Threat Actors Favor Rclone, WinSCP and cURL as Data Exfiltration Tools
Summary: Link(s):
Data exfiltration has become a key component in double extortion ransomware attacks, which are now a prevalent method used by cybercriminals. According to a new report by ReliaQuest, the top three tools used for data exfiltration between September 2023 and July 2024 are Rclone, WinSCP, and cURL. Data exfiltration involves the unauthorized transfer of data from enterprise or personal devices, often through threat actor–owned infrastructure or third-party cloud services. Cybercriminals use these tools to collect and extract large amounts of data, threatening to leak it if the victim doesn't pay the ransom.
Rclone, an open-source command-line utility, is the most widely used exfiltration tool, involved in 57% of ransomware incidents during the reported period. Its popularity stems from its fast data-transfer capabilities, cross-platform support, and ability to integrate with numerous cloud services, making it difficult for defenders to mitigate.
WinSCP, another open-source file transfer utility, is known for its user-friendly interface and is trusted by organizations, making it less likely to raise suspicion when found on a system. It offers efficient data transfers with robust error handling and logging features.
cURL, a command-line tool that transfers data via URLs, is often used for interacting with web services and is native to Windows 10, allowing attackers to use it without needing to install additional software. While not as reliable for large-scale data exfiltration as Rclone and WinSCP, cURL is effective for extracting critical information.
Security Officer Comments:
ReliaQuest also notes that other tools, such as MEGA Cloud Storage, FileZilla, Restic, and remote monitoring and management (RMM) software, are also used by cybercriminals for data exfiltration.
Suggested Corrections:
ReliaQuest recommends the following measures to prevent or reduce the impact of data-exfiltration attempts:
https://www.infosecurity-magazine.com/news/rclone-winscp-curl-top-data/