Researchers reported that Exmatter, a custom ransomware data-exfiltration tool first tied to BlackMatter, has evolved into a more capable pre-encryption theft utility and has appeared in intrusions linked to other ransomware operators, including a LockBit affiliate. Earlier analyses described Exmatter as an obfuscated .NET tool that scans logical drives, filters files by extension, size, and location, and steals high-value business data such as documents, source code, and CAD/GIS files. It primarily exfiltrates data over SFTP, with later versions adding WebDAV support, reinforcing the role of data theft and double extortion in modern ransomware operations.
A newer variant observed by S-RM added features that make Exmatter more autonomous during intrusions, including enumeration of mapped network drives from the Windows registry, lateral movement over network shares, remote self-execution using TinyIPC, and the ability to take ownership of restricted files when run with administrator privileges. The sample also embedded a Base64-encoded WebDAV client for command-and-control and used HTTP PUT over port 80 for exfiltration; in one case, attackers reportedly stole up to 1 TB of data before deploying ransomware. The activity aligns with Microsoft’s broader assessment that ransomware affiliates increasingly swap payloads and tooling while relying on hands-on intrusion, credential abuse, persistence, and pre-ransomware data theft as core elements of the extortion model.

Get the actors, campaigns, and ATT&CK mapping behind it.
16 events from the most recent confirmed update back to the earliest known activity.
S-RM reported that the Exmatter sample observed in its case had a compile time of 2024-01-18 01:37:26 and included new capabilities for mapped-drive discovery, IPC-assisted spread, remote execution, and WebDAV-based exfiltration over HTTP PUT.
S-RM said it had observed the affiliate later tracked as Velvet Tempest deploying LockBit 3.0 payloads since August 2023.
S-RM cited Microsoft attribution that Velvet Tempest, formerly DEV-0504, created and used Exmatter and had deployed Ryuk, REvil, LockBit 2.0, BlackMatter, Conti, and BlackCat/ALPHV between December 2021 and June 2022.
Microsoft reported that it observed no Conti deployment in its data after April 19, 2022, suggesting the program shut down or went on hiatus.
Microsoft observed ELBRUS abusing CVE-2021-31207 in April 2022 to escalate low-privileged Exchange access to SYSTEM-level access.
Microsoft said leaked Conti chat files from February 2022 confirmed the broad scale of DEV-0193 operations.
Microsoft said DEV-0504 deployed BlackCat against energy and other sectors in January 2022 while continuing to rely on access brokers, Cobalt Strike, and PsExec.
Microsoft stated that ELBRUS retired the BlackMatter ransomware operation in November 2021.
Microsoft reported that ELBRUS replaced the DarkSide ransomware-as-a-service ecosystem with BlackMatter in July 2021.
Kroll analyzed multiple Exmatter samples in Q4 2021 and found the tool was originally associated with BlackMatter before later variants appeared with other ransomware groups.
Microsoft said the affiliate tracked as DEV-0504 had deployed at least six ransomware-as-a-service payloads since 2020, reflecting its role as a prolific multi-program affiliate.
Microsoft described ELBRUS, also known as FIN7, as a long-running financially motivated group active since 2012 before later shifting into ransomware and extortion activity.
S-RM disclosed a recent ransomware engagement in which a LockBit affiliate used a new Exmatter variant to move laterally over network shares, remotely execute itself, take ownership of restricted files, and exfiltrate up to 1 TB of data before ransomware deployment.
Microsoft published a ransomware-as-a-service report identifying DEV-0504 as a prolific affiliate that had shifted across multiple payloads and used common intrusion tooling and access-brokered entry.
Symantec's Threat Hunter Team disclosed Exmatter as a custom .NET exfiltration utility used before ransomware deployment and noted multiple variants with evolving file targeting, exclusion logic, and SFTP/WebDAV infrastructure.
Symantec reported that at least one BlackMatter affiliate used the custom Exmatter data exfiltration tool to steal selected files before deploying ransomware on victim networks.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
s-rminform.com
Open sourcemicrosoft.com
Open sourcekroll.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.