ExMatter is a custom Windows data-exfiltration malware used in double-extortion ransomware intrusions to steal selected files from victim environments before encryption. It was first associated with the BlackMatter ransomware operation and was later used by BlackCat/ALPHV and other ransomware affiliates, including activity linked by Microsoft to the affiliate tracked as Velvet Tempest. ExMatter has also been observed in intrusions involving LockBit affiliates and in pre-ransomware stages preceding other ransomware deployments.
ExMatter is implemented as an obfuscated .NET executable and is designed to automate high-value data theft rather than indiscriminate collection. It enumerates logical drives and, in newer variants, mapped network shares, then filters files by extension, size, attributes, directory exclusions, and in some cases date range. Reported targeting has focused on business-relevant content such as office documents, archives, email stores, databases, source code, CAD and GIS files, remote desktop configuration files, images, text files, and related enterprise data. Multiple analyses note that it prioritizes recently modified files to accelerate theft of the most operationally valuable material.
Observed ExMatter variants support several exfiltration mechanisms. Early and commonly reported samples upload data primarily over SFTP, while later variants added WebDAV as a fallback or alternate channel; some reporting also notes FTP support in later BlackCat-linked updates. WebDAV-capable variants have been observed using standard WebDAV methods and HTTP PUT for transfer. Some samples include options to hide their execution window, generate reports of processed files, corrupt processed files, or self-delete after execution. Anti-forensic behavior has included overwriting part of the executable and deleting itself via PowerShell. Later variants also underwent code refactoring and obfuscation changes intended to improve stealth and hinder analysis.
More advanced variants expanded beyond local collection. Reported capabilities include enumerating mapped drives, using inter-process communication to coordinate execution across systems, moving laterally via network shares, and supporting deployment through Group Policy. When run with elevated privileges, some variants can take ownership of files to access data that would otherwise be denied. In enterprise ransomware operations, ExMatter has been deployed at scale using legitimate administrative mechanisms such as PsExec and compromised domain accounts.
ExMatter is closely associated with ransomware-led extortion operations rather than standalone espionage. Its role is to rapidly extract sensitive, monetizable data immediately before ransomware deployment, increasing leverage for leak-site extortion and reducing dwell time needed for manual collection. The malware has been observed in attacks affecting large enterprise environments and government-linked contractors, and its evolution reflects the broader trend of ransomware operators building specialized tooling for automated pre-encryption data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
S-RM’s incident response team has observed a new variant of the data exfiltration tool, Exmatter, being used by a LockBit affiliate on a recent ransomware engagement.
Exmatter, which was discovered by Symantec’s Threat Hunter Team, is designed to steal specific file types from a number of selected directories and upload them to an attacker-controlled server prior to deployment of the ransomware itself on the victim’s network.
"...deploying custom data exfiltration tools like ExMatter to siphon sensitive data prior to encryption."
25 distinct techniques documented for this family, organized by ATT&CK tactic.
If executed with administrator rights, it was also able to modify the permissions of files using the command ‘takeown’, which uses the SeTakeOwnershipPrivilege Microsoft API, giving the threat actor ownership permissions over files they were previously denied access to.
Analysis of the Exmatter binary revealed that, beneath multiple layers of obfuscation, including the use of Spanish to write its functions, and encoding large sections of the malware in Base64...
Analysis of the Exmatter binary revealed that... its ability to read mapped network drives from the registry of the host system.
the ransomware and Fendr are delivered simultaneously across a network to many systems as “v2.exe” and “v2c.exe”, or as “v2.exe” and “sender2.exe”
Exmatter... target[s] specific directories and file types for collection and exfiltration.
The use of IPC allowed it to move laterally between network shares on the victim’s network, simultaneously targeting data for exfiltration whilst remotely executing itself on other systems.
The tool, dubbed Fendr, has not only been upgraded to include more file types but also used by the gang extensively to steal data from corporate networks in December 2021 and January 2022 prior to encryption, in a popular tactic called double extortion.
In order to identify files for exfiltration, it will retrieve the drive names of all logical drives on the infected computer and collect all file path names... It will only exfiltrate files with the following extensions... It attempts to prioritize files for exfiltration by using LastWriteTime.
Exmatter is designed to steal a range of user files, databases and compressed files ... and then upload them to a preconfigured server via Secure File Transfer Protocol (SFTP).
By default, this specific sample is trying to communicate with an IP address via WebDav, initially sending a PROPFIND request.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another custom data exfiltration tool used in ransomware operations; no further analysis is provided in this content.
A custom-built data exfiltration tool used prior to ransomware deployment to automate collection and theft of sensitive data from Windows environments. This variant targets specific directories and file types, reads mapped network drives from the registry, uses TinyIPC for inter-process communication to support lateral movement and remote execution across network shares, can take ownership of files when run with administrator rights, and exfiltrates data to an attacker-controlled WebDAV server over HTTP PUT.
Custom data exfiltration tool originally associated with BlackMatter; observed used by an affiliate whose victims later appeared on LockBit’s leak site, suggesting tool sharing or multi-brand affiliate activity.
Data theft/exfiltration tool used to steal sensitive data prior to ransomware encryption as part of BlackCat’s extortion workflow.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.