Activity timeline
T1567.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-09 with 6 reports, and 15 of the 15 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1567.004 Exfiltration Over Webhook is catalogued by MITRE ATT&CK under the Exfiltration tactic in the Enterprise matrix, as a sub-technique of T1567 Exfiltration Over Web Service. Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 1 critical, 9 high, 5 medium.
Threats that use T1567.004 most often also use T1005 Data from Local System (9 threats), T1027 Obfuscated Files or Information (8 threats), T1036.005 Match Legitimate Resource Name or Location (7 threats), T1053.005 Scheduled Task (6 threats), T1071.001 Web Protocols (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
4 tracked threat actors appear in the threats that use T1567.004; the most frequent are APT28 (3), BlueDelta (3), Forest Blizzard (3), TeamPCP (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1567.004.
Data sources
Telemetry that can reveal T1567.004, per MITRE ATT&CK.
- Application Log — Application Log Content
- Command — Command Execution
- File — File Access
- Network Traffic — Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
15 tracked threats use T1567.004.
- OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvestershigh
- CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)medium
- ClosedQuorum: Go-Based Windows Implant Delegates Post-Compromise Decisions to a Four-Model LLM Voting Panelmedium
- Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware; Discloses CLOSEDQUORUM, First Documented…medium
- indexed-btree npm Campaign: Runtime-Triggered Loader Evades Install-Script Defenses via BTree.prototype.set()high
- Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accountshigh
- APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and Government Organizations in Romania, Spain, and Türkiyehigh
- HOOKEDGE: New BlueDelta (APT28/Fancy Bear) Backdoor Abuses Microsoft Edge and webhook.site for C2high
- BlueDelta (GRU/APT28) Targets Defense and Diplomacy with HOOKEDGE Backdoorhigh
- CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russiahigh
- AI Agent (Claude Mythos 5) Publishes Credential-Stealing Package 'mlflow-ui' to PyPI During Cyber…high
- AI-Generated Browser-Only Ransomware Abuses Chrome File System Access API (InfernoGrabber 9000 / DeepSeek)medium
- Browser-Only Ransomware (InfernoGrabber v9.0) Abuses Chrome File System Access API to Encrypt Android Photosmedium
- SolyxImmortal Python Infostealer — Chromium/Firefox Credential & Cookie Theft, Keylogging, Discord Webhook…high
- TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payloadcritical
Detection coverage
Threadlinqs maintains 41 detection rules mapped to T1567.004 (SPL 17, KQL 11, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1567 Exfiltration Over Web Service — 572 tracked threats at the technique level.