Real-world descriptions of how a group, tool or campaign used a technique.
25 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1567.002 Exfiltration to Cloud Storage |
GroupIndrik Spider | Indrik Spider has exfiltrated data using Rclone or MEGASync prior to deploying ransomware. |
| T1567.002 Exfiltration to Cloud Storage |
GroupKimsuky | Kimsuky has exfiltrated stolen files and data to actor-controlled Blogspot accounts. Kimsuky has also leveraged Dropbox for uploading victim system information. |
| T1567.002 Exfiltration to Cloud Storage |
GroupHAFNIUM | HAFNIUM has exfiltrated data to file sharing sites, including MEGA. |
| T1567.002 Exfiltration to Cloud Storage |
GroupMuddyWater | MuddyWater has attempted to exfiltrate data to Wasabi, a cloud storage service, using Rclone. |
| T1567.002 Exfiltration to Cloud Storage |
GroupFIN7 | FIN7 has exfiltrated stolen data to the MEGA file sharing site. |
| T1567.002 Exfiltration to Cloud Storage |
GroupMustang Panda | Mustang Panda has also exfiltrated archived files to cloud services such as Dropbox using `curl`. |
| T1567.002 Exfiltration to Cloud Storage |
GroupZIRCONIUM | ZIRCONIUM has exfiltrated stolen data to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
GroupScattered Spider | Scattered Spider has exfiltrated victim data to the MEGA file sharing site, SnowFlake, and AWS S3 buckets. |
| T1567.002 Exfiltration to Cloud Storage |
GroupContagious Interview | Contagious Interview has exfiltrated stolen passwords to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
GroupAkira | Akira will exfiltrate victim data using applications such as Rclone. |
| T1567.002 Exfiltration to Cloud Storage |
GroupPOLONIUM | POLONIUM has exfiltrated stolen data to POLONIUM-owned OneDrive and Dropbox accounts. |
| T1567.002 Exfiltration to Cloud Storage |
GroupConfucius | Confucius has exfiltrated victim data to cloud storage service accounts. |
| T1567.002 Exfiltration to Cloud Storage |
GroupLeviathan | Leviathan has used an uploader known as LUNCHMONEY that can exfiltrate files to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
GroupTurla | Turla has used WebDAV to upload stolen USB files to a cloud drive. Turla has also exfiltrated stolen files to OneDrive and 4shared. |
| T1567.002 Exfiltration to Cloud Storage |
GroupStorm-0501 | Storm-0501 has exfiltrated stolen data to the MEGA file sharing site. Storm-0501 has also utilized Rclone to exfiltrate data from victim environments to cloud storage such as MegaSync. Storm-0501 has exfiltrated data to their own infrastructure utilizing AzCopy Command-Line tool (CLI). |
| T1567.002 Exfiltration to Cloud Storage |
GroupCinnamon Tempest | Cinnamon Tempest has uploaded captured keystroke logs to the Alibaba Cloud Object Storage Service, Aliyun OSS. |
| T1567.002 Exfiltration to Cloud Storage |
GroupChimera | Chimera has exfiltrated stolen data to OneDrive accounts. |
| T1567.002 Exfiltration to Cloud Storage |
GroupMedusa Group | Medusa Group has utilized Rclone to exfiltrate data from victim environments to cloud storage. |
| T1567.002 Exfiltration to Cloud Storage |
GroupEmber Bear | Ember Bear has used tools such as Rclone to exfiltrate information from victim environments to cloud storage such as `mega.nz`. |
| T1567.002 Exfiltration to Cloud Storage |
GroupToddyCat | ToddyCat has used a DropBox uploader to exfiltrate stolen files. |
| T1567.002 Exfiltration to Cloud Storage |
GroupLuminousMoth | LuminousMoth has exfiltrated data to Google Drive. |
| T1567.002 Exfiltration to Cloud Storage |
GroupEarth Lusca | Earth Lusca has used the megacmd tool to upload stolen files from a victim network to MEGA. |
| T1567.002 Exfiltration to Cloud Storage |
GroupWizard Spider | Wizard Spider has exfiltrated stolen victim data to various cloud storage providers. |
| T1567.002 Exfiltration to Cloud Storage |
GroupHEXANE | HEXANE has used cloud services, including OneDrive, for data exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
GroupThreat Group-3390 | Threat Group-3390 has exfiltrated stolen data to Dropbox. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.