Adversaries may search local system sources, such as file systems and configuration files or local databases, to find files of interest and sensitive data prior to Exfiltration.
Adversaries may do this using a Command and Scripting Interpreter, such as cmd as well as a Network Device CLI, which have functionality to interact with the file system to gather information.[1] Adversaries may also use Automated Collection on the local system.
ID | Name | Description |
---|---|---|
S1028 | Action RAT |
Action RAT can collect local data from an infected machine.[2] |
G1030 | Agrius |
Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism.[3] |
S1025 | Amadey | |
G0138 | Andariel |
Andariel has collected large numbers of files from compromised network systems for later extraction.[5] |
S0622 | AppleSeed | |
G0006 | APT1 | |
G0007 | APT28 |
APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration.[9][10][11][12] |
G0016 | APT29 | |
G0022 | APT3 |
APT3 will identify Microsoft Office documents on the victim's computer.[14] |
G0067 | APT37 | |
G0082 | APT38 | |
G0087 | APT39 |
APT39 has used various tools to steal files from the compromised host.[17][18] |
G0096 | APT41 |
APT41 has uploaded files and data from a compromised host.[19] |
G0143 | Aquatic Panda |
Aquatic Panda captured local Windows security event log data from victim machines using the |
S1029 | AuTo Stealer |
AuTo Stealer can collect data such as PowerPoint files, Word documents, Excel files, PDF files, text files, database files, and image files from an infected machine.[2] |
G0001 | Axiom | |
S0642 | BADFLICK | |
S0128 | BADNEWS |
When it first starts, BADNEWS crawls the victim's local drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt.[23][24] |
S0337 | BadPatch |
BadPatch collects files from the local system that have the following extensions, then prepares them for exfiltration: .xls, .xlsx, .pdf, .mdb, .rar, .zip, .doc, .docx.[25] |
S0234 | Bandook | |
S0239 | Bankshot | |
S0534 | Bazar |
Bazar can retrieve information from the infected machine.[28] |
S0268 | Bisonal |
Bisonal has collected information from a compromised host.[29] |
S0564 | BlackMould |
BlackMould can copy files on a compromised host.[30] |
S0520 | BLINDINGCAN |
BLINDINGCAN has uploaded files from victim machines.[31] |
S0651 | BoxCaon | |
G0060 | BRONZE BUTLER |
BRONZE BUTLER has exfiltrated files stolen from local systems.[33] |
S1063 | Brute Ratel C4 |
Brute Ratel C4 has the ability to upload files from a compromised system.[34] |
S1039 | Bumblebee |
Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies.[35] |
C0015 | C0015 |
During C0015, the threat actors obtained files and data from the compromised network.[36] |
C0017 | C0017 |
During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks.[37] |
C0026 | C0026 |
During C0026, the threat actors collected documents from compromised hosts.[38] |
S0274 | Calisto | |
S0572 | Caterpillar WebShell |
Caterpillar WebShell has a module to collect information from the local database.[40] |
S1043 | ccf32 | |
S0674 | CharmPower |
CharmPower can collect data and files from a compromised host.[42] |
S1149 | CHIMNEYSWEEP |
CHIMNEYSWEEP can collect files from compromised hosts.[43] |
S0020 | China Chopper |
China Chopper's server component can upload local files.[44][45][46][47] |
S0667 | Chrommme | |
S0660 | Clambling |
Clambling can collect information from a compromised host.[49] |
S0154 | Cobalt Strike |
Cobalt Strike can collect data from a local system.[50][51] |
S0492 | CookieMiner |
CookieMiner has retrieved iPhone text messages from iTunes phone backup files.[52] |
S0050 | CosmicDuke |
CosmicDuke steals user files from local hard drives with file extensions that match a predefined list.[53] |
C0004 | CostaRicto |
During CostaRicto, the threat actors collected data and files from compromised networks.[54] |
S1023 | CreepyDrive |
CreepyDrive can upload files to C2 from victim machines.[55] |
S0115 | Crimson |
Crimson can collect information from a compromised host.[56] |
S0538 | Crutch | |
S0498 | Cryptoistic |
Cryptoistic can retrieve files from the local file system.[58] |
G1012 | CURIUM | |
C0029 | Cutting Edge |
During Cutting Edge, threat actors stole the running configuration and cache data from targeted Ivanti Connect Secure VPNs.[60][61] |
S0687 | Cyclops Blink |
Cyclops Blink can upload files from a compromised host.[62] |
S1014 | DanBot | |
G0070 | Dark Caracal |
Dark Caracal collected complete contents of the 'Pictures' folder from compromised Windows systems.[64] |
S0673 | DarkWatchman |
DarkWatchman can collect files from a compromised host.[65] |
S1021 | DnsSystem |
DnsSystem can upload files from infected machines after receiving a command with |
G0035 | Dragonfly | |
S0694 | DRATzarus |
DRATzarus can collect information from a compromised host.[68] |
S0502 | Drovorub | |
S0567 | Dtrack |
Dtrack can collect a variety of information from victim machines.[70] |
S1159 | DUSTTRAP | |
G1003 | Ember Bear |
Ember Bear gathers victim system information such as enumerating the volume of a given device or extracting system and security event logs for analysis.[72][73] |
S0634 | EnvyScout |
EnvyScout can collect sensitive NTLM material from a compromised host.[74] |
S0404 | esentutl |
esentutl can be used to collect data from local file systems.[75] |
S0512 | FatDuke |
FatDuke can copy files and directories from a compromised host.[76] |
G1016 | FIN13 |
FIN13 has gathered stolen credentials, sensitive data such as point-of-sale (POS), and ATM data from a compromised network before exfiltration.[77][78] |
G0037 | FIN6 |
FIN6 has collected and exfiltrated payment card data from compromised systems.[79][80][81] |
G0046 | FIN7 |
FIN7 has collected files and other sensitive information from a compromised network.[82] |
S0696 | Flagpro |
Flagpro can collect data from a compromised host, including Windows authentication information.[83] |
S0036 | FLASHFLOOD |
FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on the local system. FLASHFLOOD will scan the My Recent Documents, Desktop, Temporary Internet Files, and TEMP directories. FLASHFLOOD also collects information stored in the Windows Address Book.[84] |
S0381 | FlawedAmmyy |
FlawedAmmyy has collected information and files from a compromised machine.[85] |
S0661 | FoggyWeb |
FoggyWeb can retrieve configuration data from a compromised AD FS server.[86] |
S0193 | Forfiles |
Forfiles can be used to act on (ex: copy, move, etc.) files/directories in a system during (ex: copy files into a staging area before).[9] |
G0117 | Fox Kitten |
Fox Kitten has searched local system resources to access sensitive documents.[87] |
S0503 | FrameworkPOS |
FrameworkPOS can collect elements related to credit card data from process memory.[88] |
C0001 | Frankenstein |
During Frankenstein, the threat actors used Empire to gather various local system information.[89] |
S1044 | FunnyDream |
FunnyDream can upload files from victims' machines.[41][90] |
G0093 | GALLIUM |
GALLIUM collected data from the victim's local system, including password hashes from the SAM hive in the Registry.[91] |
G0047 | Gamaredon Group |
Gamaredon Group has collected files from infected systems and uploaded them to a C2 server.[92] |
S0666 | Gelsemium | |
S0477 | Goopy |
Goopy has the ability to exfiltrate documents from infected systems.[93] |
S0237 | GravityRAT |
GravityRAT steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf.[94] |
S0690 | Green Lambert |
Green Lambert can collect data from a compromised host.[95] |
S0632 | GrimAgent |
GrimAgent can collect data and files from a compromised host.[96] |
G0125 | HAFNIUM |
HAFNIUM has collected data and files from a compromised machine.[47] |
S0009 | Hikit | |
S0203 | Hydraq |
Hydraq creates a backdoor through which remote attackers can read data from files.[97][98] |
S1022 | IceApple |
IceApple can collect files, passwords, and other data from a compromised host.[99] |
G0100 | Inception |
Inception used a file hunting plugin to collect .txt, .pdf, .xls or .doc files from the infected host.[100] |
S0260 | InvisiMole |
InvisiMole can collect data from the system, and can monitor changes in specified directories.[101] |
S1132 | IPsec Helper |
IPsec Helper can identify specific files and folders for follow-on exfiltration.[102] |
S0015 | Ixeshe | |
S0265 | Kazuar |
Kazuar uploads files from a specified directory to the C2 server.[104] |
G0004 | Ke3chang |
Ke3chang gathered information and files from local directories for exfiltration.[105][106] |
S1020 | Kevin |
Kevin can upload logs and other data from a compromised host.[107] |
S0526 | KGH_SPY |
KGH_SPY can send a file containing victim system information to C2.[108] |
G0094 | Kimsuky |
Kimsuky has collected Office, PDF, and HWP documents from its victims.[109][110] |
S0250 | Koadic |
Koadic can download files off the target system to send back to the server.[111][112] |
S0356 | KONNI |
KONNI has stored collected information and discovered processes in a tmp file.[113] |
S1075 | KOPILUWAK |
KOPILUWAK can gather information from compromised hosts.[38] |
G1004 | LAPSUS$ |
LAPSUS$ uploaded sensitive files, information, and credentials from a targeted organization for extortion or public release.[114] |
S1160 | Latrodectus |
Latrodectus can collect data from a compromised host using a stealer module.[115] |
G0032 | Lazarus Group |
Lazarus Group has collected data and files from compromised networks.[116][117][118][119] |
S0395 | LightNeuron |
LightNeuron can collect files from a local system.[120] |
S0211 | Linfo |
Linfo creates a backdoor through which remote attackers can obtain data from local systems.[121] |
S1101 | LoFiSe |
LoFiSe can collect files of interest from targeted systems.[122] |
G1014 | LuminousMoth |
LuminousMoth has collected files and data from compromised machines.[123][124] |
S0409 | Machete |
Machete searches the File system for files of interest.[125] |
S1016 | MacMa |
MacMa can collect then exfiltrate files from the compromised system.[126] |
S1060 | Mafalda |
Mafalda can collect files and information from a compromised host.[127] |
G0059 | Magic Hound |
Magic Hound has used a web shell to exfiltrate a ZIP file containing a dump of LSASS memory on a compromised machine.[128][129] |
S0652 | MarkiRAT |
MarkiRAT can upload data from the victim's machine to the C2 server.[130] |
S0500 | MCMD |
MCMD has the ability to upload files from an infected device.[131] |
G0045 | menuPass |
menuPass has collected various files from the compromised computers.[132][133] |
S1059 | metaMain |
metaMain can collect files and system information from a compromised host.[127][134] |
S1146 | MgBot |
MgBot includes modules for collecting files from local systems based on a given set of properties and filenames.[135] |
S1015 | Milan | |
S0084 | Mis-Type |
Mis-Type has collected files and data from a compromised host.[137] |
S0083 | Misdat |
Misdat has collected files and data from a compromised host.[137] |
S0079 | MobileOrder |
MobileOrder exfiltrates data collected from the victim mobile device.[138] |
S1026 | Mongall |
Mongall has the ability to upload files from victim's machines.[139] |
S0630 | Nebulae |
Nebulae has the capability to upload collected files to C2.[140] |
S0691 | Neoichor | |
C0002 | Night Dragon |
During Night Dragon, the threat actors collected files and other data from compromised systems.[141] |
S1090 | NightClub |
NightClub can use a file monitor to steal specific files from targeted systems.[142] |
S0385 | njRAT | |
S1131 | NPPSPY |
NPPSPY records data entered from the local system logon at Winlogon to capture credentials in cleartext.[144] |
S0340 | Octopus |
Octopus can exfiltrate files from the system using a documents collector tool.[145] |
C0012 | Operation CuckooBees |
During Operation CuckooBees, the threat actors collected data, files, and other information from compromised networks.[146] |
C0022 | Operation Dream Job |
During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host.[68][147] |
C0006 | Operation Honeybee |
During Operation Honeybee, the threat actors collected data from compromised hosts.[148] |
C0014 | Operation Wocao |
During Operation Wocao, threat actors exfiltrated files and directories of interest from the targeted system.[149] |
S0352 | OSX_OCEANLOTUS.D |
OSX_OCEANLOTUS.D has the ability to upload files from a compromised host.[150] |
S0594 | Out1 |
Out1 can copy files and Registry data from compromised hosts.[151] |
S1017 | OutSteel |
OutSteel can collect information from a compromised host.[152] |
S0598 | P.A.S. Webshell |
P.A.S. Webshell has the ability to copy files on a compromised host.[153] |
S0208 | Pasam |
Pasam creates a backdoor through which remote attackers can retrieve files.[154] |
G0040 | Patchwork |
Patchwork collected and exfiltrated files from the infected system.[155] |
S1102 | Pcexter | |
S1050 | PcShare |
PcShare can collect files and information from a compromised host.[41] |
S0517 | Pillowmint |
Pillowmint has collected credit card data using native API functions.[156] |
S0048 | PinchDuke |
PinchDuke collects user files from the compromised host based on predefined file extensions.[157] |
S1031 | PingPull | |
S0012 | PoisonIvy |
PoisonIvy creates a backdoor through which remote attackers can steal system information.[159] |
S1012 | PowerLess |
PowerLess has the ability to exfiltrate data, including Chrome and Edge browser database files, from compromised machines.[160] |
S0194 | PowerSploit |
PowerSploit contains a collection of Exfiltration modules that can access data from local files, volumes, and processes.[161][162] |
S0223 | POWERSTATS |
POWERSTATS can upload files from compromised hosts.[163] |
S0238 | Proxysvc | |
S0197 | PUNCHTRACK |
PUNCHTRACK scrapes memory for properly formatted payment card data.[165][166] |
S0650 | QakBot |
QakBot can use a variety of commands, including esentutl.exe to steal sensitive data from Internet Explorer and Microsoft Edge, to acquire information that is subsequently exfiltrated.[167][168] |
S0262 | QuasarRAT |
QuasarRAT can retrieve files from compromised client machines.[169] |
S0686 | QuietSieve |
QuietSieve can collect files from a compromised host.[170] |
S1148 | Raccoon Stealer |
Raccoon Stealer collects data from victim machines based on configuration information received from command and control nodes.[171][172] |
S0629 | RainyDay |
RainyDay can use a file exfiltration tool to collect recently changed files on a compromised host.[140] |
S0458 | Ramsay |
Ramsay can collect Microsoft Word documents from the target's file system, as well as |
S1113 | RAPIDPULSE |
RAPIDPULSE retrieves files from the victim system via encrypted commands sent to the web shell.[175] |
S0169 | RawPOS |
RawPOS dumps memory from specific processes on a victim system, parses the dumped files, and scrapes them for credit card data.[176][177][178] |
S0662 | RCSession |
RCSession can collect data from a compromised host.[179][49] |
G1039 | RedCurl |
RedCurl has collected data from the local disk of compromised hosts.[180][181] |
S0448 | Rising Sun |
Rising Sun has collected data and files from a compromised host.[182] |
S0240 | ROKRAT |
ROKRAT can collect host data and specific file types.[183][184][185] |
S0090 | Rover |
Rover searches for files on local drives based on a predefined list of file extensions.[186] |
S1018 | Saint Bot |
Saint Bot can collect files and information from a compromised host.[187] |
S1099 | Samurai |
Samurai can leverage an exfiltration module to download arbitrary files from compromised machines.[188] |
G0034 | Sandworm Team |
Sandworm Team has exfiltrated internal documents, files, and other data from compromised hosts.[189] |
S1085 | Sardonic |
Sardonic has the ability to collect data from a compromised machine to deliver to the attacker.[190] |
S0461 | SDBbot |
SDBbot has the ability to access the file system on a compromised host.[191] |
S1019 | Shark | |
S1089 | SharpDisco |
SharpDisco has dropped a recent-files stealer plugin to |
S0444 | ShimRat |
ShimRat has the capability to upload collected files to a C2.[193] |
S0610 | SideTwist |
SideTwist has the ability to upload files from a compromised host.[194] |
S1110 | SLIGHTPULSE |
SLIGHTPULSE can read files specified on the local system.[195] |
S0533 | SLOTHFULMEDIA |
SLOTHFULMEDIA has uploaded files and information from victim machines.[196] |
C0024 | SolarWinds Compromise |
During the SolarWinds Compromise, APT29 extracted files from compromised networks.[197] |
S0615 | SombRAT |
SombRAT has collected data and files from a compromised host.[54][198] |
S0646 | SpicyOmelette |
SpicyOmelette has collected data and other information from a compromised host.[199] |
S1037 | STARWHALE |
STARWHALE can collect data from an infected local host.[200] |
G0038 | Stealth Falcon |
Stealth Falcon malware gathers data from the local victim system.[201] |
S1034 | StrifeWater |
StrifeWater can collect data from a compromised host.[202] |
S0559 | SUNBURST |
SUNBURST collected information from a compromised host.[203][204] |
S1064 | SVCReady | |
S0663 | SysUpdate |
SysUpdate can collect information and files from a compromised host.[206] |
S0011 | Taidoor |
Taidoor can upload data and files from a victim's machine.[207] |
S0467 | TajMahal |
TajMahal has the ability to steal documents from the local system including the print spooler queue.[208] |
G0027 | Threat Group-3390 |
Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories.[209] |
S0665 | ThreatNeedle |
ThreatNeedle can collect data and files from a compromised host.[119] |
S0668 | TinyTurla | |
G1022 | ToddyCat |
ToddyCat has run scripts to collect documents from targeted hosts.[122] |
S0671 | Tomiris |
Tomiris has the ability to collect recent files matching a hardcoded list of extensions prior to exfiltration.[211] |
S0266 | TrickBot |
TrickBot collects local files and information from the victim’s local machine.[212] |
G0010 | Turla |
Turla RPC backdoors can upload files from victim machines.[213] |
S0022 | Uroburos |
Uroburos can use its |
S0386 | Ursnif |
Ursnif has collected files from victim machines, including certificates and cookies.[215] |
S0452 | USBferry |
USBferry can collect information from an air-gapped host machine.[216] |
G1017 | Volt Typhoon |
Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information.[217][218][219] |
S0670 | WarzoneRAT |
WarzoneRAT can collect data from a compromised host.[220] |
S0515 | WellMail | |
S0514 | WellMess |
WellMess can send files from the victim machine to C2.[222][223] |
S0645 | Wevtutil |
Wevtutil can be used to export events from a specific log.[224][225] |
G0124 | Windigo |
Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors.[226] |
G0102 | Wizard Spider |
Wizard Spider has collected data from a compromised host prior to exfiltration.[227] |
S1065 | Woody RAT |
Woody RAT can collect information from a compromised host.[228] |
S0653 | xCaon | |
S0658 | XCSSET |
XCSSET collects contacts and application data from files in Desktop, Documents, Downloads, Dropbox, and WeChat folders.[229] |
S0248 | yty |
yty collects files with the following extensions: .ppt, .pptx, .pdf, .doc, .docx, .xls, .xlsx, .docm, .rtf, .inp, .xlsm, .csv, .odt, .pps, .vcf and sends them back to the C2 server.[230] |
S0672 | Zox |
Zox has the ability to upload files from a targeted system.[21] |
S0412 | ZxShell | |
S1013 | ZxxZ |
ID | Mitigation | Description |
---|---|---|
M1057 | Data Loss Prevention |
Data loss prevention can restrict access to sensitive data and detect sensitive data that is unencrypted. |
ID | Data Source | Data Component | Detects |
---|---|---|---|
DS0017 | Command | Command Execution |
Monitor executed commands and arguments that may search and collect local system sources, such as file systems or local databases, to find files of interest and sensitive data prior to Exfiltration. Remote access tools with built-in features may interact directly with the Windows API to gather data. Data may also be acquired through Windows system management tools such as Windows Management Instrumentation and PowerShell. For network devices, monitor executed commands in AAA logs, especially those run by unexpected or unauthorized users. |
DS0022 | File | File Access |
Monitor for unexpected/abnormal access to files that may be malicious collection of local data, such as user files (pdf, .docx, .jpg, etc.) or local databases. |
DS0009 | Process | OS API Execution |
Monitor for API calls that may search local system sources, such as file systems or local databases, to find files of interest and sensitive data prior to Exfiltration. |
Process Creation |
Monitor for newly executed processes that may search local system sources, such as file systems or local databases, to find files of interest and sensitive data prior to Exfiltration. |
||
DS0012 | Script | Script Execution |
Monitor for any attempts to enable scripts running on a system would be considered suspicious. If scripts are not commonly used on a system, but enabled, scripts running out of cycle from patching or other administrator functions are suspicious. Scripts should be captured from the file system when possible to determine their actions and intent. Data may also be acquired through Windows system management tools such as Windows Management Instrumentation and PowerShell. |