Data from Cloud Storage

T1530

Technique.View on attack.mitre.org

About this technique

Adversaries may access data from cloud storage.

Many IaaS providers offer solutions for online data object storage such as Amazon S3, Azure Storage, and Google Cloud Storage. Similarly, SaaS enterprise platforms such as Office 365 and Google Workspace provide cloud-based document storage to users through services such as OneDrive and Google Drive, while SaaS application providers such as Slack, Confluence, Salesforce, and Dropbox may provide cloud storage solutions as a peripheral or primary use case of their platform.

In some cases, as with IaaS-based cloud storage, there exists no overarching application (such as SQL or Elasticsearch) with which to interact with the stored objects: instead, data from these solutions is retrieved directly though the Cloud API. In SaaS applications, adversaries may be able to collect this data directly from APIs or backend cloud storage objects, rather than through their front-end application or interface (i.e., Data from Information Repositories).

Adversaries may collect sensitive data from these cloud storage solutions. Providers typically offer security guides to help end users configure systems, though misconfigurations are a common problem. There have been numerous incidents where cloud storage has been improperly secured, typically by unintentionally allowing public access to unauthenticated users, overly-broad access by all users, or even access for any anonymous person outside the control of the Identity Access Management system without even needing basic user permissions.

This open access may expose various types of sensitive data, such as credit cards, personally identifiable information, or medical records.

Adversaries may also obtain then abuse leaked credentials from source repositories, logs, or other means as a way to gain access to cloud storage objects.

Detection rules10

Rules on DetectionCode tagged with T1530.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk10

RuleTypeRiskData source
Cisco ASA - Device File Copy ActivityAnomalyNULLCisco ASA Logs
Detect GCP Storage access from a new IPAnomalyNULL
Detect New Open GCP Storage BucketsTTPNULL
Detect New Open S3 bucketsTTPNULLAWS CloudTrail
Detect New Open S3 Buckets over AWS CLITTPNULLAWS CloudTrail
Detect S3 access from a new IPAnomalyNULL
Detect Spike in S3 Bucket deletionAnomalyNULLAWS CloudTrail
O365 Exfiltration via File AccessAnomalyNULLOffice 365 Universal Audit Log
O365 Exfiltration via File DownloadAnomalyNULLOffice 365 Universal Audit Log
O365 Exfiltration via File Sync DownloadAnomalyNULLOffice 365 Universal Audit Log

Groups6

Software4

Campaigns2

Procedure examples12

Groups6

Used byProcedure example
GroupAPT42

APT42 has collected data from Microsoft 365 environments.

GroupFox Kitten

Fox Kitten has obtained files from the victim's cloud storage instances.

GroupHAFNIUM

HAFNIUM has exfitrated data from OneDrive.

GroupScattered Spider

Scattered Spider enumerates data stored in cloud resources for collection and exfiltration purposes.

GroupShinyHunters

ShinyHunters has collected data from insecure cloud buckets.

GroupStorm-0501

Storm-0501 had modified Azure Storage account resources through the `Microsoft.Storage/storageAccounts/write` operation to expose non-remotely accessible accounts for data exfiltration.

Software4

Used byProcedure example
ToolAADInternals

AADInternals can collect files from a user’s OneDrive.

ToolPacu

Pacu can enumerate and download files stored in AWS storage services, such as S3 buckets.

ToolPeirates

Peirates can dump the contents of AWS S3 buckets. It can also retrieve service account tokens from kOps buckets in Google Cloud Storage or S3.

ToolTruffleHog

TruffleHog has the ability to scan cloud storage services for credentials to include Amazon (AWS) S3 and Google Cloud Storage.

Campaigns2

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials within cloud services to download targeted data from SharePoint, and Teams.

CampaignC0027

During C0027, Scattered Spider accessed victim OneDrive environments to search for VPN and MFA enrollment information, help desk instructions, and new hire guides.

References7

  1. Amazon S3 Security, 2019 Open source
    Amazon. (2019, May 17). How can I secure the files in my Amazon S3 bucket?. Retrieved October 4, 2019.
  2. Google Cloud Storage Best Practices, 2019 Open source
    Google. (2019, September 16). Best practices for Cloud Storage. Retrieved October 4, 2019.
  3. HIPAA Journal S3 Breach, 2017 Open source
    HIPAA Journal. (2017, October 11). 47GB of Medical Records and Test Results Found in Unsecured Amazon S3 Bucket. Retrieved October 4, 2019.
  4. Microsoft Azure Storage Security, 2019 Open source
    Amlekar, M., Brooks, C., Claman, L., et. al.. (2019, March 20). Azure Storage security guide. Retrieved October 4, 2019.
  5. Rclone-mega-extortion_05_2021 Open source
    Justin Schoenfeld, Aaron Didier. (2021, May 4). Transferring leverage in a ransomware attack. Retrieved July 14, 2022.
  6. Trend Micro S3 Exposed PII, 2017 Open source
    Trend Micro. (2017, November 6). A Misconfigured Amazon S3 Exposed Almost 50 Thousand PII in Australia. Retrieved October 4, 2019.
  7. Wired Magecart S3 Buckets, 2019 Open source
    Barrett, B.. (2019, July 11). Hack Brief: A Card-Skimming Hacker Group Hit 17K Domains—and Counting. Retrieved October 4, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.