Emerging Threats
Malware2021
BlackByte
2Rules
3References
1Folders
2025-10-21Latest
Summary
BlackByte is tracked here as a malware family or toolset with 2 Sigma detections spanning 2021. Coverage centers on windows / process_creation, windows / registry_set.
Related Detections
Search this threatEmerging Threathightest
Blackbyte Ransomware Registry
Detects specific windows registry modifications made by BlackByte ransomware variants. BlackByte set three different registry values to escalate privileges and begin setting the stage for lateral movement and encryption. This rule triggers when any of the following registry keys are set to DWORD 1, however all three should be investigated as part of a larger BlackByte ransomware detection and response effort.
WindowsRegistry Set
TA0003 · PersistenceTA0005 · StealthT1112 · Modify Registrydetection.emerging-threats
François HubautMon Jan 242021
Emerging Threathightest
Potential BlackByte Ransomware Activity
Detects command line patterns used by BlackByte ransomware in different operations
WindowsProcess Creation
TA0002 · ExecutionTA0005 · StealthTA0040 · ImpactT1485 · Data Destruction+4
Florian Roth (Nextron Systems)Fri Feb 252021
References