1200KM / simulation
T1567.002 Exfiltration to Cloud Storage — Attack Simulation
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet. Examples of cloud storage services include Dropbox and Google Docs. Exfiltration to these cloud storage services can provide a significant amount of cover to the adversary if hosts within the network…
Technique description
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet. Examples of cloud storage services include Dropbox and Google Docs. Exfiltration to these cloud storage services can provide a significant amount of cover to the adversary if hosts within the network…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Exfiltrate data with rclone to cloud Storage - Mega (Windows)
Procedure 8529ee44-279a-4a19-80bf-b846a40dda58; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Exfiltrate data with rclone to cloud Storage - AWS S3
Procedure a4b74723-5cee-4300-91c3-5e34166909b4; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Threat Group-3390 · G0027
- FIN7 · G0046
- Leviathan · G0065
- MuddyWater · G0069
- Kimsuky · G0094
- Wizard Spider · G0102
- Chimera · G0114
- Indrik Spider · G0119
- HAFNIUM · G0125
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- Confucius · G0142
- HEXANE · G1001
- Ember Bear · G1003
- POLONIUM · G1005
- Earth Lusca · G1006
- LuminousMoth · G1014
- Scattered Spider · G1015
- Cinnamon Tempest · G1021
- ToddyCat · G1022
- Akira · G1024
- Medusa Group · G1051
- Contagious Interview · G1052
- Storm-0501 · G1053
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.