# T1567.002 Exfiltration to Cloud Storage

> As of 2026-10-05, T1567.002 (Exfiltration to Cloud Storage) appears in 120 tracked threats, first reported 2026-02-04 and most recently 2026-10-04, with linked actors including APT37, APT38, Akira; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 120 (26 critical, 85 high, 8 medium)
- **First seen:** 2026-02-04
- **Last seen:** 2026-10-04
- **Threat actors:** 85
- **Detection rules:** 363 (counts only; Blue tier and above)

## Key facts

- **ID:** T1567.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Exfiltration
- **Matrix:** Enterprise
- **Parent:** T1567
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1567/002/

## Activity timeline

T1567.002 first appeared in tracked threats on 2026-02-04 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 40 reports, and 120 of the 120 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1567.002 Exfiltration to Cloud Storage is catalogued by MITRE ATT&CK under the Exfiltration tactic in the Enterprise matrix, as a sub-technique of [T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567). Threadlinqs maps 120 of 2623 tracked threats (4.6%) to it; by severity that is 26 critical, 85 high, 8 medium.

Threats that use T1567.002 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (69 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (61 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (51 threats), [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (51 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (50 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

85 tracked threat actors appear in the threats that use T1567.002; the most frequent are [APT37](https://intel.threadlinqs.com/actor/APT37) (4), [APT38](https://intel.threadlinqs.com/actor/APT38) (4), [Akira](https://intel.threadlinqs.com/actor/Akira) (4), [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) (4), [Qilin](https://intel.threadlinqs.com/actor/Qilin) (4).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1567.002.

- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)

## Data sources

Telemetry that can reveal T1567.002, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [APT37](https://intel.threadlinqs.com/actor/APT37) — 4
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 4
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 4
- [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) — 4
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 4
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 4
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 4
- [Silent Ransom Group](https://intel.threadlinqs.com/actor/Silent%20Ransom%20Group) — 4
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 4
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 3
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 3
- [PayoutsKing](https://intel.threadlinqs.com/actor/PayoutsKing) — 3

## Tracked threats

The 30 most recent of 120 tracked threats that use T1567.002.

- [Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guilty](https://intel.threadlinqs.com/threat/TL-2026-2908) — high — 2026-10-04
- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…](https://intel.threadlinqs.com/threat/TL-2026-2852) — high — 2026-10-03
- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Group](https://intel.threadlinqs.com/threat/TL-2026-2829) — high — 2026-10-01
- [Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deployments](https://intel.threadlinqs.com/threat/TL-2026-2729) — high — 2026-09-27
- [France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months](https://intel.threadlinqs.com/threat/TL-2026-2564) — high — 2026-09-18
- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — high — 2026-09-17
- [Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists](https://intel.threadlinqs.com/threat/TL-2026-2543) — high — 2026-09-16
- [Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencies](https://intel.threadlinqs.com/threat/TL-2026-2534) — high — 2026-09-16
- [Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…](https://intel.threadlinqs.com/threat/TL-2026-2526) — high — 2026-09-15
- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker…](https://intel.threadlinqs.com/threat/TL-2026-2517) — high — 2026-09-15
- [Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated…](https://intel.threadlinqs.com/threat/TL-2026-2466) — critical — 2026-09-12
- [Coder Module Registry Supply-Chain Compromise Distributes Credential-Stealing Malware via Cloudflare Pool…](https://intel.threadlinqs.com/threat/TL-2026-2373) — critical — 2026-09-07
- [DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patients](https://intel.threadlinqs.com/threat/TL-2026-2328) — high — 2026-09-04
- ["Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relay](https://intel.threadlinqs.com/threat/TL-2026-2276) — high — 2026-09-01
- [The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…](https://intel.threadlinqs.com/threat/TL-2026-2271) — critical — 2026-09-01
- [Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…](https://intel.threadlinqs.com/threat/TL-2026-2243) — high — 2026-08-30
- [PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)](https://intel.threadlinqs.com/threat/TL-2026-2212) — high — 2026-08-29
- [Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Theft](https://intel.threadlinqs.com/threat/TL-2026-2229) — high — 2026-08-28
- [Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…](https://intel.threadlinqs.com/threat/TL-2026-2192) — high — 2026-08-28
- [Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusion](https://intel.threadlinqs.com/threat/TL-2026-2176) — high — 2026-08-28
- [PaperCut NG/MF Print Management Software Under Active Exploitation of Unpatched Vulnerability](https://intel.threadlinqs.com/threat/TL-2026-2171) — high — 2026-08-27
- ["The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware…](https://intel.threadlinqs.com/threat/TL-2026-2155) — high — 2026-08-26
- [UNC3753 (Luna Moth / Silent Ransom Group) Vishing and Physical Intrusion Campaign Against US Law Firms](https://intel.threadlinqs.com/threat/TL-2026-2127) — high — 2026-08-24
- [Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical…](https://intel.threadlinqs.com/threat/TL-2026-2103) — high — 2026-08-21
- [Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injection](https://intel.threadlinqs.com/threat/TL-2026-2082) — critical — 2026-08-20
- [SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governments](https://intel.threadlinqs.com/threat/TL-2026-2200) — high — 2026-08-19
- [AI-Agent-Driven Offensive Operation: Mass Cryptocurrency Wallet and Credential Compromise via Autonomous AI…](https://intel.threadlinqs.com/threat/TL-2026-2070) — critical — 2026-08-19
- [Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed)](https://intel.threadlinqs.com/threat/TL-2026-2045) — high — 2026-08-17
- [Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via…](https://intel.threadlinqs.com/threat/TL-2026-2010) — high — 2026-08-13

## Related CVEs

CVEs referenced by the tracked threats that use T1567.002, most frequent first.

- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-20481](https://intel.threadlinqs.com/cve/CVE-2024-20481)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711)
- [CVE-2025-11371](https://intel.threadlinqs.com/cve/CVE-2025-11371)
- [CVE-2025-14611](https://intel.threadlinqs.com/cve/CVE-2025-14611)
- [CVE-2025-2479](https://intel.threadlinqs.com/cve/CVE-2025-2479)
- [CVE-2025-24799](https://intel.threadlinqs.com/cve/CVE-2025-24799)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-30406](https://intel.threadlinqs.com/cve/CVE-2025-30406)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-39391](https://intel.threadlinqs.com/cve/CVE-2025-39391)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-54068](https://intel.threadlinqs.com/cve/CVE-2025-54068)

## Detection coverage

Threadlinqs maintains 363 detection rules mapped to T1567.002 (SPL 127, KQL 119, Sigma 117). Rule content is available to Blue tier accounts and above; this page shows counts only.

363 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567) — 572 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1567.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
