BlackByte ransomware has added a new data-stealing tool to its arsenal.
Affiliate of the BlackByte ransomware is now using a custom data theft tool, “ExByte,” to quickly steal data from compromised Windows devices.
In double-extortion attacks, data exfiltration is one of the most critical steps. In these types of attacks, companies are more likely to pay a ransom to prevent their data from being extorted than to receive a decryptor.
Because of this, ransomware companies, such as ALPHV and LockBit, are constantly working to improve their data-stealing tools.
Alternatively, other threat actors, such as the Karakurt group, do not even spend time encrypting local copies and focus only on data exfiltration.
See also: TikTok denies it could be used to track citizens in the US

Exbyte is the perfect tool for data leakage
Symantec security researchers discovered Exbyte, saying that threat actors are using it to upload stolen files directly from the Go-based exfiltration tool to Mega cloud storage .
This tool immediately runs anti-analysis checks to determine if it is running in a safe environment, as well as looking for debuggers and antivirus processes.
See also: Energy company EnergyAustralia suffered a cyberattack
Exbyte verifies the following processes:
- MegaDumper 1.0 by CodeCracker / SnD
- Import reconstructor
- x64dbg
- x32dbg
- OLLYDBG
- WinDbg
- The Interactive Disassembler
- Immunity Debugger – [CPU]
Additionally, the malware will check for the presence of the following DLL files:
- avghooka.dll
- avghookx.dll
- sxin.dll
- sf2.dll
- sbiedll.dll
- snxhk.dll
- cmdvrt32.dll
- cmdvrt64.dll
- wpespy.dll
- vmcheck.dll
- pstorec.dll
- dir_watch.dll
- api_log.dll
- dbghelp.dll
The BlackByte ransomware binary performs the same tests, but the exfiltration tool must run them separately, as the data is extracted before the files are encrypted .
If the tests fail, Exbyte creates a list of all document files on the compromised system and transfers them to an empty folder on Mega using the hardcoded credentials of another account.
BlackByte continues to grow
Operation BlackByte officially began operating in the summer of 2021. Within a little less than six months, they had infiltrated and stolen information from various private organizations as well as some public bodies.
The recent BlackByte attacks exploit Microsoft Exchange servers that have ProxyShell and ProxyLogon from last year, according to Symantec analysts.
Additionally, hackers use tools like AdFind, AnyDesk, NetScan, and PowerView to move laterally within a system.
See also: OldGremlin: Uses Linux ransomware to target Russian organizations
BlackByte uses some of the same methods used by other ransomware, such as deleting shadow copies to prevent easy data. Another method used is modifying firewall settings to open all remote connections. The malware then eventually runs on an instance of “scvhost.exe” to encrypt any files it finds.

Yesterday, Intel 471 published a report stating that in the third quarter of 2022, BlackByte's primary target was organizations located in Africa to avoid any potential conflict with Western law enforcement.
Information source: bleepingcomputer.com
