Exbyte

S1179

Malware.View on attack.mitre.org

About this malware

Exbyte is an exfiltration tool written in Go that is uniquely associated with BlackByte operations. Observed since 2022, Exbyte transfers collected files to online file sharing and hosting services.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1069.001
Local Groups

Exbyte checks whether the process is running with privileged local access during execution.

T1070.004
File Deletion

Exbyte will self-delete if a hard-coded configuration file is not found.

T1083
File and Directory Discovery

Exbyte enumerates all document files on an infected machine, then creates a summary of these items including filename and directory location prior to exfiltration to cloud hosting services.

T1106
Native API

Exbyte calls `ShellExecuteW` with the `IpOperation` parameter `RunAs` to launch `explorer.exe` with elevated privileges.

T1140
Deobfuscate/Decode Files or Information

Exbyte decodes and decrypts data stored in the configuration file with a key provided on the command line during execution.

T1480
Execution Guardrails

Exbyte checks for the presence of a configuration file before completing execution.

T1497.001
System Checks

Exbyte performs various checks to determine if it is running in a sandboxed environment to prevent analysis.

T1518.001
Security Software Discovery

Exbyte checks for the presence of various security software products during execution.

T1567
Exfiltration Over Web Service

Exbyte exfiltrates collected data to online file hosting sites such as `Mega.co.nz`.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Symantec BlackByte 2022 Open source
    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.