T1020: T1020
Essential information
- MITRE technique ID
T1020- Confidence
- 100/100
- Revoked
- No
- Published
- 31/05/2017 23:30
- Modified
- 27/03/2026 01:10
- Author / Source
- The MITRE Corporation
Aliases
Automated Exfiltration
Platforms
windows macos linux Network Devices
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | exfiltration |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (50)
-
The MITRE Corporation Confidence 100
Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group.<br> <br> It's worth…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (73)
-
PureHVNC usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Kiron usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Godzilla usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
LameHug usesAlienVault Confidence 100
[LAMEHUG](https://attack.mitre.org/software/S9035) is Python-based information stealer first identified in July 2025 by Ukraine's Computer Emergency Response Team (CERT-UA) in phishing emails targeting Ukrainian government officials. [LAMEHUG](https://attack.mitre.org/software/S9035) is the first…
First seen 01/01/1970 · Last seen 16/11/5138 · -
IcedID usesFamily The MITRE Corporation Confidence 100
[IcedID](https://attack.mitre.org/software/S0483) is a modular banking malware designed to steal financial information that has been observed in the wild since at least 2017. [IcedID](https://attack.mitre.org/software/S0483) has been downloaded by [Emotet](https://attack.mitre.org/software/S0367)…
First seen 01/01/1970 · Last seen 16/11/5138 · -
TrojanSpy usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
COBEACON usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Lumma Stealer usesThe MITRE Corporation Confidence 100
[Lumma Stealer](https://attack.mitre.org/software/S1213) is an information stealer malware family in use since at least 2022. [Lumma Stealer](https://attack.mitre.org/software/S1213) is a Malware as a Service (MaaS) where captured data has been…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Hannotog usesFamily The MITRE Corporation Confidence 100
[Hannotog](https://attack.mitre.org/software/S1211) is a type of backdoor malware uniquely assoicated with [Lotus Blossom](https://attack.mitre.org/groups/G0030) operations since at least 2022.(Citation: Symantec Bilbug 2022)
First seen 01/01/1970 · Last seen 16/11/5138 · -
sysProcUpdate usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
BlackCat usesFamily The MITRE Corporation Confidence 100
[BlackCat](https://attack.mitre.org/software/S1068) is ransomware written in Rust that has been offered via the Ransomware-as-a-Service (RaaS) model. First observed November 2021, [BlackCat](https://attack.mitre.org/software/S1068) has been used to target multiple sectors and…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Rhadamanthys usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Reports (41)
-
16 MITREs 3 Malwares 1 Observable 1 APT
-
19 MITREs 1 Malware
-
1 CVE 12 MITREs 1 Malware 2 Observables 1 APT
-
SystemBC – Bringing the Noise related13 MITREs 9 Malwares 158 Observables
-
9 MITREs
-
19 MITREs 1 Malware 15 Observables 1 APT
-
Analyzing LAMEHUG related13 MITREs 1 Malware 1 APT
-
11 MITREs 1 Malware 5 Observables
-
16 MITREs 7 Malwares 1 APT
-
APT37 - RokRat related21 MITREs 1 Malware 9 Observables 1 APT
-
18 MITREs 5 Malwares
-
17 MITREs 2 Malwares
Vulnerabilities (CVE) (37)
RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary …
- Attack vector
- Network
- Published
- 12/08/2025
- Modified
- 27/05/2026
Attack patterns (MITRE) (1)
-
Traffic Duplication subtechnique-of
Tool (1)
-
ShimRatReporter usesThe MITRE Corporation Confidence 100
[ShimRatReporter](https://attack.mitre.org/software/S0445) is a tool used by suspected Chinese adversary [Mofang](https://attack.mitre.org/groups/G0103) to automatically conduct initial discovery. The details from this discovery are used to customize follow-on payloads (such as…
Campaign (1)
-
ArcaneDoor uses