Rclone

MITRE ATT&CK: S1040 View on attack.mitre.org

Aliases: Rclone

Malware type
ransomware, downloader
Operating systems
linux, windows, macos
Profile updated
2026-07-07 13:47:15

Targeted industries: energy-and-utilities financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing technology-and-telecommunications

Context

Rclone is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. Rclone has been used in a number of ransomware campaigns, including those associated with the Conti and DarkSide Ransomware-as-a-Service operations.

Detection coverage

  • 58 Sigma rules

Malware & tools used

  • Exfiltration to Cloud Storage (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Data Transfer Size Limits (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Exfiltration Over Asymmetric Encrypted Non-C2 Protocol (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)

Used by threat actors

Reports & references

  • Palo Alto Unit 42 — Darkside Ransomware (report)
  • thedfirreport.com — Continuing The Bazar Ransomware Story (report)
  • MITRE ATT&CK — S1040 (report)
  • rclone.org (report)
  • redcanary.com — Rclone Mega Extortion (report)
  • research.nccgroup.com — Detecting Rclone An Effective Tool For Exfiltration (report)

External references