Rclone
MITRE ATT&CK: S1040 View on attack.mitre.org
Aliases: Rclone
- Malware type
- ransomware, downloader
- Operating systems
- linux, windows, macos
- Profile updated
- 2026-07-07 13:47:15
Targeted industries: energy-and-utilities financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing technology-and-telecommunications
Context
Rclone is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. Rclone has been used in a number of ransomware campaigns, including those associated with the Conti and DarkSide Ransomware-as-a-Service operations.
Detection coverage
- 58 Sigma rules
Malware & tools used
- Exfiltration to Cloud Storage (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Data Transfer Size Limits (attack-pattern)
- Archive via Utility (attack-pattern)
- Exfiltration Over Asymmetric Encrypted Non-C2 Protocol (attack-pattern)
- Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
Used by threat actors
- C0015 (campaign)
- Ember Bear (threat-actor)
- Cinnamon Tempest (threat-actor)
- Medusa Group (threat-actor)
- Scattered Spider (threat-actor)
- INC Ransom (threat-actor)
- Storm-0501 (threat-actor)
- WIRTE (threat-actor)
- MuddyWater (threat-actor)
- Akira (threat-actor)
Reports & references
- Palo Alto Unit 42 — Darkside Ransomware (report)
- thedfirreport.com — Continuing The Bazar Ransomware Story (report)
- MITRE ATT&CK — S1040 (report)
- rclone.org (report)
- redcanary.com — Rclone Mega Extortion (report)
- research.nccgroup.com — Detecting Rclone An Effective Tool For Exfiltration (report)