Investigating the use of custom data exfiltration tools
In 2021, some representatives of popular ransomware-as-a-service programs introduced custom data exfiltration tools as an addition to the ransomware itself. One notable example is StealBit, an information stealer distributed as part of LockBit 2.0 RaaS. Other examples include Sidoh, which was used by Ryuk ransomware affiliates, and ExMatter, which was used by BlackMatter ransomware affiliates.
In some cases, it's really easy to spot during incident investigations – ransomware affiliates may use an executable named StealBit.exe. So, you can extract information from various sources of evidence of execution you are already well aware of, and search for files with similar names. If the threat actors prefer to use masquerading techniques, just focus on staging folders used by the attackers, or use timelines to find pivot points.
...