Exbyte

MITRE ATT&CK: S1179 View on attack.mitre.org

Aliases: Exbyte

First seen
2022-01-01 00:00:00
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:23:50

Targeted industries: energy-and-utilities government-and-public-sector financial-services

Context

Exbyte is an exfiltration tool written in Go that is uniquely associated with BlackByte operations. Observed since 2022, Exbyte transfers collected files to online file sharing and hosting services.

Detection coverage

  • 96 Sigma rules

Malware & tools used

  • Execution Guardrails (attack-pattern)
  • Local Groups (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • System Checks (attack-pattern)
  • Exfiltration Over Web Service (attack-pattern)
  • Native API (attack-pattern)

Used by threat actors

Reports & references

  • Microsoft — The Five Day Job A Blackbyte Ransomware Intrusion Case Study (report)
  • security.com — Blackbyte Exbyte Ransomware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Exbyte (report)
  • Broadcom/Symantec — Blackbyte Exbyte Ransomware (report)
  • MITRE ATT&CK — S1179 (report)

External references