ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1567.002×

16 examples

TechniqueUsed byProcedure example
T1567.002
Exfiltration to Cloud Storage
MalwareTsundere Botnet

Tsundere Botnet’s variant DinDoor has used Rclone to access a Wasabi server.

T1567.002
Exfiltration to Cloud Storage
MalwareRainyDay

RainyDay can use a file exfiltration tool to upload specific files to Dropbox.

T1567.002
Exfiltration to Cloud Storage
MalwareHAMMERTOSS

HAMMERTOSS exfiltrates data by uploading it to accounts created by the actors on Web cloud storage providers for the adversaries to retrieve later.

T1567.002
Exfiltration to Cloud Storage
MalwareODAgent

ODAgent can use an attacker-controlled OneDrive account for exfiltration.

T1567.002
Exfiltration to Cloud Storage
MalwareROKRAT

ROKRAT can send collected data to cloud storage services such as PCloud.

T1567.002
Exfiltration to Cloud Storage
MalwareClambling

Clambling can send files from a victim's machine to Dropbox.

T1567.002
Exfiltration to Cloud Storage
MalwareCreepyDrive

CreepyDrive can use cloud services including OneDrive for data exfiltration.

T1567.002
Exfiltration to Cloud Storage
MalwareBoxCaon

BoxCaon has the capability to download folders' contents on the system and upload the results back to its Dropbox drive.

T1567.002
Exfiltration to Cloud Storage
MalwareCrutch

Crutch has exfiltrated stolen data to Dropbox.

T1567.002
Exfiltration to Cloud Storage
MalwareOilBooster

OilBooster can exfiltrate files to an actor-controlled OneDrive account via the Microsoft Graph API.

T1567.002
Exfiltration to Cloud Storage
MalwareBoomBox

BoomBox can upload data to dedicated per-victim folders in Dropbox.

T1567.002
Exfiltration to Cloud Storage
MalwareRIFLESPINE

RIFLESPINE can upload results from executed C2 commands to cloud storage.

T1567.002
Exfiltration to Cloud Storage
MalwareOctopus

Octopus has exfiltrated data to file sharing sites.

T1567.002
Exfiltration to Cloud Storage
MalwarePcexter

Pcexter can upload stolen files to OneDrive storage accounts via HTTP `POST`.

T1567.002
Exfiltration to Cloud Storage
ToolEmpire

Empire can use Dropbox for data exfiltration.

T1567.002
Exfiltration to Cloud Storage
ToolRclone

Rclone can exfiltrate data to cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.