Technique with 4 sub-techniques.View on attack.mitre.org
Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.
Web service providers also commonly use SSL/TLS encryption, giving adversaries an added level of protection.
Rules on DetectionCode tagged with T1567 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Cisco NVM - Rclone Execution With Network Activity | Anomaly | NULL | Cisco Network Visibility Module Flow Data | T1567.002 |
| Cisco Secure Firewall - Connection to File Sharing Domain | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event | T1567.002 |
| Cisco Secure Firewall - Potential Data Exfiltration | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event | T1567.002 |
| Cisco TFTP Server Configuration for Data Exfiltration | TTP | NULL | Cisco IOS Logs | T1567 |
| Gsuite Drive Share In External Email | Anomaly | NULL | G Suite Drive | T1567.002 |
| High Volume of Bytes Out to Url | Anomaly | NULL | Nginx Access | T1567 |
| Linux Gdrive Binary Activity | TTP | NULL | Sysmon for Linux EventID 1 | T1567 |
| LOLBAS Network Connection On Uncommon Port | Anomaly | NULL | Sysmon EventID 3 | T1567 |
| LOLBAS Rare Network Connection | Anomaly | NULL | Sysmon EventID 3 | T1567 |
| LOLBAS With Network Traffic | TTP | NULL | Sysmon EventID 3 | T1567 |
| O365 DLP Rule Triggered | Anomaly | NULL | Office 365 Universal Audit Log | T1567 |
| O365 Email Access By Security Administrator | TTP | NULL | Office 365 Universal Audit Log | T1567 |
| O365 Exfiltration via File Access | Anomaly | NULL | Office 365 Universal Audit Log | T1567 |
| O365 Exfiltration via File Download | Anomaly | NULL | Office 365 Universal Audit Log | T1567 |
| O365 Exfiltration via File Sync Download | Anomaly | NULL | Office 365 Universal Audit Log | T1567 |
| Windows Azure Storage Utility Execution Via CLI | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1567.002 |
| Windows Gdrive Binary Activity | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1567 |
| Windows OneDrive Share Mounted via Net | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1567.002 |
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 can exfiltrate data over Google Drive. |
| GroupBlackByte | BlackByte has used services such as `anonymfiles.com` and `file.io` to exfiltrate victim data. |
| GroupContagious Interview | Contagious Interview has leveraged Telegram API to exfiltrate stolen data. |
| GroupMagic Hound | Magic Hound has used the Telegram API `sendMessage` to relay data on compromised devices. |
| GroupShinyHunters | ShinyHunters has used compromised Salesforce CRM (Customer Relationship Management) dashboards to exfiltrate bulk data. Additionally, ShinyHunters has used LimeWire, a file-sharing service, to showcase samples of stolen data. |
| Used by | Procedure example |
|---|---|
| MalwareAppleSeed | AppleSeed has exfiltrated files using web services. |
| MalwareDropBook | DropBook has used legitimate web services to exfiltrate data. |
| MalwareExbyte | Exbyte exfiltrates collected data to online file hosting sites such as `Mega.co.nz`. |
| MalwareInvisibleFerret | InvisibleFerret has leveraged Telegram chat to upload stolen data using the Telegram API with a bot token. |
| Toolngrok | ngrok has been used by threat actors to configure servers for data exfiltration. |
| MalwareOilCheck | OilCheck can upload documents from compromised hosts to a shared Microsoft Office 365 Outlook email account for exfiltration. |
| MalwareSampleCheck5000 | SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve files for exfiltration. |
| Used by | Procedure example |
|---|---|
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary utilized Claude Code to generate a detailed summary report of collected data, which is then reviewed and approved by the adversary prior to exfiltration of data over Claude. |
| CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 exfiltrated data over public-facing webservers – such as Google Drive. |
| CampaignC0017 | During C0017, APT41 used Cloudflare services for data exfiltration. |
| CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors exfiltrated data via legitimate Salesforce API communication channels including the Salesforce Data Loader application. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.