StealBit is a Windows information-stealing and data-exfiltration malware developed and maintained by the LockBit ransomware operation, tracked as GOLD MYSTIC. Introduced alongside LockBit 2.0 in June 2021, it is supplied to affiliates through the operation’s management panel for deployment in already-compromised organizational networks. It steals victim files, typically before ransomware encryption, to support double-extortion demands involving threatened publication of sensitive data. StealBit is a separate exfiltration utility rather than a ransomware encryptor.
StealBit supports selective file collection, including filtering by file extension and excluding files or folders. Operators can specify targets through command-line arguments or drag files and folders into its graphical interface. It uses Windows I/O completion ports and worker threads to parallelize transfers, with named-pipe communication coordinating multiple instances. File contents are uploaded to embedded attacker-controlled endpoints using HTTP PUT requests, accompanied by metadata identifying the computer, domain, and original file location. Configurations can include multiple endpoints for failover and affiliate identifiers. Analyzed versions transmitted file contents without compression despite advertised compression capabilities.
Defense-evasion features include obfuscated and encrypted strings, runtime resolution of networking functionality, debugger detection, window-hiding controls, and optional self-deletion that overwrites the executable before removing it. Some window-hiding functionality is incomplete in analyzed versions. Transfer-rate controls allow operators to throttle exfiltration. Older samples restricted execution in several former Soviet countries, while newer samples removed that restriction. Its established operational role is post-compromise corporate data theft; it does not itself provide the initial-access mechanisms used by LockBit affiliates.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
StealBit — a tool developed by GOLD MYSTIC to facilitate data exfiltration in LockBit ransomware intrusions
24 distinct techniques documented for this family, organized by ATT&CK tactic.
StealBit stores the XOR obfuscated filenames of these DLLs in the malware’s executable file ... StealBit then decrypts RC4-encrypted strings that the malware stores in the malware’s executable file.
In StealBIT this is implemented by having a hardcoded list of extensions that should be extracted.
Exmatter is designed to steal a range of user files, databases and compressed files ... and then upload them to a preconfigured server via Secure File Transfer Protocol (SFTP).
When a victim’s network was infected by LockBit’s malicious software, their data was stolen and their systems encrypted.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom LockBit-associated tool used for data exfiltration.
A LockBit-associated data theft utility introduced alongside LockBit 2.0 to exfiltrate files as part of double-extortion operations.
Stealbit is a tool used by the LockBit group to exfiltrate data from victim networks prior to or during ransomware attacks, facilitating double extortion tactics.
LockBit 운영에서 데이터 유출(탈취)을 수행하기 위해 사용되는 전용 도구로 언급된다.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.