T1030: T1030
Essential information
- MITRE technique ID
T1030- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:38
- Modified
- 17/04/2026 12:45
- Author / Source
- The MITRE Corporation
Aliases
Data Transfer Size Limits
Platforms
windows macos linux ESXi
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | exfiltration |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (13)
-
UNC5820 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 08:03 · Modified 21/12/2025 08:03
-
The MITRE Corporation Confidence 100
[Kimsuky](https://attack.mitre.org/groups/G0094) is a North Korea-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
play usesThe MITRE Corporation Confidence 100
Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[APT29](https://attack.mitre.org/groups/G0016) is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).(Citation: White House Imposing Costs RU Gov April 2021)(Citation: UK Gov Malign RIS Activity April …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
The MITRE Corporation Confidence 100
[BITTER](https://attack.mitre.org/groups/G1002) is a suspected South Asian cyber espionage threat group that has been active since at least 2013. [BITTER](https://attack.mitre.org/groups/G1002) has targeted government, energy, and engineering organizations in Pakistan, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 09/04/2026 20:05 -
Blackwood usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 02:55 · Modified 21/12/2025 02:55
-
LuminousMoth usesThe MITRE Corporation Confidence 100
[LuminousMoth](https://attack.mitre.org/groups/G1014) is a Chinese-speaking cyber espionage group that has been active since at least October 2020. [LuminousMoth](https://attack.mitre.org/groups/G1014) has targeted high-profile organizations, including government entities, in Myanmar, the Philippines, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[APT41](https://attack.mitre.org/groups/G0096) is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, [APT41](https://attack.mitre.org/groups/G0096) has been observed …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
Worok usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 22:03 · Modified 20/12/2025 22:03
-
The MITRE Corporation Confidence 100
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 08/04/2026 13:02 -
The MITRE Corporation Confidence 100
[Mustang Panda](https://attack.mitre.org/groups/G0129) is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. [Mustang Panda](https://attack.mitre.org/groups/G0129) has been known to use tailored phishing lures …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 22/05/2026 04:12 -
The MITRE Corporation Confidence 100
[Threat Group-3390](https://attack.mitre.org/groups/G0027) is a Chinese threat group that has extensively used strategic Web compromises to target victims.(Citation: Dell TG-3390) The group has been active since at least 2010 …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
Icarus relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 23/06/2026 11:20 · Modified 23/06/2026 11:20
Malware (32)
- KoboldLoader
- Robin Banks
-
FamilyPublished 27/03/2025 21:47 · Modified 27/03/2025 21:47
- Kevin
- OopsIE
-
GoldPickaxe usesFamilyPublished 20/02/2025 20:48 · Modified 20/02/2025 20:48
-
Roarur usesFamilyPublished 20/05/2026 17:45 · Modified 20/05/2026 17:45
- HookSpoofer
- Agent Racoon
- POSHSPY
-
UniShadowTrade usesFamilyPublished 04/10/2024 10:27 · Modified 04/10/2024 10:27
- Ntospy
-
CGrabber Stealer usesFamilyPublished 17/04/2026 09:21 · Modified 17/04/2026 09:21
- Carbanak
- Virlock
- Almond
- ZxxZ
-
Hydraq - S0203 usesFamilyPublished 20/05/2026 17:45 · Modified 20/05/2026 17:45
- LithiumLoader
- AppleSeed
- ObliqueRAT
-
LunarWeb usesFamilyPublished 16/05/2024 09:35 · Modified 16/05/2024 09:35
- StealBit
- Kessel
- Mimilite
- MuuyDownloader
-
RDAT usesFamily The MITRE Corporation Confidence 100
[RDAT](https://attack.mitre.org/software/S0495) is a backdoor used by the suspected Iranian threat group [OilRig](https://attack.mitre.org/groups/G0049). [RDAT](https://attack.mitre.org/software/S0495) was originally identified in 2017 and targeted companies in the telecommunications sector.(Citation: Unit42 RDAT July …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:36 · Modified 27/03/2026 01:03 -
Direct-Sys Loader usesFamilyPublished 17/04/2026 09:21 · Modified 17/04/2026 09:21
- MagnetLoader
- Helminth
-
Cobalt Strike usesFamilyPublished 16/12/2024 14:25 · Modified 16/12/2024 14:25
-
Gootloader usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
Reports (8)
-
AlienVault Confidence 100 13 MITREs 3 IOCs 3 Observables 1 APTPublished 22/06/2026 22:21 · threat-report
-
Threat landscape — Belgium relatedConfidence 100 18 CVEs 200 MITREs 200 Malwares 20 APTs 26 ToolsPublished 29/05/2026 11:51 · threat-report
-
AlienVault Confidence 100 20 MITREs 3 IOCs 3 Observables 1 APTPublished 18/05/2026 21:29 · Modified 18/05/2026 19:56 · threat-report
-
19 MITREs 2 Malwares 91 ObservablesPublished 17/04/2026 09:21 · Modified 17/04/2026 10:45
-
11 MITREs 1 Malware 1 APTPublished 27/03/2025 21:47 · Modified 27/03/2025 21:54
-
1 CVE 10 MITREs 4 Observables 1 APTPublished 24/10/2024 11:31 · Modified 28/10/2024 12:55
-
11 MITREs 2 Malwares 9 ObservablesPublished 04/10/2024 10:27 · Modified 04/10/2024 12:42
-
15 MITREs 10 Malwares 15 ObservablesPublished 10/09/2024 08:11 · Modified 10/09/2024 08:24
Vulnerabilities (CVE) (2)
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code …
- Published
- 03/11/2021
- Modified
- 27/05/2026
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager …
- Attack vector
- Network
- Published
- 23/10/2024
- Modified
- 21/12/2025
Tool (2)
-
Mythic usesThe MITRE Corporation Confidence 100
[Mythic](https://attack.mitre.org/software/S0699) is an open source, cross-platform post-exploitation/command and control platform. [Mythic](https://attack.mitre.org/software/S0699) is designed to "plug-n-play" with various agents and communication channels.(Citation: Mythic Github)(Citation: Mythic SpecterOps)(Citation: Mythc Documentation) Deployed …
Published 26/03/2022 02:38 · Modified 27/03/2026 01:07 -
Rclone usesThe MITRE Corporation Confidence 100
[Rclone](https://attack.mitre.org/software/S1040) is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. [Rclone](https://attack.mitre.org/software/S1040) has been used in a …
Published 16/12/2025 19:37 · Modified 27/03/2026 01:07
Course Of Action (1)
- Network Intrusion Prevention mitigates
Campaign (2)
- C0015 uses
- C0026 uses