Exbyte
MITRE ATT&CK: S1179 View on attack.mitre.org
Aliases: Exbyte
- First seen
- 2022-01-01 00:00:00
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:23:50
Targeted industries: energy-and-utilities government-and-public-sector financial-services
Context
Exbyte is an exfiltration tool written in Go that is uniquely associated with BlackByte operations. Observed since 2022, Exbyte transfers collected files to online file sharing and hosting services.
Detection coverage
- 96 Sigma rules
Malware & tools used
- Execution Guardrails (attack-pattern)
- Local Groups (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Security Software Discovery (attack-pattern)
- File Deletion (attack-pattern)
- System Checks (attack-pattern)
- Exfiltration Over Web Service (attack-pattern)
- Native API (attack-pattern)
Used by threat actors
- BlackByte (threat-actor)
Reports & references
- Microsoft — The Five Day Job A Blackbyte Ransomware Intrusion Case Study (report)
- security.com — Blackbyte Exbyte Ransomware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Exbyte (report)
- Broadcom/Symantec — Blackbyte Exbyte Ransomware (report)
- MITRE ATT&CK — S1179 (report)