WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships FBI-USSS: Indicators of Compromise Associated with BlackByte Ransomware
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

FBI-USSS: Indicators of Compromise Associated with BlackByte Ransomware

Author: Alec Davison

Created: Tuesday, February 15, 2022 - 18:08

Categories: Cybersecurity

The FBI and the U.S. Secret Service have published a TLP:WHITE Joint Cybersecurity Advisory providing indicators of compromise and other information concerning BlackByte ransomware. The advisory notes that since November 2021, multiple U.S. and foreign organizations have been compromised by BlackByte, including in at least three U.S. critical infrastructure sectors. BlackByte is a Ransomware as a Service (RaaS) group that encrypts files on compromised Windows hosts systems.

The advisory includes further technical details regarding this activity and lists recommended mitigations. Organizations can access CISA’s free cyber hygiene services to help critical infrastructure organizations assess, identify, and reduce their exposure to threats, including ransomware. It also encourages partners to report suspicious or criminal activity to their local FBI field office or their local U.S. Secret Service field office or the FBI’s 24/7 CyberWatch (CyWatch) at (855)292-3937 or Cy*****@*bi.gov. Access the full advisory below.

Attached Files:

JCSA CU-000163-MW (TLP WHITE)

Related Resources

(TLP:CLEAR) FIRESTARTER Backdoor and Updated Emergency Directive for CISCO Firepower and Secure Firewall Devices

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:GREEN) FBI FLASH – Newly Observed Ransomware Variant Black Shrantac Threat to U.S. Entities

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Likely PRC State-Sponsored Activity Observed in the Water Sector – DocuSign Phishing Tactics Identified

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar