LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1567: Exfiltration Over Web Service

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Web service providers also commonly use SSL/TLS encryption, giving adversaries an added level of protection.

EnterpriseT1567TechniqueObject v1.5Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Exfiltration over a web service matters because it blends data theft into traffic many organizations already allow: SaaS, office platforms, code repositories, cloud storage, text storage sites, and other legitimate external web services. The business issue is not only malware traffic; it is whether the organization can distinguish approved use of trusted services from unauthorized movement of sensitive data over HTTPS.

Executive priority

Prioritize this technique where sensitive data, SaaS usage, developer tooling, or cloud storage are material to operations. Leaders should ask whether web egress, DLP, and SaaS audit evidence can prove what data left, which account or host sent it, and whether the destination service was authorized. This is especially relevant for incident response readiness, compliance evidence around data handling, and control decisions about web filtering and DLP scope.

Technical view

T1567 is an enterprise exfiltration technique across ESXi, Linux, macOS, Office Suite, SaaS, and Windows. ATT&CK provides no official detection text, but a related detection strategy, DET0548, exists and should be reviewed for coverage design. SOC and detection teams should validate monitoring for outbound transfers to legitimate web services, with special attention to the sub-technique context: code repositories, cloud storage, and text storage sites. Because SSL/TLS is common, detections should not depend solely on payload inspection; they should correlate destination reputation/category, user or host identity, volume, timing, process or application context, and DLP findings where available.

Likely telemetry

  • Web proxy and secure web gateway logs, including URL/category, destination domain, method, bytes sent, user, and device context
  • Firewall and network egress logs showing outbound connections to external web services
  • DNS logs and TLS metadata such as SNI/certificate context where collected
  • Endpoint network connection telemetry from Windows, Linux, macOS, and ESXi where supported
  • SaaS and Office Suite audit logs for file access, sharing, exports, uploads, and unusual account activity

Detection direction

  • Baseline approved web service usage by business unit, user role, host type, and workload so anomalous uploads are not lost in normal SaaS traffic.
  • Tune for large or unusual outbound transfers to legitimate services, especially when the host, user, time, destination category, or application context is atypical.
  • Correlate web egress with identity and SaaS audit events; web traffic alone may show the destination but not the business legitimacy of the transfer.
  • Account for HTTPS blind spots. If payload inspection is unavailable or inappropriate, rely more heavily on metadata, DLP classification, destination governance, and behavioral baselines.
  • Separate sanctioned from unsanctioned use of code repositories, cloud storage, and text storage sites to reduce false positives while preserving visibility into risky channels.

Mitigation priorities

  • Start by defining which external web services are authorized for business use and which users, devices, and workloads may access them.
  • Apply M1021 Restrict Web-Based Content through web filtering, category controls, download/upload governance, script or extension controls where appropriate, and policy enforcement for unauthorized services.
  • Apply M1057 Data Loss Prevention to identify, classify, monitor, and control movement of sensitive data across endpoint, network, SaaS, and cloud paths.
  • Ensure SaaS, Office Suite, code repository, and cloud storage audit logging is enabled and retained long enough to support incident response and compliance evidence.
  • Review exception handling: broad allow rules for popular web services can become exfiltration blind spots if not paired with logging, identity context, and DLP or behavioral monitoring.
Additional notes and limits

The supplied ATT&CK relationships show this technique is used by multiple campaigns, groups, and software entries, and it has sub-techniques for code repositories, cloud storage, and text storage sites. Those relationships support prioritizing coverage across legitimate web services, but local risk depends on the organization’s sanctioned services, data sensitivity, egress architecture, and logging maturity.

MITRE provides no official detection text for this object in the supplied fields. The related DET0548 detection strategy is named but not described here, so specific analytic logic should be validated from that source and local telemetry. This take does not assert active exploitation, local exposure, attribution, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Exfiltration Over Web Service

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Web service providers also commonly use SSL/TLS encryption, giving adversaries an added level of protection.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

4 rows
DomainIDNameRelationship / procedure
EnterpriseT1567.001Exfiltration to Code RepositorySub-techniqueExfiltration to Code Repository subtechnique of this object.
EnterpriseT1567.003Exfiltration to Text Storage SitesSub-techniqueExfiltration to Text Storage Sites subtechnique of this object.
EnterpriseT1567.002Exfiltration to Cloud StorageSub-techniqueExfiltration to Cloud Storage subtechnique of this object.
EnterpriseT1567.004Exfiltration Over WebhookSub-techniqueExfiltration Over Webhook subtechnique of this object.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0059: Magic Hound

Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.[1][2][3][4][5]

GroupEnterprise

G0007: APT28

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2] This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13]

APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[5] In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[14] Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

GroupEnterprise

G1043: BlackByte

BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.[1][2][3][4][5]

MalwareEnterprise

S1171: OilCheck

OilCheck is a C#/.NET downloader that has been used by OilRig since at least 2022 including against targets in Israel. OilCheck uses draft messages created in a shared email account for C2 communication.[1]

Windows
ToolEnterprise

S0508: ngrok

ngrok is a legitimate reverse proxy tool that can create a secure tunnel to servers located behind firewalls or on local machines that do not have a public IP. ngrok has been leveraged by threat actors in several campaigns including use for lateral movement and data exfiltration.[1][2][3][4]

Windows
MalwareEnterprise

S1179: Exbyte

Exbyte is an exfiltration tool written in Go that is uniquely associated with BlackByte operations. Observed since 2022, Exbyte transfers collected files to online file sharing and hosting services.[1]

Windows
MalwareEnterprise

S1245: InvisibleFerret

InvisibleFerret is a modular python malware that is leveraged for data exfiltration and remote access capabilities.[1][2][3] InvisibleFerret consists of four modules: main, payload, browser, and AnyDesk.[1] InvisibleFerret malware has been leveraged by North Korea-affiliated threat actors identified as DeceptiveDevelopment or Contagious Interview since 2023.[4][2][3][5] InvisibleFerret has historically been introduced to the victim environment through the use of the BeaverTail malware.[6][1][2][3][5]

LinuxmacOSWindows
CampaignEnterprise

C0051: APT28 Nearest Neighbor Campaign

APT28 Nearest Neighbor Campaign was conducted by APT28 from early February 2022 to November 2024 against organizations and individuals with expertise on Ukraine. APT28 primarily leveraged living-off-the-land techniques, while leveraging the zero-day exploitation of CVE-2022-38028. Notably, APT28 leveraged Wi-Fi networks in close proximity to the intended target to gain initial access to the victim environment. By daisy-chaining multiple compromised organizations nearby the intended target, APT28 discovered dual-homed systems (with both a wired and wireless network connection) to enable Wi-Fi and use compromised credentials to connect to the victim network.[1]

CampaignEnterprise

C0059: Salesforce Data Exfiltration

The Salesforce Data Exfiltration campaign began in October 2024 with financially-motivated threat actor UNC6040 using Spearphishing Voice (vishing) to compromise corporate Salesforce instances for large-scale data theft and extortion. Following the initial data theft, victim organizations received extortion demands from a separate threat actor, UNC6240, who claimed to be the “ShinyHunters” group. The observed infrastructure and TTPs used during the Salesforce Data Exfiltration campaign overlap with those used by threat groups with suspected ties to the broader collective known as "The Com.” These overlaps could plausibly be the result of associated actors operating within the same communities and are not necessarily an indication of a direct operational relationship.[1][2]

CampaignEnterprise

C0062: Anthropic AI-orchestrated Campaign

The Anthropic AI-orchestrated Campaign was conducted in September 2025 by a likely China nexus espionage actor identified as GTG-1002. The Anthropic AI-orchestrated Campaign was a highly coordinated operation that manipulated Claude Code to perform reconnaissance, vulnerability discovery, exploitation, lateral movement, credential harvesting, data analysis, and exfiltration operations at approximately 30 entities in the technology, financial, chemical, and government sectors. During the Anthropic AI-orchestrated Campaign, human operators used Claude Code agents and Model Context Protocol (MCP) tools to automate cyber operations. Operators broke attacks into discrete tasks, used crafted prompts, and established personas to bypass AI guardrails, enabling the agents to execute the operations with minimal human involvement.[1][2]

CampaignEnterprise

C0017: C0017

C0017 was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulnerable Internet facing web applications. During C0017, APT41 was quick to adapt and use publicly-disclosed as well as zero-day vulnerabilities for initial access, and in at least two cases re-compromised victims following remediation efforts. The goals of C0017 are unknown, however APT41 was observed exfiltrating Personal Identifiable Information (PII).[1]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.5
Created
Modified
Raw hash
0f09e6e28004f71f...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.5Current bundle0f09e6e28004…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Google Iran Threats October 2021

    Bash, A. (2021, October 14). Countering threats from Iran. Retrieved January 4, 2023.

    Open source URL
  2. [2]
    ESET Contagious Interview BeaverTail InvisibleFerret February 2025

    Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.

    Open source URL
  3. [3]
    Nearest Neighbor Volexity

    Koessel, Sean. Adair, Steven. Lancaster, Tom. (2024, November 22). The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access. Retrieved February 25, 2025.

    Open source URL
  4. [4]
    ESET OilRig Downloaders DEC 2023

    Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024.

    Open source URL
  5. [5]
    TrendMicro Pawn Storm Dec 2020

    Hacquebord, F., Remorin, L. (2020, December 17). Pawn Storm’s Lack of Sophistication as a Strategy. Retrieved January 13, 2021.

    Open source URL
  6. [6]
    Google Salesforce JUN 2025

    Google Threat Intelligence Group. (2025, June 4). The Cost of a Call: From Voice Phishing to Data Extortion. Retrieved October 22, 2025.

    Open source URL
  7. [7]
    FBI Salesforce Data Theft SEP 2025

    FBI Cyber Division. (2025, September 12). Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion. Retrieved October 22, 2025.

    Open source URL
  8. [8]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  9. [9]
    KISA Operation Muzabi

    KISA. (2021). Phishing Target Reconnaissance and Attack Resource Analysis Operation Muzabi. Retrieved March 8, 2024.

    Open source URL
  10. [10]
    Anthropic AI Orchestrated Campaign NOV 2025

    Anthropic. (2025, November). Disrupting the first reported AI-orchestrated cyber espionage campaign. Retrieved April 20, 2026.

    Open source URL
  11. [11]
    MalwareBytes Ngrok February 2020

    Segura, J. (2020, February 26). Fraudsters cloak credit card skimmer with fake content delivery network, ngrok server. Retrieved September 15, 2020.

    Open source URL
  12. [12]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  13. [13]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  14. [14]
    ESET OilRig Campaigns Sep 2023

    Hromcova, Z. and Burgher, A. (2023, September 21). OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes. Retrieved November 21, 2024.

    Open source URL
  15. [15]
    Symantec BlackByte 2022

    Symantec Threat Hunter Team. (2022, October 21). Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool. Retrieved December 16, 2024.

    Open source URL
  16. [16]
    Microsoft BlackByte 2023

    Microsoft Incident Response. (2023, July 6). The five-day job: A BlackByte ransomware intrusion case study. Retrieved December 16, 2024.

    Open source URL
  17. [17]
    Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024

    Seongsu Park. (2024, November 4). From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West. Retrieved October 17, 2025.

    Open source URL
  18. [18]
    mitre-attackT1567
    Open source URL
  19. [19]
    mitre-attackT1567
    Open source URL
  20. [20]
    mitre-attackT1567
    Open source URL
  21. [21]
    Google Iran Threats October 2021

    Bash, A. (2021, October 14). Countering threats from Iran. Retrieved January 4, 2023.

    Open source URL
  22. [22]
    ESET Contagious Interview BeaverTail InvisibleFerret February 2025

    Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.

    Open source URL
  23. [23]
    Nearest Neighbor Volexity

    Koessel, Sean. Adair, Steven. Lancaster, Tom. (2024, November 22). The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access. Retrieved February 25, 2025.

    Open source URL
  24. [24]
    ESET OilRig Downloaders DEC 2023

    Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024.

    Open source URL
  25. [25]
    TrendMicro Pawn Storm Dec 2020

    Hacquebord, F., Remorin, L. (2020, December 17). Pawn Storm’s Lack of Sophistication as a Strategy. Retrieved January 13, 2021.

    Open source URL
  26. [26]
    FBI Salesforce Data Theft SEP 2025

    FBI Cyber Division. (2025, September 12). Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion. Retrieved October 22, 2025.

    Open source URL
  27. [27]
    Google Salesforce JUN 2025

    Google Threat Intelligence Group. (2025, June 4). The Cost of a Call: From Voice Phishing to Data Extortion. Retrieved October 22, 2025.

    Open source URL
  28. [28]
    BleepingComputer Molerats Dec 2020

    Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.

    Open source URL
  29. [29]
    KISA Operation Muzabi

    KISA. (2021). Phishing Target Reconnaissance and Attack Resource Analysis Operation Muzabi. Retrieved March 8, 2024.

    Open source URL
  30. [30]
    Anthropic AI Orchestrated Campaign NOV 2025

    Anthropic. (2025, November). Disrupting the first reported AI-orchestrated cyber espionage campaign. Retrieved April 20, 2026.

    Open source URL
  31. [31]
    MalwareBytes Ngrok February 2020

    Segura, J. (2020, February 26). Fraudsters cloak credit card skimmer with fake content delivery network, ngrok server. Retrieved September 15, 2020.

    Open source URL
  32. [32]
    Mandiant APT41

    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

    Open source URL
  33. [33]
    Picus BlackByte 2022

    Huseyin Can Yuceel. (2022, February 21). TTPs used by BlackByte Ransomware Targeting Critical Infrastructure. Retrieved December 16, 2024.

    Open source URL
  34. [34]
    ESET OilRig Campaigns Sep 2023

    Hromcova, Z. and Burgher, A. (2023, September 21). OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes. Retrieved November 21, 2024.

    Open source URL
  35. [35]
    ESET OilRig Downloaders DEC 2023

    Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024.

    Open source URL
  36. [36]
    ESET OilRig Downloaders DEC 2023

    Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024.

    Open source URL
  37. [37]
    ESET Contagious Interview BeaverTail InvisibleFerret February 2025

    Matej Havranek. (2025, February 20). DeceptiveDevelopment targets freelance developers. Retrieved October 17, 2025.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.