ATT&CKReferencesCybereason StealBit Exfiltration Tool

Cybereason StealBit Exfiltration Tool

Cybereason Global SOC Team. (n.d.). THREAT ANALYSIS REPORT: Inside the LockBit Arsenal - The StealBit Exfiltration Tool. Retrieved January 29, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareStealBit

StealBit can upload data and files to the LockBit victim-shaming site.

T1027.013
Encrypted/Encoded File
MalwareStealBit

StealBit stores obfuscated DLL file names in its executable.

T1030
Data Transfer Size Limits
MalwareStealBit

StealBit can be configured to exfiltrate files at a specified rate to evade network detection mechanisms.

T1070.004
File Deletion
MalwareStealBit

StealBit can self-delete its executable file from the compromised system.

T1071.001
Web Protocols
MalwareStealBit

StealBit can use HTTP to exfiltrate files to actor-controlled infrastructure.

T1082
System Information Discovery
MalwareStealBit

StealBit can enumerate the computer name and domain membership of the compromised system.

T1083
File and Directory Discovery
MalwareStealBit

StealBit can be configured to exfiltrate specific file types.

T1095
Non-Application Layer Protocol
MalwareStealBit

StealBit can use the Windows Socket networking library to communicate with attacker-controlled endpoints.

T1106
Native API
MalwareStealBit

StealBit can use native APIs including `LoadLibraryExA` for execution and `NtSetInformationProcess` for defense evasion purposes.

T1140
Deobfuscate/Decode Files or Information
MalwareStealBit

StealBit can deobfuscate loaded modules prior to execution.

T1480
Execution Guardrails
MalwareStealBit

StealBit will execute an empty infinite loop if it detects it is being run in the context of a debugger.

T1559
Inter-Process Communication
MalwareStealBit

StealBit can use interprocess communication (IPC) to enable the designation of multiple files for exfiltration in a scalable manner.

T1614.001
System Language Discovery
MalwareStealBit

StealBit can determine system location based on the default language setting and will not execute on systems located in former Soviet countries.

T1622
Debugger Evasion
MalwareStealBit

StealBit can detect it is being run in the context of a debugger.

T1685
Disable or Modify Tools
MalwareStealBit

StealBit can configure processes to not display certain Windows error messages by through use of the `NtSetInformationProcess`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.