ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1567.002×

25 examples

TechniqueUsed byProcedure example
T1567.002
Exfiltration to Cloud Storage
GroupIndrik Spider

Indrik Spider has exfiltrated data using Rclone or MEGASync prior to deploying ransomware.

T1567.002
Exfiltration to Cloud Storage
GroupKimsuky

Kimsuky has exfiltrated stolen files and data to actor-controlled Blogspot accounts. Kimsuky has also leveraged Dropbox for uploading victim system information.

T1567.002
Exfiltration to Cloud Storage
GroupHAFNIUM

HAFNIUM has exfiltrated data to file sharing sites, including MEGA.

T1567.002
Exfiltration to Cloud Storage
GroupMuddyWater

MuddyWater has attempted to exfiltrate data to Wasabi, a cloud storage service, using Rclone.

T1567.002
Exfiltration to Cloud Storage
GroupFIN7

FIN7 has exfiltrated stolen data to the MEGA file sharing site.

T1567.002
Exfiltration to Cloud Storage
GroupMustang Panda

Mustang Panda has also exfiltrated archived files to cloud services such as Dropbox using `curl`.

T1567.002
Exfiltration to Cloud Storage
GroupZIRCONIUM

ZIRCONIUM has exfiltrated stolen data to Dropbox.

T1567.002
Exfiltration to Cloud Storage
GroupScattered Spider

Scattered Spider has exfiltrated victim data to the MEGA file sharing site, SnowFlake, and AWS S3 buckets.

T1567.002
Exfiltration to Cloud Storage
GroupContagious Interview

Contagious Interview has exfiltrated stolen passwords to Dropbox.

T1567.002
Exfiltration to Cloud Storage
GroupAkira

Akira will exfiltrate victim data using applications such as Rclone.

T1567.002
Exfiltration to Cloud Storage
GroupPOLONIUM

POLONIUM has exfiltrated stolen data to POLONIUM-owned OneDrive and Dropbox accounts.

T1567.002
Exfiltration to Cloud Storage
GroupConfucius

Confucius has exfiltrated victim data to cloud storage service accounts.

T1567.002
Exfiltration to Cloud Storage
GroupLeviathan

Leviathan has used an uploader known as LUNCHMONEY that can exfiltrate files to Dropbox.

T1567.002
Exfiltration to Cloud Storage
GroupTurla

Turla has used WebDAV to upload stolen USB files to a cloud drive. Turla has also exfiltrated stolen files to OneDrive and 4shared.

T1567.002
Exfiltration to Cloud Storage
GroupStorm-0501

Storm-0501 has exfiltrated stolen data to the MEGA file sharing site. Storm-0501 has also utilized Rclone to exfiltrate data from victim environments to cloud storage such as MegaSync. Storm-0501 has exfiltrated data to their own infrastructure utilizing AzCopy Command-Line tool (CLI).

T1567.002
Exfiltration to Cloud Storage
GroupCinnamon Tempest

Cinnamon Tempest has uploaded captured keystroke logs to the Alibaba Cloud Object Storage Service, Aliyun OSS.

T1567.002
Exfiltration to Cloud Storage
GroupChimera

Chimera has exfiltrated stolen data to OneDrive accounts.

T1567.002
Exfiltration to Cloud Storage
GroupMedusa Group

Medusa Group has utilized Rclone to exfiltrate data from victim environments to cloud storage.

T1567.002
Exfiltration to Cloud Storage
GroupEmber Bear

Ember Bear has used tools such as Rclone to exfiltrate information from victim environments to cloud storage such as `mega.nz`.

T1567.002
Exfiltration to Cloud Storage
GroupToddyCat

ToddyCat has used a DropBox uploader to exfiltrate stolen files.

T1567.002
Exfiltration to Cloud Storage
GroupLuminousMoth

LuminousMoth has exfiltrated data to Google Drive.

T1567.002
Exfiltration to Cloud Storage
GroupEarth Lusca

Earth Lusca has used the megacmd tool to upload stolen files from a victim network to MEGA.

T1567.002
Exfiltration to Cloud Storage
GroupWizard Spider

Wizard Spider has exfiltrated stolen victim data to various cloud storage providers.

T1567.002
Exfiltration to Cloud Storage
GroupHEXANE

HEXANE has used cloud services, including OneDrive, for data exfiltration.

T1567.002
Exfiltration to Cloud Storage
GroupThreat Group-3390

Threat Group-3390 has exfiltrated stolen data to Dropbox.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.