TACTIC: EXFILTRATION
Automated Exfiltration (T1020): real cases
MITRE Definition ↗ Adversaries use automated scripts to periodically transmit collected data out of the network.
Key Facts
Technique ID
T1020
Exfiltration
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
- ATT&CK Technique Identifier: T1020.
- Tactical Phase: Exfiltration.
- Substantiated in 1 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)
sentenced 2018-03-27
Primary Source Evidence Excerpt: Plea Agreement ¶ 9, Page 6
"Automated batch scripts compressed and transmitted stolen point-of-sale logs every night at midnight to C2 drops."
U.S. District Court for the Western District of Washington
View full case dossier →