OAK — OnChain Attack Knowledge

Software · OAK-S35 · ransomware

OAK-S35 — BlackByte ransomware

Type
ransomware
Aliases
BlackByte (the operator-side and leak-site-branded name from the brand's July 2021 debut, retained continuously across the multi-language codebase rotation through 2024); industry-side cross-attribution labels include the Wizard-Spider-cohort-adjacent / Conti-cohort-partial-overlap descriptive used in 2022 industry reporting that documented operator-personnel overlap with the broader Conti-cohort dispersal network, and the BlackByte 2.0 / NT / 3.0 version-string naming used to disambiguate the multi-language codebase rotations across .NET (2021–2022), Go (2022–2023), and C++ (2023–2025) implementations. BlackByte sits in the Conti-cohort-adjacent category alongside Akira (OAK-S33) — operator-personnel overlap with the broader post-Conti dispersal network is documented but the lineage relationship is partial-overlap rather than full cohort-continuity in the idiom of OAK-S27 Black Basta or OAK-S28 Royal/BlackSuit.
Active
active — BlackByte-branded operations continued through 2024 and into 2025 with sustained leak-site cadence; the brand had not been subjected to a government takedown comparable to Operation Cronos (LockBit) or the December 2023 ALPHV action as of v0.1, and remains an active-detection target. Brand-attributable extortion volume placed BlackByte as a mid-tier RaaS strain across 2022–2024 — below the top-three by leak-site postings but with sustained presence and continued multi-vertical targeting per Recorded Future / Coveware tracking.
First observed
2021-07 (BlackByte-branded operations debuted July 2021 with the .NET-language Windows encryptor; subsequent codebase rotations to Go (2022) and C++ (2023+) reflect a sustained operator-side investment in encryptor-codebase modernisation across the brand's lifetime, distinguishing BlackByte from the more-typical RaaS-sector pattern of either single-language codebase persistence or single-rewrite codebase rotation).
Used by Groups
OAK-G17 BlackByte (primary operator cluster — drafted in parallel with this Software entry; the operator cohort is tracked at cluster level rather than as a named-individual operator, with no senior-leadership indictment or OFAC designation as of v0.1). Affiliate-side cross-use is documented across the broader Russian-speaking-RaaS-cohort umbrella; Trustwave's October 2021 publication of a free decryptor exploiting a flaw in the .NET-era encryptor's key-handling routine ([trustwaveblackbyte2021]) is a notable early-disruption episode in the brand's history that triggered the operator's first major codebase rotation onto Go.
Host platforms
Windows (primary, all enterprise-server variants, with the codebase rotated across .NET (2021–2022) → Go (2022–2023) → C++ (2023–2025) per Trustwave, Microsoft, and Sophos attribution work); Linux / VMware ESXi (a dedicated ESXi-hypervisor variant emerged in 2022, mirroring the broader RaaS-sector pivot to hypervisor-targeted attacks established by LockBit and ALPHV). The multi-language codebase rotation is the family's defining technical history and provides a useful comparative reference for understanding the operator-side codebase-modernisation cadence across a long-lifetime mid-tier RaaS brand — distinct from both single-language persistence (Conti's C++-only history) and single-rewrite rotation (LockBit's NG-Dev Rust rewrite recovered pre-deployment).
Observed Techniques
OAK-T7.001 (mixer-routed-hop, used for BlackByte-affiliate ransom proceeds 2021–2023 with Sinbad pre-takedown the principal venue per Chainalysis tracking); OAK-T7.002 (CEX deposit-address layering, the post-2023 default with Garantex (OAK-G03) named in industry-forensic reporting as a recurring BlackByte-affiliate off-ramp consistent with the broader Russian-speaking-RaaS-cohort laundering pattern); OAK-T8.001 (common-funder cluster reuse, used for BlackByte-affiliate-cohort tracking across the codebase-rotation events and for documenting the partial-overlap signals with broader Conti-adjacent affiliate clusters per Chainalysis cross-cohort analysis).

Description

BlackByte is the ransomware encryptor codebase and brand maintained by a Russian-speaking operator cohort from July 2021 onward, with the brand's defining technical history being the multi-language codebase rotation across .NET (2021–2022), Go (2022–2023), and C++ (2023–2025) implementations. From a defender perspective the family occupies the mid-tier encryption-and-extortion functional role with a particular targeting profile concentrated on U.S. critical-infrastructure verticals (manufacturing, government, food and agriculture, financial services) that mirrors the broader Russian-speaking-RaaS-cohort targeting profile but at a smaller per-incident-cadence than the top-tier strains.

The encryptor's distinguishing technical features include the multi-language codebase rotation (the .NET → Go → C++ progression is documented across Trustwave, Microsoft, and Sophos analysis; each rotation reflected operator-side response to either decryptor-disclosure events (the October 2021 Trustwave decryptor for the .NET-era encryptor) or detection-rule accumulation (the Go-era encryptor's increasing AV-detection coverage by mid-2023)), aggressive evasion of EDR via Bring-Your-Own-Vulnerable-Driver (BYOVD) techniques (BlackByte was an early adopter of BYOVD via the RTCore64.sys MSI Afterburner driver vulnerability for EDR-disablement, a tradecraft that subsequently spread across the broader RaaS sector), and a dedicated VMware ESXi variant for hypervisor-level deployments. The CISA / FBI / U.S. Secret Service joint advisory AA22-039A of February 11, 2022 ([cisaaa22039a]) is the canonical early confirmed-grade institutional-attribution document for the brand, documenting the .NET-era encryptor's tradecraft and the brand's targeting of U.S. critical-infrastructure sectors.

The October 2021 Trustwave decryptor episode ([trustwaveblackbyte2021]) is one of the more-instructive early-disruption events in the modern RaaS sector — Trustwave SpiderLabs identified a flaw in the .NET-era encryptor's key-handling routine (the same RSA-encrypted key was used across all victims in a given build, allowing recovery of the key from any single decryptable file) and published a free decryptor; the operator response was a complete codebase rotation onto Go that retained the brand identity but rebuilt the technical substrate from scratch. This episode and the subsequent 2023 rotation onto C++ together establish BlackByte as the canonical worked example of sustained operator-side codebase-modernisation across multiple languages within a single long-lifetime brand, a pattern that distinguishes the brand's operator cohort as comparatively development-capable relative to mid-tier RaaS peers.

The family's role in the Russian-speaking-cybercrime-ecosystem monetization chain is the encryption-and-extortion node feeding Russian-speaking-cluster laundering venues — Garantex (OAK-G03) is named in industry-forensic reporting as a recurring affiliate off-ramp, mirroring the broader Russian-speaking-RaaS-cohort laundering pattern. The on-chain-side defining signature for BlackByte is the wallet-cluster persistence (OAK-T8.001) connecting BlackByte-attributable affiliate clusters to broader post-Conti affiliate diaspora at the partial-overlap level — sufficient to anchor the Conti-cohort-adjacent attribution reading without supporting full cohort-continuity in the idiom of Black Basta or Royal/BlackSuit.

Observed examples

  • CISA AA22-039A campaign cohort (through early 2022). The advisory documents BlackByte-attributable incidents across U.S. critical-infrastructure sectors with manufacturing, government, food and agriculture, and financial services prominently called out; the .NET-era encryptor tradecraft is documented in detail and is the basis for the early-detection-rule architecture used across U.S. government and CTI-vendor reporting. Confirmed-grade aggregate per [cisaaa22039a].
  • San Francisco 49ers incident (February 2022). BlackByte-claimed deployment against the San Francisco 49ers NFL franchise on Super Bowl Sunday; data published on the BlackByte leak site after non-payment; one of the higher-profile early-2022 incidents and the first major-U.S.-sports-franchise public attribution to a BlackByte-branded deployment. Confirmed-grade per the 49ers' own incident-disclosure and BlackByte leak-site posting.
  • Trustwave decryptor episode (October 2021). Trustwave SpiderLabs published a free decryptor exploiting a flaw in the .NET-era encryptor's key-handling routine; the decryptor was operational against approximately 3 months of BlackByte-encrypted-file builds before the operator cohort responded with a complete codebase rotation onto Go that retained the brand identity. Confirmed-grade per [trustwaveblackbyte2021] and subsequent Microsoft / Sophos tracking.
  • City of Augusta Georgia incident (May 2023). BlackByte-claimed deployment against the City of Augusta, Georgia's municipal IT infrastructure; data partially published on the BlackByte leak site; representative of the 2023 BlackByte-affiliate U.S.-municipal-targeting pattern that paralleled the broader Royal/BlackSuit municipal-targeting trend. Confirmed-grade per the City of Augusta's own incident-disclosure.
  • Multi-vertical 2023–2024 cohort. BlackByte-attributable incidents across U.S., European, and APAC sectors continued through the brand's lifetime with the C++-era encryptor's BYOVD-EDR-disablement tradecraft documented across multiple Microsoft and Sophos write-ups. Confirmed-grade aggregate per industry reporting.
  • OAK on-chain example surface. No OAK examples/ entry exists for BlackByte-binary specifically as of v0.1; the BlackByte-to-Garantex chain documented in industry-forensic reporting is a candidate for a future OAK example entry showing the OAK-S35-binary × OAK-G03-Garantex × T7.002 worked example, structurally parallel to the Conti / Black-Basta / Royal-BlackSuit chains.

Detection / attribution signals

Defenders should treat BlackByte detection as a host-layer + on-chain-layer joint problem with the multi-language codebase rotation and the BYOVD-EDR-disablement tradecraft as the principal technical fingerprints:

  • Host-layer process-tree fingerprints — characteristic file-extension changes (.blackbyte extension on encrypted files in early builds; later builds use random-string extensions per affiliate-configuration); ransom-note filenames (BlackByte_Restoremyfiles.hta HTML-application-format ransom notes are the .NET-era signature; subsequent Go-and-C++-era builds use README.txt per-folder); .NET-, Go-, and C++-binary signatures across the codebase-rotation history (each rotation requires distinct detection-rule architecture); aggressive vssadmin / wmic shadow-copy-deletion sequences.
  • BYOVD EDR-disablement tradecraft — BlackByte was an early adopter of Bring-Your-Own-Vulnerable-Driver techniques via the RTCore64.sys MSI Afterburner driver vulnerability and the DBUtil_2_3.sys Dell driver vulnerability for EDR-disablement; the BYOVD pattern is the most-distinctive pre-encryption tradecraft fingerprint and is the principal behavioural signature distinguishing BlackByte-affiliate intrusions from Conti-cohort-direct-successor-brand intrusions at the EDR-evasion layer. The tradecraft is documented in CISA AA22-039A and continuous Microsoft / Sophos reporting.
  • Pre-encryption tradecraft (general) — initial access via ProxyShell (CVE-2021-34473 / CVE-2021-34523 / CVE-2021-31207) Microsoft Exchange exploitation in early 2022, evolving to broader VPN-credential and RCE-vulnerability exploitation through 2022–2024; post-foothold deployment of Cobalt Strike (OAK-S37); credential theft via Mimikatz; lateral movement via PsExec, WMI, and operator-bundled deployment scripts; AnyDesk / Atera / Splashtop persistence-and-remote-access tooling installation.
  • On-chain-layer signatures (the OAK-relevant signal) — BlackByte affiliate-controlled ransom-payment wallets exhibit common-funder cluster reuse (OAK-T8.001) with partial-overlap density to broader post-Conti affiliate diaspora; downstream routing through Garantex (OAK-G03) is documented as a recurring affiliate off-ramp; the per-incident ransom volumes are biased toward the small-and-mid-enterprise end of the spectrum, producing an on-chain signature comparable to Akira's (OAK-S33) but distinct from the higher-volume top-tier-strain patterns.
  • CTI vendor coverage — Microsoft Threat Intelligence (BlackByte continuous tracking and the BYOVD-EDR-disablement tradecraft documentation), Sophos (sustained "State of Ransomware" reporting and the multi-language codebase rotation analysis), Trustwave SpiderLabs (the October 2021 decryptor and continuous tracking), Trend Micro (continuous version-by-version analysis across the codebase-rotation history), Recorded Future (Insikt Group sustained BlackByte reporting), Chainalysis and TRM Labs (on-chain affiliate-cluster tracking).

Note: omit specific file hashes from this entry. Defenders should consume current IOCs from CISA AA22-039A and live CTI-vendor feeds named above.

Citations

  • [cisaaa22039a] — CISA / FBI / U.S. Secret Service joint advisory AA22-039A on BlackByte ransomware, February 11, 2022. (NEW citation — see summary.)
  • [trustwaveblackbyte2021] — Trustwave SpiderLabs BlackByte decryptor release and technical analysis, October 2021. (NEW citation — see summary.)
  • [microsoftblackbyte2023] — Microsoft Threat Intelligence BlackByte continuous tracking and BYOVD-EDR-disablement tradecraft documentation. (NEW citation — see summary.)
  • [sophosblackbyte2023] — Sophos BlackByte multi-language codebase rotation analysis. (NEW citation — see summary.)
  • [trendmicroblackbyte2022] — Trend Micro BlackByte version-by-version analysis across codebase-rotation history. (NEW citation — see summary.)
  • [chainalysisblackbyte2024] — Chainalysis BlackByte-attributable ransom-payment-volume tracking and partial-overlap-with-Conti-diaspora wallet-cluster analysis. (NEW citation — see summary.)
  • [ofac2022garantex] — Treasury OFAC Garantex designation press release; broader Russian-speaking-RaaS-cohort laundering-venue context.
  • [chainalysis2025ransomware] — Chainalysis 2024-recap ransomware report; cross-family context for the BlackByte volume distribution.

Discussion

On lineage and the multi-language codebase rotation as the central framing. OAK-S35's principal value as a Software entry is as the canonical worked example of sustained operator-side codebase-modernisation across multiple languages within a single long-lifetime brand. The .NET (2021–2022) → Go (2022–2023) → C++ (2023–2025) progression is unique in the modern RaaS sector — most peers maintain a single language across the brand's lifetime (Conti's C++, ALPHV's Rust) or execute a single-rewrite rotation (LockBit's NG-Dev Rust pre-deployment). BlackByte's three-stage rotation reflects either an unusually development-capable operator cohort or sustained external pressure (decryptor disclosures, detection-rule accumulation) that forced repeated rebuilds; the public-record evidence supports both readings. The rotation pattern is itself a behavioural signature for cohort-tracking and provides a useful comparative reference for understanding the operator-side codebase-modernisation cadence across a mid-tier long-lifetime brand.

On the Conti-cohort-adjacent positioning. BlackByte sits alongside Akira (OAK-S33) in the Conti-cohort-adjacent category — operator-personnel overlap with the broader post-Conti dispersal network is documented at the partial-overlap level (some affiliate-roster overlap, some wallet-cluster overlap, some tradecraft overlap including the 2022-era Cobalt Strike deployment patterns shared across Conti-and-successor brands), but the lineage relationship is partial-overlap rather than full cohort-continuity in the idiom of OAK-S27 Black Basta or OAK-S28 Royal/BlackSuit. The Conti-cohort-adjacent positioning produces a distinct attribution surface from full-cohort-successor brands and is useful for defender-side cohort-tracking work.

On the BYOVD-EDR-disablement tradecraft as a sector-wide pattern. BlackByte was an early adopter of Bring-Your-Own-Vulnerable-Driver techniques for EDR-disablement (the RTCore64.sys MSI Afterburner driver vulnerability is the canonical BYOVD reference); the tradecraft subsequently spread across the broader RaaS sector with LockBit, BlackCat / ALPHV, Black Basta, and multiple post-2022 emergent brands all incorporating BYOVD components in their pre-encryption tradecraft by 2023–2024. BlackByte's role in establishing the operational viability of BYOVD-as-RaaS-tradecraft is structurally analogous to ALPHV's role in establishing the operational viability of Rust-language RaaS encryptors — both brands shaped subsequent sector-wide tradecraft adoption beyond their own brand-attributable victim count.

On the OAK Software-vs-Group split. OAK-S35 (this entry) is the BlackByte encryptor codebase across the multi-language rotation; OAK-G17 (drafted in parallel) is the BlackByte operator cluster. The split mirrors the OAK-S23 / OAK-G05 LockBit pattern; the principal asymmetry is that the BlackByte operator cluster has neither named-defendant indictment nor OFAC institutional-cluster designation as of v0.1, with attribution architecture relying on the CISA AA22-039A advisory and CTI-vendor cluster-level tracking. The attribution-architecture-thinness is similar to Akira's (OAK-S33) and is diagnostic of the typical attribution surface for a mid-tier long-lifetime RaaS brand operating in a Russian jurisdiction without sufficient enforcement-attention to attract named-defendant or institutional-cluster designations.

On takedown / disruption history. BlackByte has not been subjected to a government takedown comparable to Operation Cronos (LockBit) or the December 2023 ALPHV action; the Trustwave decryptor episode of October 2021 is the principal disruption event in the brand's history short of a takedown, and the operator response — complete codebase rotation onto Go within months — is one of the more-effective documented operator-response-to-decryptor-disclosure cycles in the modern RaaS sector. The brand's continued operations through 2024 and into 2025 reflect the same structural challenge of disrupting Russian-jurisdiction-based mid-tier RaaS operations that produced the Akira / Karakurt operational-continuity patterns.

Techniques observed (3)

Used by