S3Siphon is a data-theft utility used in post-compromise operations to collect files from Windows user directories and exfiltrate them to attacker-controlled Amazon S3 storage over HTTPS. It has been observed alongside other tooling including GoGRPC, BlindDoor, RevSocket, PyGRPC, and RSOX in campaigns attributed to a likely initial access broker supporting ransomware operations. Those intrusions relied on social engineering, including spam bombing, Microsoft Teams impersonation, and Quick Assist remote sessions, after which the operator deployed follow-on malware for persistence, reconnaissance, tunneling, and exfiltration.
S3Siphon iterates through common user data locations such as Desktop, Documents, Downloads, OneDrive, Pictures, Videos, and Music, then uploads selected files using HTTPS PUT requests. Its behavior indicates deliberate collection of user-accessible business data rather than indiscriminate disk theft. Reported filtering includes exclusion of files larger than 100 MB, omission of various temporary, log, shortcut, executable, driver, and library file types, and avoidance of numerous Windows cache and system paths. This design suggests an emphasis on efficient theft of potentially valuable documents while reducing noise, transfer volume, and operational friction.
The malware is associated with targeted enterprise intrusions on Windows systems and functions as an exfiltration component within a broader access-and-staging toolkit. Its role in these operations is consistent with preparation for downstream extortion or ransomware activity by enabling selective theft of victim data after initial access and reconnaissance have already been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data exfiltration tool that uploads files to an AWS S3 bucket, targeting common user directories and filtering out files larger than 100 MB.
A tool used in the same operation and associated with data theft capability.
Additional malware used in the same campaigns alongside GoGRPC.
A file-exfiltration utility that searches user directories such as Desktop, Documents, Downloads, OneDrive, and Pictures, filters files by size and extension/path exclusions, and uploads stolen data to an AWS S3 bucket for likely later extortion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.