396. Another Cloud Storage Abused by Akira Affiliates for Exfiltration

Hello everyone!

To be honest, after nearly 400 posts, finding something interesting in public reports has become a bit more challenging. Nevertheless, it’s still possible, and today we’ll once again talk about Exfiltration to Cloud Storage (T1567.002).

This time, the post is sponsored by our partners at Akira, and the following excerpt from a report caught my attention:

“Next, the threat actor used the Microsoft Edge browser to access Bing, and search for the term ‘eayupload’ before settling on Easyupload.io, a website that provides access to file uploads via drag-and-drop.”

As you can see, the attackers used yet another cloud storage service to upload the data they had collected. Access to such services can be proactively blocked, or you can monitor for suspicious connections to them:

event_type: "dnsreq"

AND

dns_rname: "easyupload.io"

Attackers are increasingly relying on legitimate tools and services, so understanding exactly which ones they may use can become a key factor in stopping them before any damage is done.

See you soon!

Comments

Popular posts from this blog

343. Ransomware Gangs Abuse SystemSettingsAdminFlows to Evade Defenses

391. Hunting for TeamPCP's Stealer

082. Huniting for Malicious Browser Extensions