Transfer Data to Cloud Account

T1537

Technique.View on attack.mitre.org

About this technique

Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.

A defender who is monitoring for large transfers to outside the cloud environment through normal file transfers or over command and control channels may not be watching for data transfers to another account within the same cloud provider. Such transfers may utilize existing cloud provider APIs and the internal address space of the cloud provider to blend into normal traffic or avoid data transfers over external network interfaces.

Adversaries may also use cloud-native mechanisms to share victim data with adversary-controlled cloud accounts, such as creating anonymous file sharing links or, in Azure, a shared access signature (SAS) URI.

Incidents have been observed where adversaries have created backups of cloud instances and transferred them to separate accounts.

Detection rules13

Rules on DetectionCode tagged with T1537.

Sigma6

Splunk7

RuleTypeRiskData source
ASL AWS EC2 Snapshot Shared ExternallyTTPNULLASL AWS CloudTrail
AWS AMI Attribute Modification for ExfiltrationTTPNULLAWS CloudTrail ModifyImageAttribute
AWS EC2 Snapshot Shared ExternallyTTPNULLAWS CloudTrail ModifySnapshotAttribute
AWS Exfiltration via Bucket ReplicationTTPNULLAWS CloudTrail PutBucketReplication
AWS Exfiltration via EC2 SnapshotTTPNULLAWS CloudTrail CreateSnapshot, AWS CloudTrail DescribeSnapshotAttribute, AWS CloudTrail ModifySnapshotAttribute, AWS CloudTrail DeleteSnapshot
AWS S3 Exfiltration Behavior IdentifiedCorrelationNULL
High Frequency Copy Of Files In Network ShareAnomalyNULLWindows Event Log Security 5145

Groups3

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

Groups3

Used byProcedure example
GroupINC Ransom

INC Ransom has used Megasync to exfiltrate data to the cloud.

GroupRedCurl

RedCurl has used cloud storage to exfiltrate data, in particular the megatools utilities were used to exfiltrate data to Mega, a file storage service.

GroupStorm-0501

Storm-0501 has copied data from the victims environment to their own infrastructure leveraging AzCopy CLI.

References3

  1. DOJ GRU Indictment Jul 2018 Open source
    Mueller, R. (2018, July 13). Indictment - United States of America vs. VIKTOR BORISOVICH NETYKSHO, et al. Retrieved November 17, 2024.
  2. Microsoft Azure Storage Shared Access Signature Open source
    Microsoft. (2023, June 7). Grant limited access to Azure Storage resources using shared access signatures (SAS). Retrieved March 4, 2024.
  3. TLDRSec AWS Attacks Open source
    Clint Gibler and Scott Piper. (2021, January 4). Lesser Known Techniques for Attacking AWS Environments. Retrieved March 4, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.