Threat actor · G1043
BlackByte
Also known as Hecamede.
BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.
ATT&CK techniques
48 mappedT1003T1012T1016T1018T1021.001T1021.002T1036.008T1041T1046T1047T1053.005T1055T1055.012T1059.001T1059.003T1068T1070.004T1071.001T1078T1078.002T1082T1087.002T1105T1112T1134.003T1135T1136.002T1140T1190T1219T1480T1482T1486T1490T1491.001T1505.003T1518.001T1543.003T1547.001T1560T1567T1569.002T1570T1583.003T1608.001T1614.001T1685T1686