Exbyte checks whether the process is running with privileged local access during execution.2
tool
Exbyte S1179
- Type
- malware
- Platform
- Windows
- Created
- 17 December 2024
- Last modified
- 9 March 2025
Exbyte is an exfiltration tool written in Go that is uniquely associated with BlackByte operations. Observed since 2022, Exbyte transfers collected files to online file sharing and hosting services.[1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S1179
Exbyte will self-delete if a hard-coded configuration file is not found.3
Exbyte enumerates all document files on an infected machine, then creates a summary of these items including filename and directory location prior to exfiltration to cloud hosting services.4
Exbyte calls ShellExecuteW with the IpOperation parameter RunAs to launch explorer.exe with elevated privileges.5
Exbyte decodes and decrypts data stored in the configuration file with a key provided on the command line during execution.6
Exbyte checks for the presence of a configuration file before completing execution.7
Standing S1179
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
44th percentile · 56% of 825 ATT&CK software entries have more Enterprise techniques.
32nd percentile · 68% of 825 ATT&CK software entries have more tactics spanned.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
48th percentile · 52% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S1179
158 distinct rules cover the 9 techniques recorded for this tool. 112 Sigma · 46 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org