
In the third article of his three-part series, Adrian Bishop at Huntsman Security explains how attackers steal sensitive data and the steps that organisations can take to defend themselves
In this three-part series analysing a hypothetical cyber-attack, we have already seen how attackers gather information about a network, including credentials and accounts and then establish a persistent presence.
Now we will investigate how attackers gather and exfiltrate sensitive data whilst preventing recovery – and the last steps that organisations can take to defend themselves.
After compromising all the required hosts on a network, the attacker will collect as much data as possible and prepare it to be transferred to another location.
To do so, they may install a script or utilities on to compromised hosts to scan local and network filesystems for important information and documents. Any files discovered are compressed, encrypted, and added to archive files on the local system.
The archive files are then moved to a single staging server and stored in locations such as the Recycle Bin to reduce the chance of discovery.
Within the Collection Tactic are Techniques that enable data collection from different sources and prepare it for exfiltration, including:
Our attack scenario uses multiple Techniques to find and prepare data for exfiltration, including:
To gain full access to a compromised system, attackers need to establish a reliable communications channel, through which to directly execute their commands. This allows them to run commands, perform unscripted activities and control systems easier than with automated scripts and utilities.
In our case, the attacker ensures that periodically, each compromised system attempts to communicate with an external command and control (C2) server using either an HTTP GET request containing a custom HTTP Cookie, or on TCP port 1913 using the SOCKS5 protocol.
The C2 server collects basic host information and provides access to utilities and a remote access tool (RAT) which are automatically downloaded and installed. Once the RAT is installed a connection to a second command and control server is made using TCP port 81, which is then used by the attacker to interact with the system via a reverse shell.
The Techniques to enable this capability are within the Command and Control Tactic and include:
The Techniques used within our attack scenario to evade detection are:
The attacker uses command line access to the staging server to setup automated transfers of the encrypted archive files using two methods:
The exfiltration of large amounts of data can be relatively easy to spot compared with other activities performed up to this point. Attackers may therefore wait until they have gathered significant information before performing this stage. Exfiltration Techniques include:
The exfiltration of data within our attack scenario uses the following Techniques:
After an attacker has exfiltrated data from the compromised hosts, they may attempt to delete or encrypt the original versions and any backups.
This is achieved by using the C2 server to download a utility to all compromised hosts which securely deletes all the collected documents and archive files. This will ensure that any demands for payment for copies of the files will not be rejected as the attacker now has sole possession of them.
The Techniques within the Impact Tactic are designed to cause damage to data and systems and include:
In the final stage of our attack scenario the attacker used the following Technique:
MITRE ATT&CK outlines a number of tactics that organisations should undertake to defend against this kind of attack. Specifically:
A number of monitoring and detection activities are also recommended including:
As this series of articles highlights, just a single attack can employ tens of different attack techniques, each of which organisations need to defend themselves against in order to ward off an attack.
However, this one attack is just the tip of the iceberg. There are countless other techniques and tactics that attackers can use to compromise a system. This is what makes cyber-security so challenging and why MITRE ATT&CK is such a valuable, if overwhelming resource.
To have a chance of keeping systems secure, it’s vital that organisations follow cyber-security best practice, whether that’s patching systems, monitoring their entire network or strictly controlling who they give access to. Even then, there are no guarantees that you’ll not fall victim to a breach.
MITRE ATT&CK provides a useful framework and best practice that can help organisations ward off attacks, but it’s still essential to ensure the basics are covered – as without doing so, the likelihood of being the next organisation in the headlines is very high.
Adrian Bishop is Head of Engineering at Huntsman Security
Main image courtesy of iStockPhoto.com
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543