LockBit expanded its ransomware-as-a-service operations with StealBit, a custom exfiltration tool used by affiliates to steal data before encryption and support double-extortion demands. Research shows StealBit was built for high-throughput theft, using named-pipe interprocess communication via STEALBIT-MASTER-PIPE and Windows I/O completion ports to parallelize transfers, while sending stolen file contents over HTTP PUT requests to attacker-controlled infrastructure embedded in the malware. Analysts also found anti-analysis checks, encrypted strings and endpoint data, and later versions that added self-deletion, transfer throttling, and partial window-hiding, although some advertised features such as hidden execution and compression were incomplete or misleading in examined samples.
The tool formed part of the broader LockBit 2.0 playbook, which resurfaced as a more aggressive operation combining rapid encryption, data theft, and automated spread across Windows domains through Active Directory group policies. Trend Micro reported detections tied to LockBit 2.0 activity in Chile, Italy, Taiwan, and the UK, noting that affiliates also abused legitimate tools such as Process Hacker and PC Hunter and used scripts to disable defenses, stop services, and clear logs. The ransomware partially encrypted files, appended the .lockbit extension, dropped Restore-My-Files.txt ransom notes, and threatened to leak stolen data, while later research tracked the gang’s exfiltration infrastructure as defenders worked to hunt StealBit-related activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Attack attempts involving LockBit 2.0 were detected between July 1 and August 15, 2021, affecting organizations in Chile, Italy, Taiwan, and the UK.
Trend Micro reported that the LockBit ransomware group resurfaced in June 2021 with LockBit 2.0, a ransomware-as-a-service variant that added double-extortion capabilities and provided affiliates with the StealBit exfiltration tool.
Cybereason published a technical analysis of StealBit describing it as a custom LockBit exfiltration tool used in double-extortion operations and documenting its architecture, anti-analysis behavior, and exfiltration methods.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
yoroi.company
Open sourcecybereason.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.