Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ BlackByte

🇷🇺BlackByte

🇷🇺 BlackByte is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 21 detection use cases to this actor across 56 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-08-10 to 2026-08-10.

crit 1
View full actor card → All threat actors MITRE ATT&CK group spec (G1043) ↗
21Use cases
1Articles
56Techniques
0IOCs

Known aliases

BlackByteBlackbyteHecamede

Top techniques

All other tracked techniques

T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1005 · Data from Local SystemT1012 · Query RegistryT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1036.008 · Masquerade File TypeT1041 · Exfiltration Over C2 ChannelT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1053.005 · Scheduled TaskT1055 · Process InjectionT1055.012 · Process HollowingT1059.001 · PowerShellT1059.003 · Windows Command ShellT1068 · Exploitation for Privilege EscalationT1070.004 · File DeletionT1071.001 · Web ProtocolsT1071.004 · DNST1078 · Valid AccountsT1078.002 · Domain AccountsT1082 · System Information DiscoveryT1087.002 · Domain AccountT1105 · Ingress Tool TransferT1112 · Modify RegistryT1134.003 · Make and Impersonate TokenT1135 · Network Share DiscoveryT1136.002 · Domain AccountT1140 · Deobfuscate/Decode Files or InformationT1176 · Software ExtensionsT1219 · Remote Access ToolsT1480 · Execution GuardrailsT1482 · Domain Trust DiscoveryT1486 · Data Encrypted for ImpactT1490 · Inhibit System RecoveryT1491.001 · Internal DefacementT1505.003 · Web ShellT1518.001 · Security Software DiscoveryT1539 · Steal Web Session CookieT1543.003 · Windows ServiceT1547.001 · Registry Run Keys / Startup FolderT1555.003 · Credentials from Web BrowsersT1560 · Archive Collected DataT1567 · Exfiltration Over Web ServiceT1569.002 · Service ExecutionT1570 · Lateral Tool TransferT1583.003 · Virtual Private ServerT1608.001 · Upload MalwareT1614.001 · System Language DiscoveryT1685 · Disable or Modify ToolsT1686 · Disable or Modify System Firewall

Detection use cases (21)

Beaconing — periodic outbound to small set of destinations Internal Suspicious browser extension installation Internal Infostealer — non-browser process accessing browser cookie/login DBs Internal Crypto-wallet file/keystore access by non-wallet process Internal Asset exposure — vulnerability matches article CVE(s) Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal Remote service execution — PsExec / SMB lateral movement Internal Trusted vendor binary / installer launching unusual children Internal 1Password impossible-travel sign-in MITRE match Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Internet-Facing Service Daemon Spawns Shell or Ingress Tool Then Beacons Out MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain MITRE match Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition MITRE match Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress MITRE match

Threat-intel articles (1)

Tracked indicators

CVEs (3)

CVE-2026-33825 CVE-2026-50751 CVE-2026-50752