BlackByte — Ransomware Profile
BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.Also tracked as
Hecamede
Tools & malware
- AdFind Network Reconnaissance
- Arp Network Reconnaissance
- BlackByte 2.0 Ransomware Ransomware
- BlackByte Ransomware Ransomware
- Cobalt Strike Adversary Simulation
- Exbyte Exfiltration Tool
- Mimikatz Credential Harvesting
- PsExec Remote Execution
Recent claimed victims
- Towne Mortgage 2025-07-30
- DARA Pharma 2025-07-30
- Lee & Associates 2025-07-30
- Cpat Flex 2025-07-30
- T2 Group 2025-07-16
- Helpsonv 2025-07-16
- Allstarmg 2025-07-16
- Ark Consultancy 2025-07-16
- GreenLight Biosciences 2025-07-16
- TOTVS 2024-09-30
- Modernauto 2024-07-17
- Modern Automotive Group 2024-07-17
- City of Newburgh 2024-06-22
- Cityofnewburgh-ny.gov 2024-06-22
- Encinajpa 2024-06-19
- Encina Wastewater Authority 2024-03-13
Vendor research
- TTPs used by BlackByte Ransomware Targeting Critical Infrastructure Picus
- BlackByte blends tried-and-true tradecraft with newly disclosed vulnerabilities to support ongoing attacks Cisco
- The five-day job: A BlackByte ransomware intrusion case study Microsoft
- Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool Symantec
- Indicators of Compromise Associated with BlackByte Ransomware FBI