TACTIC: EXFILTRATION
Exfiltration Over C2 Channel (T1041): real cases
MITRE Definition ↗ Adversaries transmit stolen data over existing command and control channels back to adversary servers.
Key Facts
Technique ID
T1041
Exfiltration
Mapped Cases
8
Primary sources
Related Laws
4
Criminal statutes
- ATT&CK Technique Identifier: T1041.
- Tactical Phase: Exfiltration.
- Substantiated in 8 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
ALPHV / BlackCat Ransomware Attack on Change Healthcare
alleged 2024-02-21
Primary Source Evidence Excerpt: HHS OCR Notice
"Stolen medical claims and personally identifiable information were uploaded to adversary-controlled cloud servers prior to payload delivery."
U.S. District Court for the District of Minnesota
View full case dossier →
Colonial Pipeline DarkSide Ransomware Attack
pleaded 2021-05-07
Primary Source Evidence Excerpt: FBI Alert Flash
"Adversaries exfiltrated approximately 100 gigabytes of internal corporate documents to cloud servers before deploying encryption routines."
U.S. District Court for the Northern District of California
View full case dossier →
U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)
sentenced 2018-03-27
Primary Source Evidence Excerpt: Plea Agreement ¶ 8
"Defendants harvested payment card track data from Point-of-Sale (POS) memory and exfiltrated records back to private C2 servers."
U.S. District Court for the Western District of Washington
View full case dossier →
U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)
sentenced 2011-03-03
Primary Source Evidence Excerpt: Trial Exhibit 14-A
"Malicious memory-scraping software extracted Track 2 payment card data from process memory and exfiltrated packets to Russian server drops."
U.S. District Court for the Western District of Washington
View full case dossier →
U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)
fugitive 2014-05-01
Primary Source Evidence Excerpt: Indictment ¶ 29, Page 16
"Exfiltrated thousands of sensitive proprietary technical specifications including AP1000 nuclear reactor piping diagrams."
U.S. District Court for the Western District of Pennsylvania
View full case dossier →
U.S. v. Albert Gonzalez (TJX & Heartland Payment Systems)
sentenced 2008-08-05
Primary Source Evidence Excerpt: Indictment ¶ 22, Page 10
"Installed packet sniffer utilities inside Heartland's payment processing network that captured unencrypted credit card magnetic stripe data during authorization."
U.S. District Court for the District of Massachusetts
View full case dossier →
U.S. v. Andrei Tyurin (JPMorgan Chase Data Breach)
sentenced 2015-11-10
Primary Source Evidence Excerpt: Indictment ¶ 15, Page 8
"Exfiltrated contact records of 83 million individual and small business accounts, the largest single corporate breach of a U.S. bank at the time."
U.S. District Court for the Southern District of New York
View full case dossier →
Snowflake Customer Multi-Tenant Credential Stuffing Campaign
alleged 2024-05-31
Primary Source Evidence Excerpt: CISA Advisory Alert
"Adversaries executed native SQL commands in Snowflake command-line clients (snowsql) to stage and export customer database tables."
U.S. District Court for the Northern District of California
View full case dossier →
Commonly Charged Criminal Statutes
18 U.S.C. § 1030(a)(2)
Unauthorized Access to Obtain Protected Information
Prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain financial, government, or protected computer records.
18 U.S.C. § 1030(a)(5)(A)
Intentional Damage to a Protected Computer
Prohibits knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer.
18 U.S.C. § 1030(a)(7)
Extortion in Connection with Computers
Prohibits transmitting in interstate or foreign commerce threats to cause damage to a protected computer or obtain confidential information with intent to extort money or value.
18 U.S.C. § 1030(b)
Conspiracy to Commit Computer Fraud
Punishes any person who conspires to commit or attempts to commit any computer fraud offense under section 1030.