Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1567.002 Exfiltration to Cloud Storage |
MalwareTsundere Botnet | Tsundere Botnet’s variant DinDoor has used Rclone to access a Wasabi server. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareRainyDay | RainyDay can use a file exfiltration tool to upload specific files to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareHAMMERTOSS | HAMMERTOSS exfiltrates data by uploading it to accounts created by the actors on Web cloud storage providers for the adversaries to retrieve later. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareODAgent | ODAgent can use an attacker-controlled OneDrive account for exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareROKRAT | ROKRAT can send collected data to cloud storage services such as PCloud. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareClambling | Clambling can send files from a victim's machine to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareCreepyDrive | CreepyDrive can use cloud services including OneDrive for data exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareBoxCaon | BoxCaon has the capability to download folders' contents on the system and upload the results back to its Dropbox drive. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareCrutch | Crutch has exfiltrated stolen data to Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareOilBooster | OilBooster can exfiltrate files to an actor-controlled OneDrive account via the Microsoft Graph API. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareBoomBox | BoomBox can upload data to dedicated per-victim folders in Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareRIFLESPINE | RIFLESPINE can upload results from executed C2 commands to cloud storage. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareOctopus | Octopus has exfiltrated data to file sharing sites. |
| T1567.002 Exfiltration to Cloud Storage |
MalwarePcexter | Pcexter can upload stolen files to OneDrive storage accounts via HTTP `POST`. |
| T1567.002 Exfiltration to Cloud Storage |
ToolEmpire | Empire can use Dropbox for data exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
ToolRclone | Rclone can exfiltrate data to cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.