StealBit

S1200

Malware.View on attack.mitre.org

About this malware

StealBit is a data exfiltration tool that is developed and maintained by the operators of the the LockBit Ransomware-as-a-Service (RaaS) and offered to affiliates to exfiltrate data from compromised systems for double extortion purposes.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1005
Data from Local System

StealBit can upload data and files to the LockBit victim-shaming site.

T1027.013
Encrypted/Encoded File

StealBit stores obfuscated DLL file names in its executable.

T1030
Data Transfer Size Limits

StealBit can be configured to exfiltrate files at a specified rate to evade network detection mechanisms.

T1070.004
File Deletion

StealBit can self-delete its executable file from the compromised system.

T1071.001
Web Protocols

StealBit can use HTTP to exfiltrate files to actor-controlled infrastructure.

T1082
System Information Discovery

StealBit can enumerate the computer name and domain membership of the compromised system.

T1083
File and Directory Discovery

StealBit can be configured to exfiltrate specific file types.

T1095
Non-Application Layer Protocol

StealBit can use the Windows Socket networking library to communicate with attacker-controlled endpoints.

T1106
Native API

StealBit can use native APIs including `LoadLibraryExA` for execution and `NtSetInformationProcess` for defense evasion purposes.

T1140
Deobfuscate/Decode Files or Information

StealBit can deobfuscate loaded modules prior to execution.

T1480
Execution Guardrails

StealBit will execute an empty infinite loop if it detects it is being run in the context of a debugger.

T1559
Inter-Process Communication

StealBit can use interprocess communication (IPC) to enable the designation of multiple files for exfiltration in a scalable manner.

T1614.001
System Language Discovery

StealBit can determine system location based on the default language setting and will not execute on systems located in former Soviet countries.

T1622
Debugger Evasion

StealBit can detect it is being run in the context of a debugger.

T1685
Disable or Modify Tools

StealBit can configure processes to not display certain Windows error messages by through use of the `NtSetInformationProcess`.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Cybereason StealBit Exfiltration Tool Open source
    Cybereason Global SOC Team. (n.d.). THREAT ANALYSIS REPORT: Inside the LockBit Arsenal - The StealBit Exfiltration Tool. Retrieved January 29, 2025.
  2. FBI Lockbit 2.0 FEB 2022 Open source
    FBI. (2022, February 4). Indicators of Compromise Associated with LockBit 2.0 Ransomware. Retrieved January 24, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.