Technique.View on attack.mitre.org
Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.
Rules on DetectionCode tagged with T1041.
| Rule | Level | Log source |
|---|---|---|
| OpenCanary - TFTP Request | high | opencanary / application |
| Network Communication Initiated To Portmap.IO Domain | medium | windows / network_connection |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco ASA - Device File Copy to Remote Location | Anomaly | NULL | Cisco ASA Logs |
| Cisco Secure Firewall - High EVE Threat Confidence | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Cisco Secure Firewall - Intrusion Events by Threat Activity | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| Cisco Secure Firewall - Lumma Stealer Download Attempt | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| Cisco Secure Firewall - Potential Data Exfiltration | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Detect SNICat SNI Exfiltration | TTP | NULL | |
| Potential Telegram API Request Via CommandLine | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Exfiltration Over C2 Via Invoke RestMethod | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Exfiltration Over C2 Via Powershell UploadString | TTP | NULL | Powershell Script Block Logging 4104 |
| Used by | Procedure example |
|---|---|
| MalwareADVSTORESHELL | ADVSTORESHELL exfiltrates data over the same channel used for C2. |
| MalwareAmadey | Amadey has sent victim data to its C2 servers. |
| MalwareAppleJeus | AppleJeus has exfiltrated collected host information to a C2 server. |
| MalwareAppleSeed | AppleSeed can exfiltrate files via the C2 channel. |
| MalwareAshTag | AshTag has exfiltrated reconnaissance data on targeted systems to C2 servers. |
| MalwareAstaroth | Astaroth exfiltrates collected information from its r1.log file to the external C2 server. |
| MalwareAttor | Attor has exfiltrated data over the C2 channel. |
| MalwareAuTo Stealer | AuTo Stealer can exfiltrate data over actor-controlled C2 servers via HTTP or TCP. |
View all 166 software examples
| Used by | Procedure example |
|---|---|
| CampaignArcaneDoor | ArcaneDoor included use of existing command and control channels for data exfiltration. |
| CampaignC0017 | During C0017, APT41 used its Cloudflare services C2 channels for data exfiltration. |
| CampaignFrankenstein | During Frankenstein, the threat actors collected information via Empire, which sent the data back to the adversary's C2. |
| CampaignHomeLand Justice | During HomeLand Justice, threat actors used HTTP to transfer data from compromised Exchange servers. |
| CampaignLeviathan Australian Intrusions | Leviathan exfiltrated collected data over existing command and control channels during Leviathan Australian Intrusions. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group exfiltrated data from a compromised host to actor-controlled C2 servers. |
| CampaignOperation Honeybee | During Operation Honeybee, the threat actors uploaded stolen files to their C2 servers. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used the XServer backdoor to exfiltrate data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.