Exfiltration Over Alternative Protocol

T1048

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.

Alternate protocols include FTP, SMTP, HTTP/S, DNS, SMB, or any other network protocol not being used as the main command and control channel. Adversaries may also opt to encrypt and/or obfuscate these alternate channels.

Exfiltration Over Alternative Protocol can be done using various common operating system utilities such as Net/SMB or FTP. On macOS and Linux curl may be used to invoke protocols such as HTTP/S or FTP/S to exfiltrate data from a system.

Many IaaS and SaaS platforms (such as Microsoft Exchange, Microsoft SharePoint, GitHub, and AWS S3) support the direct download of files, emails, source code, and other sensitive information via the web console or Cloud API.

Detection rules37

Rules on DetectionCode tagged with T1048 or one of its sub-techniques.

Sigma18

RuleLevelLog sourceTechnique
DNS Exfiltration and Tunneling Tools Executionhighwindows / process_creationT1048.001
Powershell DNSExfiltrationhighwindows / ps_scriptT1048
PUA - Restic Backup Tool Executionhighwindows / process_creationT1048
Suspicious Redirection to Local Admin Sharehighwindows / process_creationT1048
Suspicious WebDav Client Execution Via Rundll32.EXEhighwindows / process_creationT1048.003
Copy From Or To Admin Share Or Sysvol Foldermediumwindows / process_creationT1048
Data Exfiltration with Wgetmediumlinux / NULLT1048.003
Data Export From MSSQL Table Via BCP.EXEmediumwindows / process_creationT1048
DNS TOR Proxiesmediumzeek / NULLT1048
PowerShell ICMP Exfiltrationmediumwindows / ps_scriptT1048.003
Python WebServer Execution - Linuxmediumlinux / process_creationT1048.003
Suspicious DNS Query with B64 Encoded StringmediumNULL / dnsT1048.003
Suspicious Outbound SMTP Connectionsmediumwindows / network_connectionT1048.003
Tap Driver Installationmediumwindows / NULLT1048
Tap Installer Executionmediumwindows / process_creationT1048

Splunk19

RuleTypeRiskData sourceTechnique
Cisco ASA - Device File Copy to Remote LocationAnomalyNULLCisco ASA LogsT1048.003
Cisco Secure Firewall - Potential Data ExfiltrationAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1048.003
Clients Connecting to Multiple DNS ServersTTPNULLT1048.003
Detect DNS Data Exfiltration using pretrained model in DSDLAnomalyNULLT1048.003
Detect Long DNS TXT Record ResponseTTPNULLT1048.003
Detection of DNS TunnelsTTPNULLT1048.003
DNS Exfiltration Using Nslookup AppTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1048
DNS Query Length With High Standard DeviationAnomalyNULLSysmon EventID 22T1048.003
Excessive Usage of NSLOOKUP AppAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1048
Gsuite Outbound Email With Attachment To External DomainHuntingNULLG Suite GmailT1048.003
Linux Shell Pseudo Device Reverse ShellAnomalyNULLSysmon for Linux EventID 1T1048.003
Multiple Archive Files Http Post TrafficTTPNULLSplunk Stream HTTPT1048.003
O365 DLP Rule TriggeredAnomalyNULLOffice 365 Universal Audit LogT1048
Ollama Possible Model Exfiltration Data LeakageAnomalyNULLOllama ServerT1048
Plain HTTP POST Exfiltrated DataTTPNULLSplunk Stream HTTPT1048.003

Sub-techniques3

IDNameExamples
T1048.001Exfiltration Over Symmetric Encrypted Non-C2 Protocol0
T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol8
T1048.003Exfiltration Over Unencrypted Non-C2 Protocol35

Groups2

Software7

Campaigns0

None recorded.

Procedure examples9

Groups2

Used byProcedure example
GroupPlay

Play has used WinSCP to exfiltrate data to actor-controlled accounts.

GroupTeamTNT

TeamTNT has sent locally staged files with collected credentials to C2 servers using cURL.

Software7

Used byProcedure example
ToolAADInternals

AADInternals can directly download cloud user data such as OneDrive files.

MalwareBundlore

Bundlore uses the curl -s -L -o command to exfiltrate archived data to a URL.

MalwareChaes

Chaes has exfiltrated its collected data from the infected machine to the C2, sometimes using the MIME protocol.

MalwareFrameworkPOS

FrameworkPOS can use DNS tunneling for exfiltration of credit card data.

MalwareHydraq

Hydraq connects to a predefined domain on port 443 to exfil gathered information.

MalwareKobalos

Kobalos can exfiltrate credentials over the network via UDP.

MalwarePoetRAT

PoetRAT has used a .NET tool named dog.exe to exiltrate information over an e-mail account.

References2

  1. 20 macOS Common Tools and Techniques Open source
    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.
  2. Palo Alto OilRig Oct 2016 Open source
    Grunzweig, J. and Falcone, R.. (2016, October 4). OilRig Malware Campaign Updates Toolset and Expands Targets. Retrieved May 3, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.