# T1537 Transfer Data to Cloud Account

> As of 2026-10-05, T1537 (Transfer Data to Cloud Account) appears in 69 tracked threats, first reported 2026-02-02 and most recently 2026-09-27, with linked actors including ShinyHunters, UNC6240, Scattered LAPSUS$ Hunters; it most often appears alongside T1078 (Valid Accounts).

- **Tracked threats:** 69 (22 critical, 37 high, 9 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-27
- **Threat actors:** 40
- **Detection rules:** 85 (counts only; Blue tier and above)

## Key facts

- **ID:** T1537
- **Framework:** MITRE ATT&CK
- **Tactics:** Exfiltration
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1537/

## Activity timeline

T1537 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 20 reports, and 69 of the 69 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1537 Transfer Data to Cloud Account is catalogued by MITRE ATT&CK under the Exfiltration tactic in the Enterprise matrix. Threadlinqs maps 69 of 2623 tracked threats (2.6%) to it; by severity that is 22 critical, 37 high, 9 medium.

Threats that use T1537 most often also use [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (48 threats), [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (36 threats), [T1526 Cloud Service Discovery](https://intel.threadlinqs.com/technique/T1526) (35 threats), [T1583 Acquire Infrastructure](https://intel.threadlinqs.com/technique/T1583) (35 threats), [T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567) (34 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

40 tracked threat actors appear in the threats that use T1537; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (11), [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) (7), [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) (6), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (6), [The Com](https://intel.threadlinqs.com/actor/The%20Com) (5).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1537.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)
- [M1054 Software Configuration](https://attack.mitre.org/mitigations/M1054/)
- [M1057 Data Loss Prevention](https://attack.mitre.org/mitigations/M1057/)

## Data sources

Telemetry that can reveal T1537, per MITRE ATT&CK.

- Application Log — Application Log Content
- Cloud Storage — Cloud Storage Creation, Cloud Storage Metadata, Cloud Storage Modification
- Network Traffic — Network Traffic Content
- Snapshot — Snapshot Creation, Snapshot Metadata, Snapshot Modification

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 11
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 7
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 6
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 6
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 5
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 5
- [UNC6395](https://intel.threadlinqs.com/actor/UNC6395) — 5
- [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) — 5
- [UNC5537](https://intel.threadlinqs.com/actor/UNC5537) — 4
- [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) — 3
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 2
- [Icarus](https://intel.threadlinqs.com/actor/Icarus) — 2

## Tracked threats

The 30 most recent of 69 tracked threats that use T1537.

- [Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deployments](https://intel.threadlinqs.com/threat/TL-2026-2729) — high — 2026-09-27
- [Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…](https://intel.threadlinqs.com/threat/TL-2026-2666) — critical — 2026-09-26
- [Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem](https://intel.threadlinqs.com/threat/TL-2026-2663) — 2026-09-26
- [SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…](https://intel.threadlinqs.com/threat/TL-2026-2646) — high — 2026-09-25
- [Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capability](https://intel.threadlinqs.com/threat/TL-2026-2468) — high — 2026-09-12
- [Emperador ransomware group claims breach of Uniguaçu (Brazilian education sector)](https://intel.threadlinqs.com/threat/TL-2026-2207) — medium — 2026-08-29
- [Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations…](https://intel.threadlinqs.com/threat/TL-2026-2201) — high — 2026-08-29
- [SilkParasite: China-Nexus APT Campaign Using 7 Malware Families Across Central Asia](https://intel.threadlinqs.com/threat/TL-2026-2068) — high — 2026-08-19
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…](https://intel.threadlinqs.com/threat/TL-2026-1987) — critical — 2026-08-11
- [AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671…](https://intel.threadlinqs.com/threat/TL-2026-1963) — high — 2026-08-09
- [UNC6671 Vishing Campaign Impersonates IT Support to Target 200+ Financial and Enterprise Organizations for…](https://intel.threadlinqs.com/threat/TL-2026-1959) — critical — 2026-08-09
- [Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables Gmail/Slack/X/Claude.ai Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-1923) — high — 2026-08-07
- [North Korean UNC5342 EtherHiding Campaign: Node.js RAT Delivered via Fake macOS Update Lures Using Ethereum…](https://intel.threadlinqs.com/threat/TL-2026-1794) — high — 2026-07-31
- [ShutterGap: Ephemeral Public Exposure of AWS RDS/DocumentDB Snapshots, AMIs & SSM Documents Evades…](https://intel.threadlinqs.com/threat/TL-2026-1788) — medium — 2026-07-31
- [OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face](https://intel.threadlinqs.com/threat/TL-2026-1750) — critical — 2026-07-28
- [CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol](https://intel.threadlinqs.com/threat/TL-2026-1747) — critical — 2026-07-28
- [AnMed Health Ransomware/Malware Disruption Closes 79-83 South Carolina/Georgia Facilities, Extortion Note…](https://intel.threadlinqs.com/threat/TL-2026-1727) — high — 2026-07-27
- [ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift Supply-Chain Compromise Targeting Salesforce…](https://intel.threadlinqs.com/threat/TL-2026-1711) — critical — 2026-07-26
- [GCP Cross-Project Compute Image Exfiltration via Compromised Developer Credentials](https://intel.threadlinqs.com/threat/TL-2026-1648) — high — 2026-07-23
- [Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accounts](https://intel.threadlinqs.com/threat/TL-2026-1641) — high — 2026-07-22
- [ReHub: Russian-Language Cybercrime Marketplace Sponsoring DragonForce, LockBit, CHAOS, Anubis, The…](https://intel.threadlinqs.com/threat/TL-2026-1594) — medium — 2026-07-21
- [Alleged Starbucks Data Breach — Threat Actor 'anes2010' Claims 176M Customer Records for Sale on Cybercrime…](https://intel.threadlinqs.com/threat/TL-2026-1578) — medium — 2026-07-20
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20
- [Extortion Actor Pivots from Blocked Remote-Access Tool to Fake IT-Support Social Engineering for Data…](https://intel.threadlinqs.com/threat/TL-2026-1359) — medium — 2026-07-15
- [Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and…](https://intel.threadlinqs.com/threat/TL-2026-1347) — high — 2026-07-15
- [Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths…](https://intel.threadlinqs.com/threat/TL-2026-1288) — high — 2026-07-14
- [FulcrumSec Double-Extortion Data Theft of Global Schools Foundation (GSF) EdTech Network via Unrotated 2022…](https://intel.threadlinqs.com/threat/TL-2026-1209) — high — 2026-07-11
- [npm 12 Disables Install Scripts, Git Dependencies, and Remote Tarball URLs by Default to Curb Supply-Chain…](https://intel.threadlinqs.com/threat/TL-2026-1163) — medium — 2026-07-10
- [AI-"Vibe-Coded" PowerShell Script ("Untitled1.ps1") Used for Active Directory Enumeration and S3…](https://intel.threadlinqs.com/threat/TL-2026-1152) — medium — 2026-07-09
- [JADEPUFFER: AI Agent Exploits Langflow RCE (CVE-2025-3248) to Automate Database Ransomware/Extortion Attack](https://intel.threadlinqs.com/threat/TL-2026-1117) — critical — 2026-07-05

## Related CVEs

CVEs referenced by the tracked threats that use T1537, most frequent first.

- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519)
- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-57726](https://intel.threadlinqs.com/cve/CVE-2024-57726)
- [CVE-2024-57728](https://intel.threadlinqs.com/cve/CVE-2024-57728)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-35273](https://intel.threadlinqs.com/cve/CVE-2026-35273)
- [CVE-2026-35616](https://intel.threadlinqs.com/cve/CVE-2026-35616)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-63077](https://intel.threadlinqs.com/cve/CVE-2026-63077)
- [CVE-2026-65617](https://intel.threadlinqs.com/cve/CVE-2026-65617)
- [CVE-2026-65921](https://intel.threadlinqs.com/cve/CVE-2026-65921)
- [CVE-2026-65923](https://intel.threadlinqs.com/cve/CVE-2026-65923)
- [CVE-2026-65924](https://intel.threadlinqs.com/cve/CVE-2026-65924)
- [CVE-2026-65925](https://intel.threadlinqs.com/cve/CVE-2026-65925)
- [CVE-2026-66014](https://intel.threadlinqs.com/cve/CVE-2026-66014)
- [CVE-2026-68820](https://intel.threadlinqs.com/cve/CVE-2026-68820)

## Detection coverage

Threadlinqs maintains 85 detection rules mapped to T1537 (SPL 31, KQL 29, Sigma 25). Rule content is available to Blue tier accounts and above; this page shows counts only.

85 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1537
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
