logo

Everyday tools, extraordinary crimes: the ransomware exfiltration playbook

ID: b2f9b7ca-0be0-5df8-8f5e-4aeb44b5e982

STIX ID: report--b2f9b7ca-0be0-5df8-8f5e-4aeb44b5e982

Feed Name: Cisco Talos

Threat Score
70/100

Date Published: 2026-03-19

Date Updated: 2026-04-27

Author: Maria Jose Erquiaga

...
...

This report presents the Exfiltration Framework, a cross-platform, behavior-focused model that normalizes how legitimate OS, endpoint, and cloud-native tools are abused for data exfiltration. It emphasizes that attackers increasingly use trusted utilities (e.g., rclone, PowerShell, cloud CLIs) and cloud storage to evade IOC-based detections, highlights recurring patterns such as masquerading and low-and-slow transfers, and recommends correlating endpoint, network, and cloud telemetry and behavioral baselining for reliable detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.