T1567Exfiltration Over Web Service
T1567 — Exfiltration Over Web Service is a MITRE ATT&CK technique in the Exfiltration tactic. Clankerusecase tracks 71 detection use cases covering it and 48 threat-intel articles citing it.
Exfiltration
71Use cases
48Articles
4Sub-techniques
1Tactic
Sub-techniques (4)
Use cases covering this technique (71)
Application data exfiltration successful [WEEKLY] Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s [WEEKLY] SSRF-Driven Secret Egress: Public-Facing App Reaches Cloud Metadata/Attacker Host [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra O365 DLP Rule Triggered O365 Email Access By Security Administrator O365 Exfiltration via File Access O365 Exfiltration via File Download O365 Exfiltration via File Sync Download Linux Gdrive Binary Activity LOLBAS With Network Traffic Windows Gdrive Binary Activity Cisco TFTP Server Configuration for Data Exfiltration High Volume of Bytes Out to Url Splunk Data exfiltration from Analytics Workspace using sid query [LLM] Endpoint egress/DNS to anonfilesnew.com anonymous file host (TheHatman sample staging) [LLM] conflibot post-injection secret exfiltration: token grab by git/shell child on CI runner (CVE-2026-55158) [LLM] TeamPCP CI/CD credential-stealer C2 egress to 83.142.209.203 / checkmarx.zone [LLM] JWR phishing kit exfiltration & instruction API endpoints (/api/open/the_final_interface, addCvv) [LLM] anthropickit exfiltration POST to Pipedream endpoint (enqqnvvtgrnyl.x.pipedream.net) [LLM] flyto-verification runner egress to external public host — FLYTO_RUNNER_SECRET exfiltration [LLM] Budibase server leaks datasource auth to first-seen host (undici + Authorization egress) [LLM] Network egress from CI/build host to GhostAction secret-exfil infrastructure [LLM] CI runner process POSTing secrets to GhostAction exfil host via curl/wget/node [LLM] Shai-Hulud credential exfiltration: node/npm outbound to webhook.site [LLM] Injective SDK wallet-key exfil to lookalike domain testnet.archival.chain.grpc-web.injective.network [LLM] First-seen external egress from GitHub Actions Runner.Worker child process [LLM] Developer-runtime exfiltration to webhook.site (Shai-Hulud token drop) [LLM] Exfiltration to attacker-controlled Sentry ingest endpoint (onering crate) [LLM] Rust build script making outbound network connection (build-time exfil) [LLM] node child of npm install initiating outbound network to non-registry destination [LLM] Mini Shai-Hulud npm worm exfil to filev2.getsession.org [LLM] postmark-mcp BCC exfil to giftshop.club [LLM] DNS/HTTPS exfil to sentry.anyclaw.store (Codex token C2 masquerading as Sentry) [LLM] Mini Shai-Hulud npm worm C2/exfil egress (masscan.cloud, git-tanstack.com, getsession.org) [LLM] Megalodon CI/CD exfil: outbound HTTPS to C2 216.126.225.129:8443 [LLM] DNS / Network egress to TeamPCP Nx Console C2 domain check.git-service.com [LLM] Outbound C2 to t.m-kosche.com from CI/CD runner or any endpoint [LLM] Mini Shai-Hulud GitHub dead-drop exfiltration via python-requests/2.31.0 [LLM] Mini Shai-Hulud npm Worm C2 callback to Session Protocol CDN and masscan.cloud [LLM] Shai-Hulud style repository poisoning — .claude/router_runtime.js drop [LLM] Mini Shai-Hulud 'OhNoWhatsGoingOnWithGitHub' dead-drop keyword in outbound URL [LLM] Svix Ingest webhook exfiltration relay (src_3387PLMB2uhXOBe3Q8sHu) [LLM] Mini Shai-Hulud post-compromise persistence artifacts in .claude/, .vscode/, .github/workflows/ [LLM] Exfil to skyhanni.cloud C2 with X-Rise-To-The-Trinny header [LLM] Suspicious draft email manipulation against barrantaya.1010@outlook.com (BoxOfFriends Graph API C2) [LLM] Shai-Hulud preinstall: node/npm spawning git/curl/gh pushing to attacker repo or GitHub API [LLM] hackerbot-claw payload host: DNS/HTTP egress to hackmoltrepeat.com (C2 + exfil) [LLM] hackerbot-claw token exfiltration: curl POST with GITHUB_TOKEN to recv.hackmoltrepeat.com [LLM] Trivy supply-chain C2 beacon to typosquat domain scan.aquasecurtiy.org [LLM] DNS tunneling exfiltration pattern to *.t.opentensor-cdn.com (hex chunk/index/total/session) [LLM] C2 beaconing to Vercel-hosted Cloudflare-impersonating domains (cloudflareguard / cloudflareinsights) [LLM] Outbound traffic to *.oastify.com (BurpSuite Collaborator) from corporate endpoint [LLM] Egress to Qix npm phishing/exfil infrastructure (npmjs.help, publicvm.com, BunnyCDN buckets) [LLM] GhostChat C2 beacon URL pattern: hitpak.org/page.php?tynor=<host>sss<user> [LLM] Shai-Hulud 3.0 'Goldox-T3chs' GitHub exfiltration marker observed [LLM] Outbound exfiltration to webhook.site from npm / node / bun process tree [LLM] Outbound email BCC'd to giftshop.club exfil domain (postmark-mcp backdoor) [LLM] DNS or HTTP egress to giftshop.club exfil domain [LLM] Shai-Hulud worm C2 exfiltration to webhook.site UUID bb8ca5f6 [LLM] Egress to websocket-api2.publicvm.com (Qix campaign credential exfil C2) [LLM] Discord webhook / CDN exfiltration from non-browser process (Empyrean stealer C2) [LLM] npm dropper exfiltration to pkgio.com telemetry server [LLM] SourMint/Mintegral SDK covert click-data exfiltration to n.systemlog.me [LLM] Agama wallet C2/exfil callback to updatecheck.herokuapp.com (electron-native-notify) [LLM] Copay wallet-stealer C2 exfil to copayapi.host / 111.90.151.134Articles citing this technique (48)
crit Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List. art-35
high Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization art-221
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-458
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-515
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-520
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-596
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-673