3-50b7-8503-24fb6a809c93

STIX ID: report--0cdeff13-b1e3-50b7-8503-24fb6a809c93

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2022-02-13

Date Updated: 2026-04-29

...
...

BlackByte is a ransomware-as-a-service operation that employs double-extortion via a public "leaks" site, exploits vulnerabilities in public-facing devices for initial access, and has used Cobalt Strike; earlier versions re-used encryption keys making some files potentially recoverable. The report lists mitigation advice (patching public-facing services, phishing defenses, EDR/AV coverage, backups, MFA), notes use of anonymfiles.com and file.io for data exfiltration, and maps observed behaviors to multiple MITRE ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.