Netskope Threat Labs

BlackByte

ATP Sandbox Adv. HeuristicsAVNetskope IPS

BlackByte is a ransomware as a service operation active since 2021 whose affiliates have compromised organizations around the world, including the San Francisco 49ers in 2022 and critical infrastructure sectors in the United States. It exfiltrates data and pressures victims through a leak site, and its operators have expanded the family to support Windows, Linux, and VMware ESXi systems. The group primarily gains initial access through exposed remote access services and unpatched vulnerabilities.

First seen
April 2022
Last seen
October 2026
Blackbyte
Alert Name
Binary.Ransomware.BlackByte
Document-RTF.Ransomware.BlackByte
Gen:Variant.Ransom.BlackByte.1
Gen:Variant.Ransom.BlackByte.11
Gen:Variant.Ransom.BlackByte.14
Generic.Ransom.BlackByte.A.33484396
Trojan.Ransom.BlackByte.A
Trojan.Ransom.BlackByte.B
Trojan.Ransom.BlackByte.B:836E6
Win32.Ransomware.BlackByte