Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1043
MITRE ATT&CK Group

BlackByte (G1043)

Hecamede
ShareXLinkedInRedditHN

[BlackByte](https://attack.mitre.org/groups/G1043) is a ransomware threat actor operating since at least 2021. [BlackByte](https://attack.mitre.org/groups/G1043) is associated with several versions of ransomware also labeled [BlackByte Ransomware](https://attack.mitre.org/software/S1180). [BlackByte](https://attack.mitre.org/groups/G1043) ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as [BlackByte 2.0 Ransomware](https://attack.mitre.org/software/S1181) use more robust encryption mechanisms. [BlackByte](https://attack.mitre.org/groups/G1043) is notable for operations targeting critical infrastructure entities among other targets across North America.(Citation: FBI BlackByte 2022)(Citation: Picus BlackByte 2022)(Citation: Symantec BlackByte 2022)(Citation: Microsoft BlackByte 2023)(Citation: Cisco BlackByte 2024)

▪Techniques used (48)

T1082System Information DiscoveryT1016System Network Configuration DiscoveryT1046Network Service DiscoveryT1105Ingress Tool TransferT1482Domain Trust DiscoveryT1686Disable or Modify System FirewallT1036.008Masquerade File TypeT1053.005Scheduled TaskT1134.003Make and Impersonate TokenT1070.004File DeletionT1543.003Windows ServiceT1021.001Remote Desktop ProtocolT1685Disable or Modify ToolsT1614.001System Language DiscoveryT1560Archive Collected DataT1059.003Windows Command ShellT1136.002Domain AccountT1112Modify RegistryT1055.012Process HollowingT1491.001Internal DefacementT1071.001Web ProtocolsT1087.002Domain AccountT1570Lateral Tool TransferT1583.003Virtual Private ServerT1190Exploit Public-Facing ApplicationT1608.001Upload MalwareT1490Inhibit System RecoveryT1012Query RegistryT1059.001PowerShellT1041Exfiltration Over C2 ChannelT1003OS Credential DumpingT1569.002Service ExecutionT1135Network Share DiscoveryT1140Deobfuscate/Decode Files or InformationT1068Exploitation for Privilege EscalationT1505.003Web ShellT1078Valid AccountsT1567Exfiltration Over Web ServiceT1055Process InjectionT1021.002SMB/Windows Admin SharesT1078.002Domain AccountsT1547.001Registry Run Keys / Startup FolderT1480Execution GuardrailsT1486Data Encrypted for ImpactT1518.001Security Software DiscoveryT1219Remote Access ToolsT1047Windows Management InstrumentationT1018Remote System Discovery

▪Software used (8)

S0552AdFindtoolS1180BlackByte RansomwaremalwareS1179ExbytemalwareS0099ArptoolS1181BlackByte 2.0 RansomwaremalwareS0029PsExectoolS0154Cobalt StrikemalwareS0002Mimikatztool
G1043on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.