Exfiltration Over Webhook

T1567.004

Sub-technique of T1567 Exfiltration Over Web Service.View on attack.mitre.org

About this technique

Adversaries may exfiltrate data to a webhook endpoint rather than over their primary command and control channel. Webhooks are simple mechanisms for allowing a server to push data over HTTP/S to a client without the need for the client to continuously poll the server. Many public and commercial services, such as Discord, Slack, and `webhook.site`, support the creation of webhook endpoints that can be used by other services, such as Github, Jira, or Trello. When changes happen in the linked services (such as pushing a repository update or modifying a ticket), these services will automatically post the data to the webhook endpoint for use by the consuming application.

Adversaries may link an adversary-owned environment to a victim-owned SaaS service to achieve repeated Automated Exfiltration of emails, chat messages, and other data. Alternatively, instead of linking the webhook endpoint to a service, an adversary can manually post staged data directly to the URL in order to exfiltrate it.

Access to webhook endpoints is often over HTTPS, which gives the adversary an additional level of protection. Exfiltration leveraging webhooks can also blend in with normal network traffic if the webhook endpoint points to a commonly used SaaS application or collaboration service.

Detection rules0

Rules on DetectionCode tagged with T1567.004.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software1

Campaigns1

Procedure examples2

Software1

Used byProcedure example
MalwareShai-Hulud

Shai-Hulud has exfiltrated repository secrets to `webhook[.]site`.

Campaigns1

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged an attacker-controlled Slack channel to exfiltrate data.

References7

  1. Checkmarx Webhooks Open source
    Jossef Harush Kadouri. (2022, March 7). Webhook Party — Malicious packages caught exfiltrating data via legit webhook services. Retrieved July 20, 2023.
  2. CyberArk Labs Discord Open source
    CyberArk Labs. (2023, April 13). The (Not so) Secret War on Discord. Retrieved July 20, 2023.
  3. Discord Intro to Webhooks Open source
    D. (n.d.). Intro to Webhooks. Retrieved July 20, 2023.
  4. Microsoft SQL Server Open source
    Microsoft Threat Intelligence. (2023, October 3). Defending new vectors: Threat actors attempt SQL Server to cloud lateral movement. Retrieved October 3, 2023.
  5. Push Security SaaS Attacks Repository Webhooks Open source
    Push Security. (2023, July 31). Webhooks. Retrieved August 4, 2023.
  6. RedHat Webhooks Open source
    RedHat. (2022, June 1). What is a webhook?. Retrieved July 20, 2023.
  7. Talos Discord Webhook Abuse Open source
    Nick Biasini, Edmund Brumaghin, Chris Neal, and Paul Eubanks. (2021, April 7). https://blog.talosintelligence.com/collab-app-abuse/. Retrieved July 20, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.