Activity timeline
T1567.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 40 reports, and 120 of the 120 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1567.002 Exfiltration to Cloud Storage is catalogued by MITRE ATT&CK under the Exfiltration tactic in the Enterprise matrix, as a sub-technique of T1567 Exfiltration Over Web Service. Threadlinqs maps 120 of 2623 tracked threats (4.6%) to it; by severity that is 26 critical, 85 high, 8 medium.
Threats that use T1567.002 most often also use T1071.001 Web Protocols (69 threats), T1005 Data from Local System (61 threats), T1027 Obfuscated Files or Information (51 threats), T1059.001 PowerShell (51 threats), T1685 Disable or Modify Tools (50 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
85 tracked threat actors appear in the threats that use T1567.002; the most frequent are APT37 (4), APT38 (4), Akira (4), Luna Moth (4), Qilin (4).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1567.002.
Data sources
Telemetry that can reveal T1567.002, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 120 tracked threats that use T1567.002.
- Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guiltyhigh
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…high
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)high
- Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Grouphigh
- Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deploymentshigh
- France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Monthshigh
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observedhigh
- Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalistshigh
- Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencieshigh
- Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…high
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker…high
- Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated…critical
- Coder Module Registry Supply-Chain Compromise Distributes Credential-Stealing Malware via Cloudflare Pool…critical
- DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patientshigh
- "Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relayhigh
- The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…critical
- Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…high
- PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)high
- Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Thefthigh
- Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…high
- Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusionhigh
- PaperCut NG/MF Print Management Software Under Active Exploitation of Unpatched Vulnerabilityhigh
- "The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware…high
- UNC3753 (Luna Moth / Silent Ransom Group) Vishing and Physical Intrusion Campaign Against US Law Firmshigh
- Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical…high
- Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injectioncritical
- SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governmentshigh
- AI-Agent-Driven Offensive Operation: Mass Cryptocurrency Wallet and Credential Compromise via Autonomous AI…critical
- Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed)high
- Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via…high
Detection coverage
Threadlinqs maintains 363 detection rules mapped to T1567.002 (SPL 127, KQL 119, Sigma 117). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1567 Exfiltration Over Web Service — 572 tracked threats at the technique level.