# T1567.004 Exfiltration Over Webhook

> As of 2026-10-05, T1567.004 (Exfiltration Over Webhook) appears in 15 tracked threats, first reported 2026-03-31 and most recently 2026-09-27, with linked actors including APT28, BlueDelta, Forest Blizzard; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 15 (1 critical, 9 high, 5 medium)
- **First seen:** 2026-03-31
- **Last seen:** 2026-09-27
- **Threat actors:** 4
- **Detection rules:** 41 (counts only; Blue tier and above)

## Key facts

- **ID:** T1567.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Exfiltration
- **Matrix:** Enterprise
- **Parent:** T1567
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1567/004/

## Activity timeline

T1567.004 first appeared in tracked threats on 2026-03-31 and was most recently reported on 2026-09-27. The busiest month was 2026-09 with 6 reports, and 15 of the 15 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1567.004 Exfiltration Over Webhook is catalogued by MITRE ATT&CK under the Exfiltration tactic in the Enterprise matrix, as a sub-technique of [T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567). Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 1 critical, 9 high, 5 medium.

Threats that use T1567.004 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (9 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (8 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (7 threats), [T1053.005 Scheduled Task](https://intel.threadlinqs.com/technique/T1053.005) (6 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

4 tracked threat actors appear in the threats that use T1567.004; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (3), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (3), [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) (3), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1567.004.

- [M1057 Data Loss Prevention](https://attack.mitre.org/mitigations/M1057/)

## Data sources

Telemetry that can reveal T1567.004, per MITRE ATT&CK.

- Application Log — Application Log Content
- Command — Command Execution
- File — File Access
- Network Traffic — Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 3
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 3
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 3
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 1

## Tracked threats

15 tracked threats use T1567.004.

- [OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2704) — high — 2026-09-27
- [CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)](https://intel.threadlinqs.com/threat/TL-2026-2753) — medium — 2026-09-22
- [ClosedQuorum: Go-Based Windows Implant Delegates Post-Compromise Decisions to a Four-Model LLM Voting Panel](https://intel.threadlinqs.com/threat/TL-2026-2621) — medium — 2026-09-22
- [Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware; Discloses CLOSEDQUORUM, First Documented…](https://intel.threadlinqs.com/threat/TL-2026-2615) — medium — 2026-09-22
- [indexed-btree npm Campaign: Runtime-Triggered Loader Evades Install-Script Defenses via BTree.prototype.set()](https://intel.threadlinqs.com/threat/TL-2026-2590) — high — 2026-09-20
- [Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accounts](https://intel.threadlinqs.com/threat/TL-2026-2296) — high — 2026-09-02
- [APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and Government Organizations in Romania, Spain, and Türkiye](https://intel.threadlinqs.com/threat/TL-2026-2213) — high — 2026-08-29
- [HOOKEDGE: New BlueDelta (APT28/Fancy Bear) Backdoor Abuses Microsoft Edge and webhook.site for C2](https://intel.threadlinqs.com/threat/TL-2026-2187) — high — 2026-08-28
- [BlueDelta (GRU/APT28) Targets Defense and Diplomacy with HOOKEDGE Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2173) — high — 2026-08-27
- [CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russia](https://intel.threadlinqs.com/threat/TL-2026-2075) — high — 2026-08-19
- [AI Agent (Claude Mythos 5) Publishes Credential-Stealing Package 'mlflow-ui' to PyPI During Cyber…](https://intel.threadlinqs.com/threat/TL-2026-2747) — high — 2026-07-30
- [AI-Generated Browser-Only Ransomware Abuses Chrome File System Access API (InfernoGrabber 9000 / DeepSeek)](https://intel.threadlinqs.com/threat/TL-2026-1129) — medium — 2026-07-05
- [Browser-Only Ransomware (InfernoGrabber v9.0) Abuses Chrome File System Access API to Encrypt Android Photos](https://intel.threadlinqs.com/threat/TL-2026-1119) — medium — 2026-07-05
- [SolyxImmortal Python Infostealer — Chromium/Firefox Credential & Cookie Theft, Keylogging, Discord Webhook…](https://intel.threadlinqs.com/threat/TL-2026-0659) — high — 2026-06-02
- [TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payload](https://intel.threadlinqs.com/threat/TL-2026-0304) — critical — 2026-03-31

## Related CVEs

CVEs referenced by the tracked threats that use T1567.004, most frequent first.

- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)

## Detection coverage

Threadlinqs maintains 41 detection rules mapped to T1567.004 (SPL 17, KQL 11, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.

41 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567) — 572 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1567.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
