ExMatter
- Malware type
- ransomware
- Profile updated
- 2026-07-07 13:47:14
Targeted industries: energy-and-utilities financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications
Context
Exfiltration tool written in .NET, used by at least one BlackMatter ransomware operator.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Exmatter (yara-rule)
Reports & references
- Broadcom/Symantec — Blackmatter Data Exfiltration (report)
- s-rminform.com — Exmatter Malware Levels Up (report)
- netskope.com — Blackcat Ransomware Tactics And Techniques From A Targeted Attack (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Exmatter (report)
- kroll.com — Analyzing Exmatter Ransomware Data Exfiltration Tool (report)
- accenture.com — Stealbit Exmatter Exfiltration Tool Analysis (report)
- twitter.com — 1461787168037240834 (report)