Ransomware threat actors routinely stage and exfiltrate data before deploying file encryption to enable 'double extortion.' Huntress analysts document real-world command lines and tools observed in incidents, including 7Zip, WinRAR, FileZilla (fzsftp.exe), RClone, Restic, BackBlaze (b2.exe), WinSCP, and the increasingly used s5cmd — an open-source S3-compatible tool spotted in Qilin ransomware attacks. LOLBins like finger.exe, ftp.exe, and bitsadmin.exe are also abused for exfiltration. Detection is challenging because these techniques closely resemble legitimate sysadmin activity. Huntress data shows exfiltration preceded ransomware deployment in over 70% of attacks. Defenders are advised to monitor for specific tool usage patterns tied to archival and cloud-sync utilities.

6m read timeFrom huntress.com
Post cover image
Table of contents
Data staging: From archival tools to cloud storage sitesData exfiltration: LOLBins, backup utilities, and RCloneS5cmd for data exfiltrationData exfiltration: Detection challenges
2 Impressions