Data Transfer Size Limits

T1030

Technique.View on attack.mitre.org

About this technique

An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds. This approach may be used to avoid triggering network data transfer threshold alerts.

Detection rules5

Rules on DetectionCode tagged with T1030.

Sigma2

RuleLevelLog source
Split A File Into Pieceslowmacos / process_creation
Split A File Into Pieces - Linuxlowlinux / NULL

Splunk3

RuleTypeRiskData source
Linux Auditd Data Transfer Size Limits Via SplitAnomalyNULLLinux Auditd Execve
Linux Auditd Data Transfer Size Limits Via Split SyscallAnomalyNULLLinux Auditd Syscall
MacOS Data ChunkingAnomalyNULLOsquery Results

Groups5

Software14

Campaigns2

Procedure examples21

Groups5

Used byProcedure example
GroupAPT28

APT28 has split archived exfiltration files into chunks smaller than 1MB.

GroupAPT41

APT41 transfers post-exploitation files dividing the payload into fixed-size chunks to evade detection.

GroupLuminousMoth

LuminousMoth has split archived files into multiple parts to bypass a 5MB limit.

GroupPlay

Play has split victims' files into chunks for exfiltration.

GroupThreat Group-3390

Threat Group-3390 actors have split RAR files for exfiltration into parts.

Software14

Used byProcedure example
MalwareAppleSeed

AppleSeed has divided files if the size is 0x1000000 bytes or more.

MalwareCarbanak

Carbanak exfiltrates data in compressed chunks if a message is larger than 4096 bytes .

MalwareCobalt Strike

Cobalt Strike will break large data sets into smaller chunks for exfiltration.

MalwareHelminth

Helminth splits data into chunks up to 23 bytes and sends the data in DNS queries to its C2 server.

MalwareKessel

Kessel can split the data to be exilftrated into chunks that will fit in subdomains of DNS queries.

MalwareKevin

Kevin can exfiltrate data to the C2 server in 27-character chunks.

MalwareLunarWeb

LunarWeb can split exfiltrated data that exceeds 1.33 MB in size into multiple random sized parts between 384 and 512 KB.

ToolMythic

Mythic supports custom chunk sizes used to upload/download files.

View all 14 software examples

Campaigns2

Used byProcedure example
CampaignC0015

During C0015, the threat actors limited Rclone's bandwidth setting during exfiltration.

CampaignC0026

During C0026, the threat actors split encrypted archives containing stolen files and information into 3MB parts prior to exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.