# T1567 Exfiltration Over Web Service

> As of 2026-10-05, T1567 (Exfiltration Over Web Service) appears in 572 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including TeamPCP, ShinyHunters, Contagious Interview; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 572 (175 critical, 322 high, 66 medium, 3 low)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-03
- **Threat actors:** 141
- **Detection rules:** 634 (counts only; Blue tier and above)

## Key facts

- **ID:** T1567
- **Framework:** MITRE ATT&CK
- **Tactics:** Exfiltration
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1567/

## Activity timeline

T1567 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 187 reports, and 572 of the 572 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1567 Exfiltration Over Web Service is catalogued by MITRE ATT&CK under the Exfiltration tactic in the Enterprise matrix. Threadlinqs maps 572 of 2623 tracked threats (21.8%) to it; by severity that is 175 critical, 322 high, 66 medium, 3 low.

Threats that use T1567 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (301 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (300 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (286 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (263 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (258 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

141 tracked threat actors appear in the threats that use T1567; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (27), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (18), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (14), [APT38](https://intel.threadlinqs.com/actor/APT38) (10), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (10).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1567.

- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1057 Data Loss Prevention](https://attack.mitre.org/mitigations/M1057/)

## Data sources

Telemetry that can reveal T1567, per MITRE ATT&CK.

- Application Log — Application Log Content
- Command — Command Execution
- File — File Access
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 27
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 18
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 14
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 10
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 10
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 9
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 9
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 8
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 8
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 8
- [UNC6040](https://intel.threadlinqs.com/actor/UNC6040) — 8
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 7

## Tracked threats

The 30 most recent of 572 tracked threats that use T1567.

- [AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…](https://intel.threadlinqs.com/threat/TL-2026-2880) — high — 2026-10-03
- [CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…](https://intel.threadlinqs.com/threat/TL-2026-2802) — high — 2026-09-30
- [MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer](https://intel.threadlinqs.com/threat/TL-2026-2801) — high — 2026-09-30
- [North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling](https://intel.threadlinqs.com/threat/TL-2026-2782) — high — 2026-09-29
- [Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)](https://intel.threadlinqs.com/threat/TL-2026-2757) — high — 2026-09-28
- [Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…](https://intel.threadlinqs.com/threat/TL-2026-2739) — high — 2026-09-28
- [ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…](https://intel.threadlinqs.com/threat/TL-2026-2730) — high — 2026-09-28
- [CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…](https://intel.threadlinqs.com/threat/TL-2026-2726) — critical — 2026-09-28
- [SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM Data Exfiltration in Salesforce Agentforce](https://intel.threadlinqs.com/threat/TL-2026-2710) — high — 2026-09-27
- [AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt…](https://intel.threadlinqs.com/threat/TL-2026-2668) — medium — 2026-09-26
- [Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)](https://intel.threadlinqs.com/threat/TL-2026-2713) — medium — 2026-09-25
- [Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2670) — high — 2026-09-25
- [TokenGrabber: Python-based MaaS Infostealer Builder](https://intel.threadlinqs.com/threat/TL-2026-2643) — high — 2026-09-25
- [SalesBleed: Salesforce Agentforce vulnerabilities enable zero-click CRM data theft and trusted-agent Slack…](https://intel.threadlinqs.com/threat/TL-2026-2642) — high — 2026-09-24
- [OAuth Token Theft via Sideloaded AppX Packages Abusing Microsoft-Signed Web Hosts (WWAHost.exe)](https://intel.threadlinqs.com/threat/TL-2026-2628) — high — 2026-09-23
- [TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…](https://intel.threadlinqs.com/threat/TL-2026-2616) — high — 2026-09-22
- [BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection](https://intel.threadlinqs.com/threat/TL-2026-2610) — medium — 2026-09-21
- [Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated](https://intel.threadlinqs.com/threat/TL-2026-2598) — high — 2026-09-21
- [ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour…](https://intel.threadlinqs.com/threat/TL-2026-2584) — medium — 2026-09-19
- [EtherHiding / Blockchain Dead Drops: Nation-State Actors Drive 440% Surge in On-Chain Malware C2](https://intel.threadlinqs.com/threat/TL-2026-2547) — high — 2026-09-17
- [Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…](https://intel.threadlinqs.com/threat/TL-2026-2545) — high — 2026-09-16
- [Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-2472) — high — 2026-09-13
- [Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated…](https://intel.threadlinqs.com/threat/TL-2026-2466) — critical — 2026-09-12
- [OpenAI Agent Swarm ("GemStuffer") Flooded RubyGems With 2,000+ Malicious Packages, Achieved RCE on…](https://intel.threadlinqs.com/threat/TL-2026-2459) — high — 2026-09-12
- [CVE-2025-25249: Fortinet Heap-Based Buffer Overflow Exploited to Deploy PivotC2 RAT on FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2431) — critical — 2026-09-10
- [Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran…](https://intel.threadlinqs.com/threat/TL-2026-2420) — high — 2026-09-09
- [Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2416) — high — 2026-09-09
- [Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…](https://intel.threadlinqs.com/threat/TL-2026-2409) — critical — 2026-09-08
- [Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED Leak](https://intel.threadlinqs.com/threat/TL-2026-2383) — high — 2026-09-07
- [BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2374) — critical — 2026-09-07

## Related CVEs

CVEs referenced by the tracked threats that use T1567, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-59536](https://intel.threadlinqs.com/cve/CVE-2025-59536)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-21852](https://intel.threadlinqs.com/cve/CVE-2026-21852)
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2017-11317](https://intel.threadlinqs.com/cve/CVE-2017-11317)
- [CVE-2019-18935](https://intel.threadlinqs.com/cve/CVE-2019-18935)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)

## Detection coverage

Threadlinqs maintains 634 detection rules mapped to T1567 (SPL 226, KQL 196, Sigma 210, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.

634 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1567.001 Exfiltration to Code Repository](https://intel.threadlinqs.com/technique/T1567.001) — 26 tracked threats
- [T1567.002 Exfiltration to Cloud Storage](https://intel.threadlinqs.com/technique/T1567.002) — 120 tracked threats
- T1567.003 Exfiltration to Text Storage Sites — 0 tracked threats
- [T1567.004 Exfiltration Over Webhook](https://intel.threadlinqs.com/technique/T1567.004) — 15 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1567
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
