BlackByte 2.0 Ransomware

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[BlackByte 2.0 Ransomware](https://attack.mitre.org/software/S1181) is a replacement for [BlackByte Ransomware](https://attack.mitre.org/software/S1180). Unlike [BlackByte Ransomware](https://attack.mitre.org/software/S1180), [BlackByte 2.0 Ransomware](https://attack.mitre.org/software/S1181) does not have a common key for victim decryption. [BlackByte 2.0 Ransomware](https://attack.mitre.org/software/S1181) remains uniquely associated with [BlackByte](https://attack.mitre.org/groups/G1043) operations.(Citation: Microsoft BlackByte 2023)

Associated Techniques (11)
ID ATT&CK Tactics
T1055 Process Injection -
T1068 Exploitation for Privilege Escalation -
T1070.004 File Deletion -
T1070.006 Timestomp -
T1112 Modify Registry -
T1135 Network Share Discovery -
T1486 Data Encrypted for Impact -
T1489 Service Stop -
T1490 Inhibit System Recovery -
T1562.004 Disable or Modify System Firewall -
T1569.002 Service Execution -
Used by Actors (1)
Metadata
ID: 169
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00