Technique.View on attack.mitre.org
Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
A defender who is monitoring for large transfers to outside the cloud environment through normal file transfers or over command and control channels may not be watching for data transfers to another account within the same cloud provider. Such transfers may utilize existing cloud provider APIs and the internal address space of the cloud provider to blend into normal traffic or avoid data transfers over external network interfaces.
Adversaries may also use cloud-native mechanisms to share victim data with adversary-controlled cloud accounts, such as creating anonymous file sharing links or, in Azure, a shared access signature (SAS) URI.
Incidents have been observed where adversaries have created backups of cloud instances and transferred them to separate accounts.
Rules on DetectionCode tagged with T1537.
| Rule | Level | Log source |
|---|---|---|
| AWS Snapshot Backup Exfiltration | medium | aws / NULL |
| Data Exfiltration to Unsanctioned Apps | medium | m365 / NULL |
| Github Fork Private Repositories Setting Enabled/Cleared | medium | github / NULL |
| Github Repository/Organization Transferred | medium | github / NULL |
| AWS EC2 VM Export Failure | low | aws / NULL |
| AWS S3 Data Management Tampering | low | aws / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| ASL AWS EC2 Snapshot Shared Externally | TTP | NULL | ASL AWS CloudTrail |
| AWS AMI Attribute Modification for Exfiltration | TTP | NULL | AWS CloudTrail ModifyImageAttribute |
| AWS EC2 Snapshot Shared Externally | TTP | NULL | AWS CloudTrail ModifySnapshotAttribute |
| AWS Exfiltration via Bucket Replication | TTP | NULL | AWS CloudTrail PutBucketReplication |
| AWS Exfiltration via EC2 Snapshot | TTP | NULL | AWS CloudTrail CreateSnapshot, AWS CloudTrail DescribeSnapshotAttribute, AWS CloudTrail ModifySnapshotAttribute, AWS CloudTrail DeleteSnapshot |
| AWS S3 Exfiltration Behavior Identified | Correlation | NULL | |
| High Frequency Copy Of Files In Network Share | Anomaly | NULL | Windows Event Log Security 5145 |
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| GroupINC Ransom | INC Ransom has used Megasync to exfiltrate data to the cloud. |
| GroupRedCurl | RedCurl has used cloud storage to exfiltrate data, in particular the megatools utilities were used to exfiltrate data to Mega, a file storage service. |
| GroupStorm-0501 | Storm-0501 has copied data from the victims environment to their own infrastructure leveraging AzCopy CLI. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.