Exbyte — Malware Profile
Exbyte is an exfiltration tool written in Go that is uniquely associated with BlackByte operations. Observed since 2022, Exbyte transfers collected files to online file sharing and hosting services.
MITRE ATT&CK techniques (9)
- T1069.001 Local Groups
- T1070.004 File Deletion
- T1083 File and Directory Discovery
- T1106 Native API
- T1140 Deobfuscate/Decode Files or Information
- T1480 Execution Guardrails
- T1497.001 System Checks
- T1518.001 Security Software Discovery
- T1567 Exfiltration Over Web Service