Exbyte is a custom Go-based data exfiltration malware associated with the BlackByte ransomware ecosystem and used by at least one BlackByte affiliate to accelerate theft of victim data during intrusions. It is designed to enumerate files of interest on compromised Windows systems, collect their locations, and upload the stolen data to external cloud-hosted file storage, supporting double-extortion ransomware operations.
Exbyte exhibits anti-analysis and execution-guarding behavior before carrying out exfiltration. It checks for the presence of a configuration file, verifies whether it is running with privileged local access, and performs security-software and analysis-environment discovery during execution. Reported anti-analysis behavior includes debugger detection and checks for analysis tools and sandbox- or antivirus-related components, indicating an effort to avoid execution in monitored environments and to align with BlackByte’s broader defense-evasion tradecraft.
Operationally, Exbyte enumerates document-type files on infected hosts and stages metadata about discovered files before uploading them to actor-controlled cloud storage. Its use of legitimate web-based file hosting for exfiltration helps blend malicious traffic with normal outbound activity. Exbyte has been cited alongside other mature ransomware-as-a-service custom exfiltration tools such as StealBit, reflecting the increasing specialization of tooling used to support data theft prior to ransomware deployment.
Exbyte is most accurately characterized as an infostealer focused on file collection and exfiltration rather than credential theft. Its known role is to facilitate theft of victim documents from enterprise environments compromised during BlackByte operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Symantec’s Threat Hunter Team has discovered that at least one affiliate of the BlackByte ransomware operation has begun using a custom data exfiltration tool during their attacks. The malware (Infostealer.Exbyte) is designed to expedite the theft of data from the victim’s network and upload it to an external server.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Many entries explicitly describe deleting artifacts 'to cover tracks,' 'evade detection,' 'remove evidence,' 'reduce their footprint,' or as part of 'post-intrusion cleanup process.' Examples include APT28 deleting files to cover tracks, FIN5 using SDelete to clean up the environment, and Dragonfly deleting operational files as part of cleanup.
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
Next, Exbyte enumerates all document files on the infected computer, such as .txt, .doc, and .pdf files, and saves the full path and file name to %APPDATA%\dummy.
On execution, Exbyte performs a series of checks for indicators that it may be running in a sandboxed environment. This is intended to make it more difficult for security researchers to analyze the malware.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom data exfiltration tool associated with BlackByte and used to facilitate data theft in ransomware operations.
A custom Go-based data exfiltration tool used in BlackByte attacks. It performs anti-analysis and anti-sandbox checks, enumerates document files such as .txt, .doc, and .pdf, stores file paths in %APPDATA%\dummy, and uploads stolen files to Mega.co.nz using hardcoded credentials.
Malware/tool that checks for security software products during execution.
Malware that checks whether it is executing with privileged/local elevated access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.