Loading the current evidence view. Navigation and account controls remain available.
ATT&CK knowledge
Loading the current evidence view. Navigation and account controls remain available.
Tactics: exfiltration
3
known groups
0
software
41
corpus matches
about
Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
A defender who is monitoring for large transfers to outside the cloud environment through normal file transfers or over command and control channels may not be watching for data transfers to another account within the same cloud provider. Such transfers may utilize existing cloud provider APIs and the internal address space of the cloud provider to blend into normal traffic or avoid data transfers over external network interfaces.
Adversaries may also use cloud-native mechanisms to share victim data with adversary-controlled cloud accounts, such as creating anonymous file sharing links or, in Azure, a shared access signature (SAS) URI.
Incidents have been observed where adversaries have created backups of cloud instances and transferred them to separate accounts.
used by actors
3 known groups
software
0 malware & tools implement this
None mapped.
corpus indicators tagged T1537
41 carry this technique
A shared-technique signal for hunting: each row resolves to its own verdict. Not attribution to any one group.
showing top 30 by severity of 41