

Secret Service noted that the ransomware group had targeted critical infrastructure. Federal Bureau of Investigation and the U.S.

They also displayed pervasiveness with a notable increase (300%) in the number of attacks associated with the RaaS in October-December 2021, compared with July-September 2021. and global organizations, including a number in energy, agriculture, financial services and the public sector. Since November 2021, they have targeted multiple U.S. The operators behind this ransomware have been very active since it first emerged. BlackByte has similarities to other ransomware variants such as Lockbit 2.0 that avoid systems that use Russian and a number of Eastern European languages, including many written with Cyrillic alphabets. Operators have exploited ProxyShell vulnerabilities to gain a foothold in the victim's environment. BlackByte is ransomware as a service (RaaS) that first emerged in July 2021.
