1200KM / tool
Rclone — Attack Tool
Rclone is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. Rclone has been used in a number of ransomware campaigns, including those associated with the Conti and DarkSide Ransomware-as-a-Service operations.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: Rclone
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- MuddyWater · G0069 · Pinned relationship source (relationship--34cdcb7f-2584-4d27-90ee-c128300e922b)
- WIRTE · G0090 · Pinned relationship source (relationship--75668677-ec35-4aee-bfd8-d412e4e35d4b)
- Ember Bear · G1003 · Pinned relationship source (relationship--d433a8af-05f0-4766-adb5-abc63f9bf1b9)
- Scattered Spider · G1015 · Pinned relationship source (relationship--498002b0-1700-45f4-8404-27c1d19a074f)
- Cinnamon Tempest · G1021 · Pinned relationship source (relationship--e5f53e43-5b6a-480c-b770-85ca47b17050)
- Akira · G1024 · Pinned relationship source (relationship--e59eafd8-6579-4ca0-b357-6df989142449)
- INC Ransom · G1032 · Pinned relationship source (relationship--82b401c4-abde-4b4d-afe7-2a2fde54de7d)
- Medusa Group · G1051 · Pinned relationship source (relationship--797bea76-9542-4254-bbf1-1df474d02301)
- Storm-0501 · G1053 · Pinned relationship source (relationship--7b82c1d0-b675-47bd-bb8c-3e0fb96c304a)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1030 · Data Transfer Size Limits · Detection rules & anomalies
- T1048.002 · Exfiltration Over Asymmetric Encrypted Non-C2 Protocol · Detection rules & anomalies
- T1048.003 · Exfiltration Over Unencrypted Non-C2 Protocol · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1560.001 · Archive via Utility · Detection rules & anomalies
- T1567.002 · Exfiltration to Cloud Storage · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.