Automated Exfiltration

T1020

Technique with 1 sub-technique.View on attack.mitre.org

About this technique

Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.

When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel and Exfiltration Over Alternative Protocol.

Detection rules12

Rules on DetectionCode tagged with T1020 or one of its sub-techniques.

Sigma8

Splunk4

RuleTypeRiskData sourceTechnique
Detect RClone Command-Line UsageTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow DataT1020
Detect Renamed RCloneHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1020
Detect Traffic MirroringTTPNULLCisco IOS LogsT1020.001
Windows Mustang Panda USB Tool ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1020

Sub-techniques1

IDNameExamples
T1020.001Traffic Duplication0

Groups7

Software21

Campaigns3

Procedure examples31

Groups7

Used byProcedure example
GroupGamaredon Group

Gamaredon Group has used modules that automatically upload gathered documents to the C2 server.

GroupKe3chang

Ke3chang has performed frequent and scheduled data exfiltration from compromised networks.

GroupKimsuky

Kimsuky has exfiltrated data to C2 servers using an automated script that executes every 10 minutes and after successful checks for the presence of pre-designated staged filenames.

GroupRedCurl

RedCurl has used batch scripts to exfiltrate data.

GroupSidewinder

Sidewinder has configured tools to automatically send collected files to attacker controlled servers.

GroupTropic Trooper

Tropic Trooper has used a copy function to automatically exfiltrate sensitive data from air-gapped systems using USB storage.

GroupWinter Vivern

Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.

Software21

Used byProcedure example
MalwareAttor

Attor has a file uploader plugin that automatically exfiltrates the collected data and log files to the C2 server.

MalwareCosmicDuke

CosmicDuke exfiltrates collected files automatically over FTP to remote servers.

MalwareCrutch

Crutch has automatically exfiltrated stolen files to Dropbox.

MalwareDoki

Doki has used a script that gathers information from a hardcoded list of IP addresses and uploads to an Ngrok URL.

MalwareEbury

If credentials are not collected for two weeks, Ebury encrypts the credentials using a public key and sends them via UDP to an IP address located in the DNS TXT record.

ToolEmpire

Empire has the ability to automatically send collected data back to the threat actors' C2.

MalwareHannotog

Hannotog can upload encyrpted data for exfiltration.

MalwareLightNeuron

LightNeuron can be configured to automatically exfiltrate files under a specified directory.

View all 21 software examples

Campaigns3

Used byProcedure example
CampaignArcaneDoor

ArcaneDoor included scripted exfiltration of collected data.

CampaignFrankenstein

During Frankenstein, the threat actors collected information via Empire, which was automatically sent back to the adversary's C2.

CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used API queries to automatically exfiltrate large volumes of data.

References1

  1. ESET Gamaredon June 2020 Open source
    Boutin, J. (2020, June 11). Gamaredon group grows its game. Retrieved June 16, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.