StealBit is a custom Windows data-exfiltration malware developed and maintained by the LockBit ransomware operation for use by its affiliates in double-extortion intrusions. It is distributed through the LockBit affiliate panel and is used before or alongside ransomware deployment to steal selected victim files for extortion leverage. LockBit operators initially relied on public tools for exfiltration, but later replaced them with StealBit as part of the group’s broader industrialization of ransomware operations.
StealBit is closely associated with LockBit and has been repeatedly described as a bespoke exfiltration or information-stealing tool used to automate theft of victim data. Its purpose is selective collection and transfer of files from compromised environments rather than credential harvesting. Reported behavior includes selective theft based on file extensions, transmission of affiliate-related metadata during uploads, and use of embedded failover infrastructure. Technical analyses describe it as heavily obfuscated, using anti-analysis checks such as inspection of NtGlobalFlag in the PEB, decryption of embedded strings at runtime, and dynamic loading of required modules.
Analyzed samples show that StealBit uses named-pipe-based interprocess communication and the Windows I/O completion port model to parallelize file transfer operations and improve exfiltration speed. It supports both GUI-assisted and command-line-driven operation, including options related to hiding execution, throttling transfer speed, limiting scope, and self-deletion. Some samples create a visible operator window despite advertised hidden-mode support, and some analyses found that advertised compression capabilities were not fully implemented, with file contents instead sent uncompressed. StealBit has been observed exfiltrating data over HTTP PUT requests and using a dedicated named pipe for coordination between processes.
StealBit is part of the LockBit ecosystem’s support tooling and has been referenced alongside other ransomware-linked custom exfiltration tools such as Ryuk Stealer and Exmatter. Law-enforcement actions against LockBit recovered StealBit source code, further confirming its role as a core affiliate utility within the LockBit platform. It has been used across LockBit intrusions affecting a wide range of sectors and geographies wherever LockBit affiliates operated.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this Threat Analysis report, the GSOC investigates the StealBit malware, a data exfiltration tool that the LockBit threat group develops and maintains.
StealBit — a tool developed by GOLD MYSTIC to facilitate data exfiltration in LockBit ransomware intrusions
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Recorded Commands cmd.exe /c vssadmin Delete Shadows /All /Quiet ... cmd.exe /c wevtutil cl security
MITRE ATT&CK Techniques for StealBit Malware ... Native API ... StealBit first checks whether the StealBit process runs in the context of a debugger ... StealBit creates the named pipe file ... by invoking the NtCreateNamedPipeFile function ... invokes the ZwReadFile function to read the content of the file
StealBit stores the XOR obfuscated filenames of these DLLs in the malware’s executable file ... StealBit then decrypts RC4-encrypted strings that the malware stores in the malware’s executable file.
Many entries explicitly describe deleting artifacts 'to cover tracks,' 'evade detection,' 'remove evidence,' 'reduce their footprint,' or as part of 'post-intrusion cleanup process.' Examples include APT28 deleting files to cover tracks, FIN5 using SDelete to clean up the environment, and Dragonfly deleting operational files as part of cleanup.
As infection begins, Lockbit 2.0 deletes log files and shadow copies residing on disk.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
StealBit displays the computer name of the compromised system and the name of the domain to which the system belongs ... The data that StealBit sends to the attacker-controlled endpoint includes ... The computer name of the compromised system and the name of the domain
In StealBIT this is implemented by having a hardcoded list of extensions that should be extracted.
On that repository, law enforcement also discovered source code for LockBit’s StealBit tool, which helped LockBit affiliates exfiltrate data stolen through LockBit attacks.
To evade exfiltration detection mechanisms that monitor the amount of sent data to remote endpoints over time, StealBit operators can configure StealBit to exfiltrate file content at a given rate ... by configuring the -net/-n or -once/-o command line parameters.
Exmatter is designed to steal a range of user files, databases and compressed files ... and then upload them to a preconfigured server via Secure File Transfer Protocol (SFTP).
When a victim’s network was infected by LockBit’s malicious software, their data was stolen and their systems encrypted.
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom LockBit-associated tool used for data exfiltration.
A LockBit-associated data theft utility introduced alongside LockBit 2.0 to exfiltrate files as part of double-extortion operations.
Stealbit is a tool used by the LockBit group to exfiltrate data from victim networks prior to or during ransomware attacks, facilitating double extortion tactics.
LockBit 운영에서 데이터 유출(탈취)을 수행하기 위해 사용되는 전용 도구로 언급된다.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.