ExMatter is a custom Windows data-theft utility used in ransomware intrusions to automate pre-encryption exfiltration for double-extortion operations. It was first publicly associated with the BlackMatter ecosystem and was later used by BlackCat/ALPHV and by affiliates linked to other ransomware operations, including LockBit and activity observed prior to Conti deployment. Microsoft has attributed creation and use of ExMatter to the affiliate tracked as Velvet Tempest.
ExMatter is typically implemented as an obfuscated .NET executable and is designed to enumerate logical drives, traverse directories, and selectively collect files likely to provide extortion value. Reported targeting has included office documents, archives, email stores, databases, source code, remote desktop artifacts, CAD and GIS files, images, text files, and other business-relevant data. Multiple analyses indicate that it filters by extension, size, attributes, and directory, skips common operating-system and application paths, and often prioritizes recently modified files to accelerate theft of current, high-value material.
The malware’s exfiltration mechanisms have evolved across variants. Early and commonly reported versions primarily uploaded data over SFTP on TCP port 22, while later variants added WebDAV as a fallback or primary channel. Additional reporting describes support for FTP in later BlackCat-linked updates and HTTP PUT over port 80 in a newer variant. Some samples included options for hidden-window execution, report generation, self-deletion, self-overwrite, and environment-validation or self-destruct logic. Symantec also reported a BlackCat-linked update adding an eraser capability that corrupts processed files.
Later variants expanded operational autonomy. Observed enhancements include enumeration of mapped network drives, inter-process communication using TinyIPC, movement across network shares, remote self-execution, and deployment via Group Policy. When run with elevated privileges, some variants can take ownership of files to access data otherwise denied to the operator. These changes indicate a shift from a single-host collector toward a more scalable enterprise exfiltration tool suited to large ransomware engagements.
ExMatter is most often observed shortly before ransomware deployment and alongside broader intrusion activity such as reconnaissance, credential abuse, privilege escalation, lateral movement, and remote execution with administrative tools such as PsExec. It is closely associated with double-extortion tradecraft in which attackers steal sensitive data before encryption to increase leverage over victims across sectors, including government, healthcare, and enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
S-RM’s incident response team has observed a new variant of the data exfiltration tool, Exmatter, being used by a LockBit affiliate on a recent ransomware engagement.
Exmatter, which was discovered by Symantec’s Threat Hunter Team, is designed to steal specific file types from a number of selected directories and upload them to an attacker-controlled server prior to deployment of the ransomware itself on the victim’s network.
"...deploying custom data exfiltration tools like ExMatter to siphon sensitive data prior to encryption."
25 distinct techniques documented for this family, organized by ATT&CK tactic.
If executed with administrator rights, it was also able to modify the permissions of files using the command ‘takeown’, which uses the SeTakeOwnershipPrivilege Microsoft API, giving the threat actor ownership permissions over files they were previously denied access to.
Analysis of the Exmatter binary revealed that, beneath multiple layers of obfuscation, including the use of Spanish to write its functions, and encoding large sections of the malware in Base64...
Analysis of the Exmatter binary revealed that... its ability to read mapped network drives from the registry of the host system.
the ransomware and Fendr are delivered simultaneously across a network to many systems as “v2.exe” and “v2c.exe”, or as “v2.exe” and “sender2.exe”
Exmatter... target[s] specific directories and file types for collection and exfiltration.
The use of IPC allowed it to move laterally between network shares on the victim’s network, simultaneously targeting data for exfiltration whilst remotely executing itself on other systems.
The tool, dubbed Fendr, has not only been upgraded to include more file types but also used by the gang extensively to steal data from corporate networks in December 2021 and January 2022 prior to encryption, in a popular tactic called double extortion.
In order to identify files for exfiltration, it will retrieve the drive names of all logical drives on the infected computer and collect all file path names... It will only exfiltrate files with the following extensions... It attempts to prioritize files for exfiltration by using LastWriteTime.
Exmatter is designed to steal a range of user files, databases and compressed files ... and then upload them to a preconfigured server via Secure File Transfer Protocol (SFTP).
Between November 3 and December 26, 673,977 flows took place... a large majority ... involved only two IP addresses... All of these flows used port 22 of 174.138.64[.]88.
Tool description: “ExMatter… upload… via SFTP” and mapping “T1048… .002: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol”
Of those, a large majority (462,552/673,977) occurred from December 15 onward and involved only two IP addresses, one attributed to the vendor and a DigitalOcean IP address, 174.138.64[.]88. These transfers may represent the attackers’ data exfiltration from the vendor’s network.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data exfiltration tool associated in the report with BlackCat activity; described as connecting from victim networks to remote servers over port 22, consistent with suspected exfiltration traffic in this incident.
Exfiltration tool associated in the report with BlackCat. It is described as using command-and-control infrastructure largely on DigitalOcean IP addresses and exfiltrating data to a remote server over port 22.
Mentioned as another custom data exfiltration tool used in ransomware operations; no further analysis is provided in this content.
A custom-built data exfiltration tool used prior to ransomware deployment to automate collection and theft of sensitive data from Windows environments. This variant targets specific directories and file types, reads mapped network drives from the registry, uses TinyIPC for inter-process communication to support lateral movement and remote execution across network shares, can take ownership of files when run with administrator rights, and exfiltrates data to an attacker-controlled WebDAV server over HTTP PUT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.