ExMatter

Malware type
ransomware
Profile updated
2026-07-07 13:47:14

Targeted industries: energy-and-utilities financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications

Context

Exfiltration tool written in .NET, used by at least one BlackMatter ransomware operator.

Detection coverage

  • 1 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Exmatter (yara-rule)

Reports & references

  • Broadcom/Symantec — Blackmatter Data Exfiltration (report)
  • s-rminform.com — Exmatter Malware Levels Up (report)
  • netskope.com — Blackcat Ransomware Tactics And Techniques From A Targeted Attack (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Exmatter (report)
  • kroll.com — Analyzing Exmatter Ransomware Data Exfiltration Tool (report)
  • accenture.com — Stealbit Exmatter Exfiltration Tool Analysis (report)
  • twitter.com — 1461787168037240834 (report)

External references