Software · OAK-S35 · ransomware
OAK-S35 — BlackByte ransomware
Description
BlackByte is the ransomware encryptor codebase and brand maintained by a Russian-speaking operator cohort from July 2021 onward, with the brand's defining technical history being the multi-language codebase rotation across .NET (2021–2022), Go (2022–2023), and C++ (2023–2025) implementations. From a defender perspective the family occupies the mid-tier encryption-and-extortion functional role with a particular targeting profile concentrated on U.S. critical-infrastructure verticals (manufacturing, government, food and agriculture, financial services) that mirrors the broader Russian-speaking-RaaS-cohort targeting profile but at a smaller per-incident-cadence than the top-tier strains.
The encryptor's distinguishing technical features include the multi-language codebase rotation (the .NET → Go → C++ progression is documented across Trustwave, Microsoft, and Sophos analysis; each rotation reflected operator-side response to either decryptor-disclosure events (the October 2021 Trustwave decryptor for the .NET-era encryptor) or detection-rule accumulation (the Go-era encryptor's increasing AV-detection coverage by mid-2023)), aggressive evasion of EDR via Bring-Your-Own-Vulnerable-Driver (BYOVD) techniques (BlackByte was an early adopter of BYOVD via the RTCore64.sys MSI Afterburner driver vulnerability for EDR-disablement, a tradecraft that subsequently spread across the broader RaaS sector), and a dedicated VMware ESXi variant for hypervisor-level deployments. The CISA / FBI / U.S. Secret Service joint advisory AA22-039A of February 11, 2022 ([cisaaa22039a]) is the canonical early confirmed-grade institutional-attribution document for the brand, documenting the .NET-era encryptor's tradecraft and the brand's targeting of U.S. critical-infrastructure sectors.
The October 2021 Trustwave decryptor episode ([trustwaveblackbyte2021]) is one of the more-instructive early-disruption events in the modern RaaS sector — Trustwave SpiderLabs identified a flaw in the .NET-era encryptor's key-handling routine (the same RSA-encrypted key was used across all victims in a given build, allowing recovery of the key from any single decryptable file) and published a free decryptor; the operator response was a complete codebase rotation onto Go that retained the brand identity but rebuilt the technical substrate from scratch. This episode and the subsequent 2023 rotation onto C++ together establish BlackByte as the canonical worked example of sustained operator-side codebase-modernisation across multiple languages within a single long-lifetime brand, a pattern that distinguishes the brand's operator cohort as comparatively development-capable relative to mid-tier RaaS peers.
The family's role in the Russian-speaking-cybercrime-ecosystem monetization chain is the encryption-and-extortion node feeding Russian-speaking-cluster laundering venues — Garantex (OAK-G03) is named in industry-forensic reporting as a recurring affiliate off-ramp, mirroring the broader Russian-speaking-RaaS-cohort laundering pattern. The on-chain-side defining signature for BlackByte is the wallet-cluster persistence (OAK-T8.001) connecting BlackByte-attributable affiliate clusters to broader post-Conti affiliate diaspora at the partial-overlap level — sufficient to anchor the Conti-cohort-adjacent attribution reading without supporting full cohort-continuity in the idiom of Black Basta or Royal/BlackSuit.
Observed examples
- CISA AA22-039A campaign cohort (through early 2022). The advisory documents BlackByte-attributable incidents across U.S. critical-infrastructure sectors with manufacturing, government, food and agriculture, and financial services prominently called out; the .NET-era encryptor tradecraft is documented in detail and is the basis for the early-detection-rule architecture used across U.S. government and CTI-vendor reporting. Confirmed-grade aggregate per
[cisaaa22039a]. - San Francisco 49ers incident (February 2022). BlackByte-claimed deployment against the San Francisco 49ers NFL franchise on Super Bowl Sunday; data published on the BlackByte leak site after non-payment; one of the higher-profile early-2022 incidents and the first major-U.S.-sports-franchise public attribution to a BlackByte-branded deployment. Confirmed-grade per the 49ers' own incident-disclosure and BlackByte leak-site posting.
- Trustwave decryptor episode (October 2021). Trustwave SpiderLabs published a free decryptor exploiting a flaw in the .NET-era encryptor's key-handling routine; the decryptor was operational against approximately 3 months of BlackByte-encrypted-file builds before the operator cohort responded with a complete codebase rotation onto Go that retained the brand identity. Confirmed-grade per
[trustwaveblackbyte2021]and subsequent Microsoft / Sophos tracking. - City of Augusta Georgia incident (May 2023). BlackByte-claimed deployment against the City of Augusta, Georgia's municipal IT infrastructure; data partially published on the BlackByte leak site; representative of the 2023 BlackByte-affiliate U.S.-municipal-targeting pattern that paralleled the broader Royal/BlackSuit municipal-targeting trend. Confirmed-grade per the City of Augusta's own incident-disclosure.
- Multi-vertical 2023–2024 cohort. BlackByte-attributable incidents across U.S., European, and APAC sectors continued through the brand's lifetime with the C++-era encryptor's BYOVD-EDR-disablement tradecraft documented across multiple Microsoft and Sophos write-ups. Confirmed-grade aggregate per industry reporting.
- OAK on-chain example surface. No OAK
examples/entry exists for BlackByte-binary specifically as of v0.1; the BlackByte-to-Garantex chain documented in industry-forensic reporting is a candidate for a future OAK example entry showing the OAK-S35-binary × OAK-G03-Garantex × T7.002 worked example, structurally parallel to the Conti / Black-Basta / Royal-BlackSuit chains.
Detection / attribution signals
Defenders should treat BlackByte detection as a host-layer + on-chain-layer joint problem with the multi-language codebase rotation and the BYOVD-EDR-disablement tradecraft as the principal technical fingerprints:
- Host-layer process-tree fingerprints — characteristic file-extension changes (
.blackbyteextension on encrypted files in early builds; later builds use random-string extensions per affiliate-configuration); ransom-note filenames (BlackByte_Restoremyfiles.htaHTML-application-format ransom notes are the .NET-era signature; subsequent Go-and-C++-era builds useREADME.txtper-folder); .NET-, Go-, and C++-binary signatures across the codebase-rotation history (each rotation requires distinct detection-rule architecture); aggressive vssadmin / wmic shadow-copy-deletion sequences. - BYOVD EDR-disablement tradecraft — BlackByte was an early adopter of Bring-Your-Own-Vulnerable-Driver techniques via the RTCore64.sys MSI Afterburner driver vulnerability and the DBUtil_2_3.sys Dell driver vulnerability for EDR-disablement; the BYOVD pattern is the most-distinctive pre-encryption tradecraft fingerprint and is the principal behavioural signature distinguishing BlackByte-affiliate intrusions from Conti-cohort-direct-successor-brand intrusions at the EDR-evasion layer. The tradecraft is documented in CISA AA22-039A and continuous Microsoft / Sophos reporting.
- Pre-encryption tradecraft (general) — initial access via ProxyShell (CVE-2021-34473 / CVE-2021-34523 / CVE-2021-31207) Microsoft Exchange exploitation in early 2022, evolving to broader VPN-credential and RCE-vulnerability exploitation through 2022–2024; post-foothold deployment of Cobalt Strike (OAK-S37); credential theft via Mimikatz; lateral movement via PsExec, WMI, and operator-bundled deployment scripts; AnyDesk / Atera / Splashtop persistence-and-remote-access tooling installation.
- On-chain-layer signatures (the OAK-relevant signal) — BlackByte affiliate-controlled ransom-payment wallets exhibit common-funder cluster reuse (OAK-T8.001) with partial-overlap density to broader post-Conti affiliate diaspora; downstream routing through Garantex (OAK-G03) is documented as a recurring affiliate off-ramp; the per-incident ransom volumes are biased toward the small-and-mid-enterprise end of the spectrum, producing an on-chain signature comparable to Akira's (OAK-S33) but distinct from the higher-volume top-tier-strain patterns.
- CTI vendor coverage — Microsoft Threat Intelligence (BlackByte continuous tracking and the BYOVD-EDR-disablement tradecraft documentation), Sophos (sustained "State of Ransomware" reporting and the multi-language codebase rotation analysis), Trustwave SpiderLabs (the October 2021 decryptor and continuous tracking), Trend Micro (continuous version-by-version analysis across the codebase-rotation history), Recorded Future (Insikt Group sustained BlackByte reporting), Chainalysis and TRM Labs (on-chain affiliate-cluster tracking).
Note: omit specific file hashes from this entry. Defenders should consume current IOCs from CISA AA22-039A and live CTI-vendor feeds named above.
Citations
[cisaaa22039a]— CISA / FBI / U.S. Secret Service joint advisory AA22-039A on BlackByte ransomware, February 11, 2022. (NEW citation — see summary.)[trustwaveblackbyte2021]— Trustwave SpiderLabs BlackByte decryptor release and technical analysis, October 2021. (NEW citation — see summary.)[microsoftblackbyte2023]— Microsoft Threat Intelligence BlackByte continuous tracking and BYOVD-EDR-disablement tradecraft documentation. (NEW citation — see summary.)[sophosblackbyte2023]— Sophos BlackByte multi-language codebase rotation analysis. (NEW citation — see summary.)[trendmicroblackbyte2022]— Trend Micro BlackByte version-by-version analysis across codebase-rotation history. (NEW citation — see summary.)[chainalysisblackbyte2024]— Chainalysis BlackByte-attributable ransom-payment-volume tracking and partial-overlap-with-Conti-diaspora wallet-cluster analysis. (NEW citation — see summary.)[ofac2022garantex]— Treasury OFAC Garantex designation press release; broader Russian-speaking-RaaS-cohort laundering-venue context.[chainalysis2025ransomware]— Chainalysis 2024-recap ransomware report; cross-family context for the BlackByte volume distribution.
Discussion
On lineage and the multi-language codebase rotation as the central framing. OAK-S35's principal value as a Software entry is as the canonical worked example of sustained operator-side codebase-modernisation across multiple languages within a single long-lifetime brand. The .NET (2021–2022) → Go (2022–2023) → C++ (2023–2025) progression is unique in the modern RaaS sector — most peers maintain a single language across the brand's lifetime (Conti's C++, ALPHV's Rust) or execute a single-rewrite rotation (LockBit's NG-Dev Rust pre-deployment). BlackByte's three-stage rotation reflects either an unusually development-capable operator cohort or sustained external pressure (decryptor disclosures, detection-rule accumulation) that forced repeated rebuilds; the public-record evidence supports both readings. The rotation pattern is itself a behavioural signature for cohort-tracking and provides a useful comparative reference for understanding the operator-side codebase-modernisation cadence across a mid-tier long-lifetime brand.
On the Conti-cohort-adjacent positioning. BlackByte sits alongside Akira (OAK-S33) in the Conti-cohort-adjacent category — operator-personnel overlap with the broader post-Conti dispersal network is documented at the partial-overlap level (some affiliate-roster overlap, some wallet-cluster overlap, some tradecraft overlap including the 2022-era Cobalt Strike deployment patterns shared across Conti-and-successor brands), but the lineage relationship is partial-overlap rather than full cohort-continuity in the idiom of OAK-S27 Black Basta or OAK-S28 Royal/BlackSuit. The Conti-cohort-adjacent positioning produces a distinct attribution surface from full-cohort-successor brands and is useful for defender-side cohort-tracking work.
On the BYOVD-EDR-disablement tradecraft as a sector-wide pattern. BlackByte was an early adopter of Bring-Your-Own-Vulnerable-Driver techniques for EDR-disablement (the RTCore64.sys MSI Afterburner driver vulnerability is the canonical BYOVD reference); the tradecraft subsequently spread across the broader RaaS sector with LockBit, BlackCat / ALPHV, Black Basta, and multiple post-2022 emergent brands all incorporating BYOVD components in their pre-encryption tradecraft by 2023–2024. BlackByte's role in establishing the operational viability of BYOVD-as-RaaS-tradecraft is structurally analogous to ALPHV's role in establishing the operational viability of Rust-language RaaS encryptors — both brands shaped subsequent sector-wide tradecraft adoption beyond their own brand-attributable victim count.
On the OAK Software-vs-Group split. OAK-S35 (this entry) is the BlackByte encryptor codebase across the multi-language rotation; OAK-G17 (drafted in parallel) is the BlackByte operator cluster. The split mirrors the OAK-S23 / OAK-G05 LockBit pattern; the principal asymmetry is that the BlackByte operator cluster has neither named-defendant indictment nor OFAC institutional-cluster designation as of v0.1, with attribution architecture relying on the CISA AA22-039A advisory and CTI-vendor cluster-level tracking. The attribution-architecture-thinness is similar to Akira's (OAK-S33) and is diagnostic of the typical attribution surface for a mid-tier long-lifetime RaaS brand operating in a Russian jurisdiction without sufficient enforcement-attention to attract named-defendant or institutional-cluster designations.
On takedown / disruption history. BlackByte has not been subjected to a government takedown comparable to Operation Cronos (LockBit) or the December 2023 ALPHV action; the Trustwave decryptor episode of October 2021 is the principal disruption event in the brand's history short of a takedown, and the operator response — complete codebase rotation onto Go within months — is one of the more-effective documented operator-response-to-decryptor-disclosure cycles in the modern RaaS sector. The brand's continued operations through 2024 and into 2025 reflect the same structural challenge of disrupting Russian-jurisdiction-based mid-tier RaaS operations that produced the Akira / Karakurt operational-continuity patterns.