Exmatter, also known as Fendr, is a custom .NET-based data-theft and exfiltration malware targeting Windows systems. Discovered in 2021 in BlackMatter ransomware attacks, it was subsequently used in BlackCat/ALPHV/Noberus, Conti, and LockBit operations. Its creation and use have been attributed to the ransomware affiliate Velvet Tempest, formerly tracked as DEV-0504. Operators deploy it within compromised enterprise networks to steal sensitive business data before ransomware execution, supporting double-extortion attacks.
Exmatter enumerates logical drives and selectively collects documents, databases, email stores, archives, source code, and engineering files. Variant-specific filters select files by extension, size, modification time, and location while excluding operating-system and application directories. Some versions prioritize recently modified files. Stolen data is transferred to attacker-controlled servers using SFTP, WebDAV, or FTP, depending on the variant; WebDAV can serve as a fallback when SFTP fails. Later versions can generate reports of processed files and corrupt collected files through an optional erasure feature.
Observed deployment methods include Group Policy Objects and remote execution with PsExec or network shares. A later variant discovers mapped network drives, coordinates multiple instances through interprocess communication, and remotely executes itself on additional systems while collecting data. When already running with administrative privileges, it can take ownership of otherwise inaccessible files. Defense-evasion features include executable protection and obfuscation, window hiding, and PowerShell-based overwriting and deletion of its own executable. Some versions also support self-destruction in unsuitable execution environments. Exmatter does not exhibit persistence behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
S-RM’s incident response team has observed a new variant of the data exfiltration tool, Exmatter, being used by a LockBit affiliate on a recent ransomware engagement.
Exmatter, which was discovered by Symantec’s Threat Hunter Team, is designed to steal specific file types from a number of selected directories and upload them to an attacker-controlled server prior to deployment of the ransomware itself on the victim’s network.
"...deploying custom data exfiltration tools like ExMatter to siphon sensitive data prior to encryption."
25 distinct techniques documented for this family, organized by ATT&CK tactic.
If executed with administrator rights, it was also able to modify the permissions of files using the command ‘takeown’, which uses the SeTakeOwnershipPrivilege Microsoft API, giving the threat actor ownership permissions over files they were previously denied access to.
Analysis of the Exmatter binary revealed that, beneath multiple layers of obfuscation, including the use of Spanish to write its functions, and encoding large sections of the malware in Base64...
Analysis of the Exmatter binary revealed that... its ability to read mapped network drives from the registry of the host system.
the ransomware and Fendr are delivered simultaneously across a network to many systems as “v2.exe” and “v2c.exe”, or as “v2.exe” and “sender2.exe”
Exmatter... target[s] specific directories and file types for collection and exfiltration.
The use of IPC allowed it to move laterally between network shares on the victim’s network, simultaneously targeting data for exfiltration whilst remotely executing itself on other systems.
The tool, dubbed Fendr, has not only been upgraded to include more file types but also used by the gang extensively to steal data from corporate networks in December 2021 and January 2022 prior to encryption, in a popular tactic called double extortion.
In order to identify files for exfiltration, it will retrieve the drive names of all logical drives on the infected computer and collect all file path names... It will only exfiltrate files with the following extensions... It attempts to prioritize files for exfiltration by using LastWriteTime.
Exmatter is designed to steal a range of user files, databases and compressed files ... and then upload them to a preconfigured server via Secure File Transfer Protocol (SFTP).
Between November 3 and December 26, 673,977 flows took place... a large majority ... involved only two IP addresses... All of these flows used port 22 of 174.138.64[.]88.
Tool description: “ExMatter… upload… via SFTP” and mapping “T1048… .002: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol”
Of those, a large majority (462,552/673,977) occurred from December 15 onward and involved only two IP addresses, one attributed to the vendor and a DigitalOcean IP address, 174.138.64[.]88. These transfers may represent the attackers’ data exfiltration from the vendor’s network.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data exfiltration tool associated in the report with BlackCat activity; described as connecting from victim networks to remote servers over port 22, consistent with suspected exfiltration traffic in this incident.
Exfiltration tool associated in the report with BlackCat. It is described as using command-and-control infrastructure largely on DigitalOcean IP addresses and exfiltrating data to a remote server over port 22.
Mentioned as another custom data exfiltration tool used in ransomware operations; no further analysis is provided in this content.
A custom-built data exfiltration tool used prior to ransomware deployment to automate collection and theft of sensitive data from Windows environments. This variant targets specific directories and file types, reads mapped network drives from the registry, uses TinyIPC for inter-process communication to support lateral movement and remote execution across network shares, can take ownership of files when run with administrator rights, and exfiltrates data to an attacker-controlled WebDAV server over HTTP PUT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.