Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service. A defender who is monitoring for large transfers to outside the cloud environment through normal file transfers or over command and control channels may not be watching for data transfers to another account within the same cloud provider. Such transfers may utilize existing cloud provider APIs and the internal address space of the cloud provider to blend into normal traffic or avoid data transfers over external network interfaces.(Citation: TLDRSec AWS Attacks) Adversaries may also use cloud-native mechanisms to share victim data with adversary-controlled cloud accounts, such as creating anonymous file sharing links or, in Azure, a shared access signature (SAS) URI.(Citation: Microsoft Azure Storage Shared Access Signature) Incidents have been observed where adversaries have created backups of cloud instances and transferred them to separate accounts.(Citation: DOJ GRU Indictment Jul 2018)

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Data Loss Prevention
is blocked by User Account Management
is blocked by Software Configuration
is blocked by Cross-Platform Detection of Data Transfer to Cloud Account
is blocked by Filter Network Traffic
is blocked by Access Restriction For Change
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Cybersecurity & Data Protection Attributes
is blocked by Use of External Technology Assets, Applications and/or Services (TAAS)
is blocked by Separation of Duties (SoD)
is blocked by Identification & Authentication for Organizational Users
is blocked by Identification & Authentication for Non-Organizational Users
is blocked by Identification & Authentication for Devices
is blocked by Identifier Management (User Names)
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Boundary Protection
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Remote Access
is blocked by Information Output Filtering
is blocked by Input Data Validation
Impressum German English