T1567Exfiltration Over Web Service
T1567 — Exfiltration Over Web Service is a MITRE ATT&CK technique in the Exfiltration tactic. Clankerusecase tracks 71 detection use cases covering it and 49 threat-intel articles citing it.
Exfiltration
71Use cases
49Articles
4Sub-techniques
1Tactic
Sub-techniques (4)
Use cases covering this technique (71)
Application data exfiltration successful [WEEKLY] Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra O365 DLP Rule Triggered O365 Email Access By Security Administrator O365 Exfiltration via File Access O365 Exfiltration via File Download O365 Exfiltration via File Sync Download Linux Gdrive Binary Activity LOLBAS With Network Traffic Windows Gdrive Binary Activity Cisco TFTP Server Configuration for Data Exfiltration High Volume of Bytes Out to Url Splunk Data exfiltration from Analytics Workspace using sid query [LLM] Bulk M365 / SharePoint / OneDrive file download by a single identity (cloud data theft) [LLM] TELESHIM/MIXEDKEY sideload host binary beacons to Telegram (C2 + exfil) [LLM] InsureOTP kit exfiltration: browser connecting to api.telegram.org Bot API [LLM] Budibase server leaks datasource auth to first-seen host (undici + Authorization egress) [LLM] macOS BlueNoroff stealer exfiltrating to Telegram bot (Aurora channel) [LLM] Network egress from CI/build host to GhostAction secret-exfil infrastructure [LLM] CI runner process POSTing secrets to GhostAction exfil host via curl/wget/node [LLM] Shai-Hulud credential exfiltration: node/npm outbound to webhook.site [LLM] Injective SDK wallet-key exfil to lookalike domain testnet.archival.chain.grpc-web.injective.network [LLM] CVE-2026-50027 unauthenticated bulk read/enumeration of mcp-memory-service document store [LLM] First-seen external egress from GitHub Actions Runner.Worker child process [LLM] Developer-runtime exfiltration to webhook.site (Shai-Hulud token drop) [LLM] Exfiltration to attacker-controlled Sentry ingest endpoint (onering crate) [LLM] Rust build script making outbound network connection (build-time exfil) [LLM] node child of npm install initiating outbound network to non-registry destination [LLM] Mini Shai-Hulud npm worm exfil to filev2.getsession.org [LLM] postmark-mcp BCC exfil to giftshop.club [LLM] DNS/HTTPS exfil to sentry.anyclaw.store (Codex token C2 masquerading as Sentry) [LLM] Mini Shai-Hulud npm worm C2/exfil egress (masscan.cloud, git-tanstack.com, getsession.org) [LLM] Megalodon CI/CD exfil: outbound HTTPS to C2 216.126.225.129:8443 [LLM] DNS / Network egress to TeamPCP Nx Console C2 domain check.git-service.com [LLM] Outbound C2 to t.m-kosche.com from CI/CD runner or any endpoint [LLM] Mini Shai-Hulud GitHub dead-drop exfiltration via python-requests/2.31.0 [LLM] Mini Shai-Hulud npm Worm C2 callback to Session Protocol CDN and masscan.cloud [LLM] Shai-Hulud style repository poisoning — .claude/router_runtime.js drop [LLM] Mini Shai-Hulud 'OhNoWhatsGoingOnWithGitHub' dead-drop keyword in outbound URL [LLM] Svix Ingest webhook exfiltration relay (src_3387PLMB2uhXOBe3Q8sHu) [LLM] Mini Shai-Hulud post-compromise persistence artifacts in .claude/, .vscode/, .github/workflows/ [LLM] Exfil to skyhanni.cloud C2 with X-Rise-To-The-Trinny header [LLM] Suspicious draft email manipulation against barrantaya.1010@outlook.com (BoxOfFriends Graph API C2) [LLM] Shai-Hulud preinstall: node/npm spawning git/curl/gh pushing to attacker repo or GitHub API [LLM] hackerbot-claw payload host: DNS/HTTP egress to hackmoltrepeat.com (C2 + exfil) [LLM] hackerbot-claw token exfiltration: curl POST with GITHUB_TOKEN to recv.hackmoltrepeat.com [LLM] TeamPCP tpcp.tar.gz exfil POST signature on egress proxy / WAF [LLM] Trivy supply-chain C2 beacon to typosquat domain scan.aquasecurtiy.org [LLM] DNS tunneling exfiltration pattern to *.t.opentensor-cdn.com (hex chunk/index/total/session) [LLM] C2 beaconing to Vercel-hosted Cloudflare-impersonating domains (cloudflareguard / cloudflareinsights) [LLM] Outbound traffic to *.oastify.com (BurpSuite Collaborator) from corporate endpoint [LLM] Egress to Qix npm phishing/exfil infrastructure (npmjs.help, publicvm.com, BunnyCDN buckets) [LLM] GhostChat C2 beacon URL pattern: hitpak.org/page.php?tynor=<host>sss<user> [LLM] Nx s1ngularity exfiltration via public GitHub repo 's1ngularity-repository' [LLM] Shai-Hulud 3.0 'Goldox-T3chs' GitHub exfiltration marker observed [LLM] Outbound exfiltration to webhook.site from npm / node / bun process tree [LLM] Outbound email BCC'd to giftshop.club exfil domain (postmark-mcp backdoor) [LLM] DNS or HTTP egress to giftshop.club exfil domain [LLM] Shai-Hulud worm C2 exfiltration to webhook.site UUID bb8ca5f6 [LLM] Egress to websocket-api2.publicvm.com (Qix campaign credential exfil C2) [LLM] Discord webhook / CDN exfiltration from non-browser process (Empyrean stealer C2) [LLM] npm dropper exfiltration to pkgio.com telemetry server [LLM] SourMint/Mintegral SDK covert click-data exfiltration to n.systemlog.me [LLM] Agama wallet C2/exfil callback to updatecheck.herokuapp.com (electron-native-notify) [LLM] Copay wallet-stealer C2 exfil to copayapi.host / 111.90.151.134Articles citing this technique (49)
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-74
high Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization art-114
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-412
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-471
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-475
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-555
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-640