Activity timeline
T1567 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 187 reports, and 572 of the 572 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1567 Exfiltration Over Web Service is catalogued by MITRE ATT&CK under the Exfiltration tactic in the Enterprise matrix. Threadlinqs maps 572 of 2623 tracked threats (21.8%) to it; by severity that is 175 critical, 322 high, 66 medium, 3 low.
Threats that use T1567 most often also use T1005 Data from Local System (301 threats), T1059 Command and Scripting Interpreter (300 threats), T1027 Obfuscated Files or Information (286 threats), T1071 Application Layer Protocol (263 threats), T1036 Masquerading (258 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
141 tracked threat actors appear in the threats that use T1567; the most frequent are TeamPCP (27), ShinyHunters (18), Contagious Interview (14), APT38 (10), MuddyWater (10).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1567.
Data sources
Telemetry that can reveal T1567, per MITRE ATT&CK.
- Application Log — Application Log Content
- Command — Command Execution
- File — File Access
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 572 tracked threats that use T1567.
- AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…high
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…high
- MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealerhigh
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signalinghigh
- Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)high
- Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…high
- ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…high
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…critical
- SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM Data Exfiltration in Salesforce Agentforcehigh
- AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…medium
- Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)medium
- Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day…high
- TokenGrabber: Python-based MaaS Infostealer Builderhigh
- SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack…high
- OAuth Token Theft via Sideloaded AppX Packages Abusing Microsoft-Signed Web Hosts (WWAHost.exe)high
- TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…high
- BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injectionmedium
- Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltratedhigh
- ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour…medium
- EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2high
- Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…high
- Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltrationhigh
- Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated…critical
- OpenAI Agent Swarm ("GemStuffer") Flooded RubyGems With 2,000+ Malicious Packages, Achieved RCE on…high
- CVE-2025-25249: Fortinet Heap-Based Buffer Overflow Exploited to Deploy PivotC2 RAT on FortiGate Devicescritical
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran…high
- Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypasshigh
- Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…critical
- Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED Leakhigh
- BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypasscritical
Detection coverage
Threadlinqs maintains 634 detection rules mapped to T1567 (SPL 226, KQL 196, Sigma 210, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1567.001 Exfiltration to Code Repository — 26 tracked threats
- T1567.002 Exfiltration to Cloud Storage — 120 tracked threats
- T1567.003 Exfiltration to Text Storage Sites — 0 tracked threats
- T1567.004 Exfiltration Over Webhook — 15 tracked threats