BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems.67
group
BlackByte G1043
- Created
- 16 December 2024
- Last modified
- 31 July 2026
- Aliases
- BlackByte · Hecamede
BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.[1][2][3][4][5]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G1043
BlackByte queried registry values to determine system language settings.8
BlackByte used tools such as Arp to pull system network information and identify connected devices.910
BlackByte used tools such as Arp to identify remotely-connected devices.1112
BlackByte has used RDP to access other hosts within victim networks.1314
BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations.151617
Standing G1043
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
84th percentile · 84% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
94th percentile · 94% of 176 ATT&CK groups have this many tactics spanned or fewer.
76th percentile · 76% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
80th percentile · 80% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G1043
2255 distinct rules cover the 48 techniques recorded for this group. The 2591 technique-to-rule mappings resolve to 2255 distinct rules, because one rule can cover several techniques. 1421 Sigma · 834 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org