🇷🇺BlackByte
🇷🇺 BlackByte is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 17 detection use cases to this actor across 49 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-06-12 to 2026-06-12.
high 1
17Use cases
1Articles
49Techniques
0IOCs
Known aliases
BlackByteBlackbyteHecamede
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1012 · Query RegistryT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1036.008 · Masquerade File TypeT1041 · Exfiltration Over C2 ChannelT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1053.005 · Scheduled TaskT1055 · Process InjectionT1055.012 · Process HollowingT1059.001 · PowerShellT1059.003 · Windows Command ShellT1068 · Exploitation for Privilege EscalationT1070.004 · File DeletionT1071.001 · Web ProtocolsT1078 · Valid AccountsT1078.002 · Domain AccountsT1082 · System Information DiscoveryT1087.002 · Domain AccountT1105 · Ingress Tool TransferT1112 · Modify RegistryT1134.003 · Make and Impersonate TokenT1135 · Network Share DiscoveryT1136.002 · Domain AccountT1140 · Deobfuscate/Decode Files or InformationT1219 · Remote Access ToolsT1480 · Execution GuardrailsT1482 · Domain Trust DiscoveryT1490 · Inhibit System RecoveryT1491.001 · Internal DefacementT1505.003 · Web ShellT1518.001 · Security Software DiscoveryT1543.003 · Windows ServiceT1547.001 · Registry Run Keys / Startup FolderT1560 · Archive Collected DataT1567 · Exfiltration Over Web ServiceT1569.002 · Service ExecutionT1570 · Lateral Tool TransferT1583.003 · Virtual Private ServerT1608.001 · Upload MalwareT1614.001 · System Language DiscoveryT1685 · Disable or Modify ToolsT1686 · Disable or Modify System Firewall