Cybereason Global SOC Team. (n.d.). THREAT ANALYSIS REPORT: Inside the LockBit Arsenal - The StealBit Exfiltration Tool. Retrieved January 29, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareStealBit | StealBit can upload data and files to the LockBit victim-shaming site. |
| T1027.013 Encrypted/Encoded File |
MalwareStealBit | StealBit stores obfuscated DLL file names in its executable. |
| T1030 Data Transfer Size Limits |
MalwareStealBit | StealBit can be configured to exfiltrate files at a specified rate to evade network detection mechanisms. |
| T1070.004 File Deletion |
MalwareStealBit | StealBit can self-delete its executable file from the compromised system. |
| T1071.001 Web Protocols |
MalwareStealBit | StealBit can use HTTP to exfiltrate files to actor-controlled infrastructure. |
| T1082 System Information Discovery |
MalwareStealBit | StealBit can enumerate the computer name and domain membership of the compromised system. |
| T1083 File and Directory Discovery |
MalwareStealBit | StealBit can be configured to exfiltrate specific file types. |
| T1095 Non-Application Layer Protocol |
MalwareStealBit | StealBit can use the Windows Socket networking library to communicate with attacker-controlled endpoints. |
| T1106 Native API |
MalwareStealBit | StealBit can use native APIs including `LoadLibraryExA` for execution and `NtSetInformationProcess` for defense evasion purposes. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareStealBit | StealBit can deobfuscate loaded modules prior to execution. |
| T1480 Execution Guardrails |
MalwareStealBit | StealBit will execute an empty infinite loop if it detects it is being run in the context of a debugger. |
| T1559 Inter-Process Communication |
MalwareStealBit | StealBit can use interprocess communication (IPC) to enable the designation of multiple files for exfiltration in a scalable manner. |
| T1614.001 System Language Discovery |
MalwareStealBit | StealBit can determine system location based on the default language setting and will not execute on systems located in former Soviet countries. |
| T1622 Debugger Evasion |
MalwareStealBit | StealBit can detect it is being run in the context of a debugger. |
| T1685 Disable or Modify Tools |
MalwareStealBit | StealBit can configure processes to not display certain Windows error messages by through use of the `NtSetInformationProcess`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.