216.73.217.22

Rclone

The MITRE Corporation · Published 30/08/2022 15:02 · Modified 27/03/2026 01:07

Essential information

Confidence
100/100
Published
30/08/2022 15:02
Modified
27/03/2026 01:07
Revoked
No
Author / Source
The MITRE Corporation
Related entities
6 attack patterns (mitre), 9 intrusion sets (apt), 1 campaign, 1 campaigns

Description

[Rclone](https://attack.mitre.org/software/S1040) is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. [Rclone](https://attack.mitre.org/software/S1040) has been used in a number of ransomware campaigns, including those associated with the [Conti](https://attack.mitre.org/software/S0575) and DarkSide Ransomware-as-a-Service operations.(Citation: Rclone)(Citation: Rclone Wars)(Citation: Detecting Rclone)(Citation: DarkSide Ransomware Gang)(Citation: DFIR Conti Bazar Nov 2021)

Marking (TLP)

Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references