WinSCP is a legitimate Windows file transfer utility (Windows Secure Copy) that supports SCP/SFTP and is repeatedly described in the content as being abused by threat actors for data exfiltration rather than as malware in its own right. The content links WinSCP to multiple intrusion sets and ransomware/extortion operations, including Akira affiliates, Phobos/8Base actors, DPRK RGB 3rd Bureau / Andariel (Onyx Sleet), and the Silent Ransom Group (Luna Moth/Chatty Spider/UNC3753). Reported use cases include exfiltration to external SFTP servers, FTP and other protocol-based transfers to actor-controlled infrastructure, and use alongside tools such as PuTTY, Rclone, FileZilla, WinRAR, Cloudflared, and Impacket. In Akira-related intrusions, actors used WinSCP to exfiltrate data to two external SFTP servers after staging archives with WinRAR, and WinSCP.exe was also listed as a tool IOC in SonicWall SSL VPN-related Akira activity. Additional reporting cited WinSCP/FileZilla as alternative exfiltration tooling in Akira and Fog intrusions. Phobos actors were specifically observed using WinSCP and Mega.io for file exfiltration. The Andariel advisory states the group has used PuTTY and WinSCP to exfiltrate data to North Korea-controlled servers via FTP and other protocols. The FBI reporting on Silent Ransom Group states the actors commonly exfiltrate stolen data using WinSCP or a hidden/renamed version of Rclone after gaining access through callback phishing and social engineering. High-confidence behavioral context in the content therefore characterizes WinSCP as dual-use software frequently leveraged for exfiltration over non-C2 protocols, especially SCP/SFTP over port 22, across ransomware, extortion, and espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...data exfiltration conducted through 'WinSCP' (Windows Secure Copy) or a hidden or renamed version of 'Rclone.'"
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Plusieurs outils découverts sur le système d’information compromis ont pu permettre à l’attaquant de maintenir ses accès sur certaines machines ou d’exfiltrer des données, comme le client SSH Putty ou le client FTP WinSCP [T1021].
The cyber actors then exfiltrate files from the victim’s network, sometimes using the free open-source tool WinSCP
WinSCP executed with command-line arguments indicating scripted file transfer - commonly used by ransomware operators for data exfiltration via SFTP/FTP/SCP.
Data exfiltration was likely carried out through WinSCP , a legitimate file transfer tool commonly abused by threat actors for its reliability and encryption capabilities.
After creating archives containing collected files, affiliates used different softwares to exfiltrate several gigabytes of data: WinSCP and FileZilla.
an unmonitored Windows server began initiating FTP connections to an external IP address, sending over 100GB of data
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WinSCP was used by Akira affiliates for SFTP-based data exfiltration and also appeared in comparative tooling differences across intrusions.
Legitimate SCP/SFTP client used to attempt data exfiltration over SSH (port 22) during the campaign.
Legitimate Windows SCP/SFTP client abused by the threat actors for data exfiltration from compromised environments.
Legitimate file transfer client abused for data exfiltration in support of extortion operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.