Attackers can exfiltrate data from cloud environments by abusing legitimate cross-account sharing, backup, and replication features instead of moving files over traditional outbound channels. MITRE ATT&CK tracks this behavior as T1537 — Transfer Data to Cloud Account, describing how adversaries use provider APIs and internal cloud networking to make exfiltration resemble normal intra-cloud activity and evade controls focused on internet egress or command-and-control traffic.
Research detailing AWS tradecraft shows attackers with snapshot-related permissions can create Amazon EC2 and Amazon RDS snapshots, share them with attacker-controlled AWS accounts, and recover the underlying data without logging back into the original instance or database. Similar abuse is possible in Amazon S3, where adversaries can alter replication rules or trigger batch replication jobs to copy bucket contents into external accounts, particularly when overly permissive IAM roles are available. The activity largely occurs through cloud control-plane operations, reducing host-level forensic evidence and increasing the importance of monitoring CloudTrail, restricting IAM and KMS permissions, and encrypting sensitive resources.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A technical blog post analyzed how attackers with compromised AWS access can abuse native cross-account features in EC2, RDS, and S3 to move victim data into attacker-controlled AWS accounts with limited host-level forensic traces. The post mapped this behavior to MITRE ATT&CK technique T1537 and outlined mitigations including encryption, tighter IAM/KMS controls, and CloudTrail monitoring.
MITRE ATT&CK documented technique T1537, Transfer Data to Cloud Account, describing how adversaries can exfiltrate data within the same cloud provider by using account-to-account sharing, syncing, or backup transfer mechanisms that may evade traditional exfiltration monitoring.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.