Exfiltration Over Web Service

T1567

Technique with 4 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Web service providers also commonly use SSL/TLS encryption, giving adversaries an added level of protection.

Detection rules44

Rules on DetectionCode tagged with T1567 or one of its sub-techniques.

Sigma26

RuleLevelLog sourceTechnique
Communication To Ngrok Tunneling Service - Linuxhighlinux / network_connectionT1567
Communication To Ngrok Tunneling Service Initiatedhighwindows / network_connectionT1567
Curl File Upload To File Sharing Websiteshighwindows / process_creationT1567.002
DNS Query for Anonfiles.com Domain - DNS Clienthighwindows / NULLT1567.002
DNS Query for Anonfiles.com Domain - Sysmonhighwindows / dns_queryT1567.002
Monero Crypto Coin Mining Pool LookuphighNULL / dnsT1567
Process Initiated Network Connection To Ngrok Domainhighwindows / network_connectionT1567
PUA - Rclone Executionhighwindows / process_creationT1567.002
PUA - Restic Backup Tool Executionhighwindows / process_creationT1567.002
Suspicious Dropbox API Usagehighwindows / network_connectionT1567.002
Arbitrary File Download Via ConfigSecurityPolicy.EXEmediumwindows / process_creationT1567
DNS Query To MEGA Hosting Websitemediumwindows / dns_queryT1567.002
DNS Query To MEGA Hosting Website - DNS Clientmediumwindows / NULLT1567.002
LOLBAS Data Exfiltration by DataSvcUtil.exemediumwindows / process_creationT1567
Network Connection Initiated To BTunnels Domainsmediumwindows / network_connectionT1567

Splunk18

RuleTypeRiskData sourceTechnique
Cisco NVM - Rclone Execution With Network ActivityAnomalyNULLCisco Network Visibility Module Flow DataT1567.002
Cisco Secure Firewall - Connection to File Sharing DomainAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1567.002
Cisco Secure Firewall - Potential Data ExfiltrationAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1567.002
Cisco TFTP Server Configuration for Data ExfiltrationTTPNULLCisco IOS LogsT1567
Gsuite Drive Share In External EmailAnomalyNULLG Suite DriveT1567.002
High Volume of Bytes Out to UrlAnomalyNULLNginx AccessT1567
Linux Gdrive Binary ActivityTTPNULLSysmon for Linux EventID 1T1567
LOLBAS Network Connection On Uncommon PortAnomalyNULLSysmon EventID 3T1567
LOLBAS Rare Network ConnectionAnomalyNULLSysmon EventID 3T1567
LOLBAS With Network TrafficTTPNULLSysmon EventID 3T1567
O365 DLP Rule TriggeredAnomalyNULLOffice 365 Universal Audit LogT1567
O365 Email Access By Security AdministratorTTPNULLOffice 365 Universal Audit LogT1567
O365 Exfiltration via File AccessAnomalyNULLOffice 365 Universal Audit LogT1567
O365 Exfiltration via File DownloadAnomalyNULLOffice 365 Universal Audit LogT1567
O365 Exfiltration via File Sync DownloadAnomalyNULLOffice 365 Universal Audit LogT1567

Sub-techniques4

IDNameExamples
T1567.001Exfiltration to Code Repository4
T1567.002Exfiltration to Cloud Storage44
T1567.003Exfiltration to Text Storage Sites0
T1567.004Exfiltration Over Webhook2

Groups5

Software7

Campaigns4

Procedure examples16

Groups5

Used byProcedure example
GroupAPT28

APT28 can exfiltrate data over Google Drive.

GroupBlackByte

BlackByte has used services such as `anonymfiles.com` and `file.io` to exfiltrate victim data.

GroupContagious Interview

Contagious Interview has leveraged Telegram API to exfiltrate stolen data.

GroupMagic Hound

Magic Hound has used the Telegram API `sendMessage` to relay data on compromised devices.

GroupShinyHunters

ShinyHunters has used compromised Salesforce CRM (Customer Relationship Management) dashboards to exfiltrate bulk data. Additionally, ShinyHunters has used LimeWire, a file-sharing service, to showcase samples of stolen data.

Software7

Used byProcedure example
MalwareAppleSeed

AppleSeed has exfiltrated files using web services.

MalwareDropBook

DropBook has used legitimate web services to exfiltrate data.

MalwareExbyte

Exbyte exfiltrates collected data to online file hosting sites such as `Mega.co.nz`.

MalwareInvisibleFerret

InvisibleFerret has leveraged Telegram chat to upload stolen data using the Telegram API with a bot token.

Toolngrok

ngrok has been used by threat actors to configure servers for data exfiltration.

MalwareOilCheck

OilCheck can upload documents from compromised hosts to a shared Microsoft Office 365 Outlook email account for exfiltration.

MalwareSampleCheck5000

SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve files for exfiltration.

Campaigns4

Used byProcedure example
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary utilized Claude Code to generate a detailed summary report of collected data, which is then reviewed and approved by the adversary prior to exfiltration of data over Claude.

CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 exfiltrated data over public-facing webservers – such as Google Drive.

CampaignC0017

During C0017, APT41 used Cloudflare services for data exfiltration.

CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors exfiltrated data via legitimate Salesforce API communication channels including the Salesforce Data Loader application.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.