Malware.View on attack.mitre.org
StealBit is a data exfiltration tool that is developed and maintained by the operators of the the LockBit Ransomware-as-a-Service (RaaS) and offered to affiliates to exfiltrate data from compromised systems for double extortion purposes.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
StealBit can upload data and files to the LockBit victim-shaming site. |
| T1027.013 Encrypted/Encoded File |
StealBit stores obfuscated DLL file names in its executable. |
| T1030 Data Transfer Size Limits |
StealBit can be configured to exfiltrate files at a specified rate to evade network detection mechanisms. |
| T1070.004 File Deletion |
StealBit can self-delete its executable file from the compromised system. |
| T1071.001 Web Protocols |
StealBit can use HTTP to exfiltrate files to actor-controlled infrastructure. |
| T1082 System Information Discovery |
StealBit can enumerate the computer name and domain membership of the compromised system. |
| T1083 File and Directory Discovery |
StealBit can be configured to exfiltrate specific file types. |
| T1095 Non-Application Layer Protocol |
StealBit can use the Windows Socket networking library to communicate with attacker-controlled endpoints. |
| T1106 Native API |
StealBit can use native APIs including `LoadLibraryExA` for execution and `NtSetInformationProcess` for defense evasion purposes. |
| T1140 Deobfuscate/Decode Files or Information |
StealBit can deobfuscate loaded modules prior to execution. |
| T1480 Execution Guardrails |
StealBit will execute an empty infinite loop if it detects it is being run in the context of a debugger. |
| T1559 Inter-Process Communication |
StealBit can use interprocess communication (IPC) to enable the designation of multiple files for exfiltration in a scalable manner. |
| T1614.001 System Language Discovery |
StealBit can determine system location based on the default language setting and will not execute on systems located in former Soviet countries. |
| T1622 Debugger Evasion |
StealBit can detect it is being run in the context of a debugger. |
| T1685 Disable or Modify Tools |
StealBit can configure processes to not display certain Windows error messages by through use of the `NtSetInformationProcess`. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.