Using Backup Utilities for Data Exfiltration | Huntress Blog
ID: 15acdd8c-2b76-5441-ac89-a99f20d61fdd
STIX ID: report--15acdd8c-2b76-5441-ac89-a99f20d61fdd
Feed Name: Huntress Blog
Huntress investigated two Windows Server 2019 endpoints where an attacker, using previously compromised credentials and an endpoint named “debian,” executed scanner-like tooling and the restic backup application (renamed in one case) to attempt exfiltration of file-share contents to cloud S3 buckets (Backblaze and Wasabi); EDR telemetry captured command lines, registry modification to enable RDP, environment variable setting for AWS credentials and restic password, multiple SHA-256 hashes for observed binaries, and MITRE ATT&CK mappings, though investigators believe exfiltration may have been unsuccessful before containment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
