Exfiltration to Code Repository

T1567.001

Sub-technique of T1567 Exfiltration Over Web Service.View on attack.mitre.org

About this technique

Adversaries may exfiltrate data to a code repository rather than over their primary command and control channel. Code repositories are often accessible via an API (ex: https://api.github.com). Access to these APIs are often over HTTPS, which gives the adversary an additional level of protection.

Exfiltration to a code repository can also provide a significant amount of cover to the adversary if it is a popular service already used by hosts within the network.

Detection rules2

Rules on DetectionCode tagged with T1567.001.

Sigma2

RuleLevelLog source
Network Connection Initiated To DevTunnels Domainmediumwindows / network_connection
GitHub Repository Pages Site Changed to Publiclowgithub / NULL

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software4

Campaigns0

None recorded.

Procedure examples4

Software4

Used byProcedure example
ToolEmpire

Empire can use GitHub for data exfiltration.

MalwareMini Shai-Hulud

Mini Shai-Hulud has exfiltrated data through the use of the victim’s own GitHub repository by creating a new public repository using a unique naming convention from a curated list of key words or themes.

MalwareShai-Hulud

Shai-Hulud has created a repository named `Shai-Hulud` under the compromised account that commits a JSON dump that contains system information, environment variables and collected secrets. Shai-Hulud has also posted stolen credentials to public GitHub repositories.

MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can create a repository in the victim's GitHub account using the victim's own GITHUB_TOKEN to upload stolen credentials.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.