Ransomware-driven data exfiltration: techniques and implications
ID: 08dcac02-c72d-5847-9e68-0f5d2228f4a8
STIX ID: report--08dcac02-c72d-5847-9e68-0f5d2228f4a8
Feed Name: Sekoia.io Blog (archive)
Date Published: 2024-11-27
Date Updated: 2026-04-29
Author: Livia Tibirna, Caroline Lewis and Sekoia TDR
This report analyzes the increasing centrality of data exfiltration in ransomware and extortion operations since 2019, detailing motivations behind double extortion, the prioritization and triage of high-value datasets, and the mix of custom, commodity, and legitimate tools used to stealthily collect and transfer data. It notes occasional use of infostealers and MaaS, emphasizes the prevalence of publicly available utilities to blend with normal activity, and recommends early, multi-method detection focused on suspicious behaviors, access patterns, and known exfiltration tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
