logo

Exposing Data Exfiltration: Detecting LOLBins, TTPs, and Ransomware Tactics

ID: 14247e3c-4aec-5c29-a48c-8a9644e18bc9

STIX ID: report--14247e3c-4aec-5c29-a48c-8a9644e18bc9

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-08-19

Date Updated: 2026-04-28

...
...

Huntress outlines common data staging and exfiltration techniques used by ransomware actors, providing real-world command-line examples and observed tool usage (archivers, backup utilities, cloud-sync tools, LOLBins and s5cmd) across multiple incidents; the report highlights that attackers commonly exfiltrate data immediately prior to encryption (enabling double extortion) and emphasizes detection challenges for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.