Remote Data Staging

T1074.002

Sub-technique of T1074 Data Staged.View on attack.mitre.org

About this technique

Adversaries may stage data collected from multiple systems in a central location or directory on one system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location.

In cloud environments, adversaries may stage data within a particular instance or virtual machine before exfiltration. An adversary may Create Cloud Instance and stage data in that instance.

By staging data on one system prior to Exfiltration, adversaries can minimize the number of connections made to their C2 server and better evade detection.

Detection rules0

Rules on DetectionCode tagged with T1074.002.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups11

Software1

Campaigns2

Procedure examples14

Groups11

Used byProcedure example
GroupAPT28

APT28 has staged archives of collected data on a target's Outlook Web Access (OWA) server.

GroupChimera

Chimera has staged stolen data on designated servers in the target environment.

GroupFIN6

FIN6 actors have compressed data from remote systems and moved it to another staging system before exfiltration.

GroupFIN8

FIN8 aggregates staged data from a network into a single location.

GroupLeviathan

Leviathan has staged data remotely prior to exfiltration.

GroupmenuPass

menuPass has staged data on remote MSP systems or other victim networks prior to exfiltration.

GroupMirrorFace

MirrorFace has gathered data and files of interest on a single victim machine.

GroupMoustachedBouncer

MoustachedBouncer has used plugins to save captured screenshots to `.\AActdata\` on an SMB share.

View all 11 groups examples

Software1

Used byProcedure example
Malwareccf32

ccf32 has copied files to a remote machine infected with Chinoxy or another backdoor.

Campaigns2

Used byProcedure example
CampaignNight Dragon

During Night Dragon, threat actors copied files to company web servers and subsequently downloaded them.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 staged data and files in password-protected archives on a victim's OWA server.

References1

  1. Mandiant M-Trends 2020 Open source
    Mandiant. (2020, February). M-Trends 2020. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.