Exfiltration Tools: How Cybercriminals Make Off with Your Data
ID: c93d970e-abf3-5ca2-a918-67b54687dd7d
STIX ID: report--c93d970e-abf3-5ca2-a918-67b54687dd7d
Feed Name: ReliaQuest Blog
ReliaQuest analyzed incidents from Sep 2023–Jul 2024 and found Rclone to be the dominant data-exfiltration tool (present in ~57% of incidents), with WinSCP, cURL, MEGA, Restic, FileZilla, and RMM tools also used; the report details a double-extortion case where attackers masqueraded Rclone as firefox.exe to exfiltrate data to cloud storage, provides command- and configuration-level indicators (e.g., rclone.conf, specific rclone/curl commands), maps actor usage (including ransomware groups and APTs), and offers practical detection and mitigation recommendations such as application control, centralized logging, DLP, canary files, and blocking abused cloud services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
