BlackByte ransomware exploits Microsoft Servers ProxyShell Vulnerabilities

Threat Level – Red | Vulnerability Report
Download PDF


For a detailed advisory, download the pdf file here.

BlackByte ransomware is targeting organizations with unpatched ProxyShell vulnerabilities. Proxy Shell was addressed by hive pro threat researcher in the previous advisory released on August 24.

ProxyShell is a combination of three flaws in Microsoft Exchange:

CVE-2021-34473 Pre-auth path confusion vulnerability to bypass access control.CVE-2021-34523 Privilege escalation vulnerability in the Exchange PowerShell backend.CVE-2021-31207 Post-auth remote code execution via arbitrary file write.

These security flaws are used together by threat actors to perform unauthenticated, remote code execution on vulnerable servers. After exploiting these vulnerabilities, the threat actors then install web shells, coin miners, ransomwares or backdoors on the servers. Attackers then use this web shell to deploy cobalt strike beacon into Windows Update Agent and get the credentials for a service account on compromised servers. The actor then installs Anydesk to gain control of the system and do lateral movement in the organization network. Post exploitation, attackers carry on with using Cobalt Strike to execute the Blackbyte ransomware and encrypt the data.

Affected organizations can decrypt their files using a free decryption tool written by Trustwave. Users can patch their server for ProxyShell vulnerabilities using the link down below.

Techniques used by Blackbyte ransomware are :

T1505.003 Server Software Component: Web ShellT1055 Process InjectionT1059.001 Command and Scripting Interpreter: PowerShellT1595.002 Active Scanning: Vulnerability ScanningT1027 Obfuscated Files of InformationT1490 Inhibit System RecoveryT1112 Modify RegistryT1562.001 Impair Defenses: Disable or Modify ToolsT1562.004 Impair Defenses: Disable or Modify System FirewallT1018 Remote System DiscoveryT1016 System Network Configuration DiscoveryT1070.004 Indicator Removal on Host: File DeletionT1560.001 Archive Collected Data: Archive via Utility


Vulnerability Details



Actor Detail



Indicators of Compromise(IoCs)



Patch Link




What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox