Rclone — Malware Profile
Rclone is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. Rclone has been used in a number of ransomware campaigns, including those associated with the Conti and DarkSide Ransomware-as-a-Service operations.
MITRE ATT&CK techniques (6)
- T1030 Data Transfer Size Limits
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
- T1083 File and Directory Discovery
- T1560.001 Archive via Utility
- T1567.002 Exfiltration to Cloud Storage
IntelFusions coverage
- CISA, FBI, and NSA Joint Advisory: Conti Ransomware Surpasses 1,000 Attacks with TrickBot, Cobalt Strike, and Double Extortion 2026-02-16
- CISA #StopRansomware: Hive Ransomware Claims 1,300+ Victims and $100M in Payments Targeting Healthcare and Critical Infrastructure 2026-02-16
- Spectral Flux (NightSpire): Threat Actor Profile and Technical Analysis 2026-03-07
- NightSpire Kill Chain: How a FortiOS Zero-Day Became Ransomware's Favorite Front Door 2026-02-01
- Phishing now starts most intrusions as attackers beat MFA 2026-07-29
Attributed threat actors
- MuddyWater
- Scattered Spider
- WIRTE
- Storm-0501
- INC Ransom
- Ember Bear
- Medusa Ransomware
- AvosLocker machine-inferred link
- DarkSide machine-inferred link
- Royal machine-inferred link
- BlackSuit machine-inferred link
- Silent Ransom Group machine-inferred link
- Anubis machine-inferred link
- BravoX machine-inferred link
- FulcrumSec machine-inferred link
- PEAR Team machine-inferred link
- Cactus machine-inferred link
- Sinobi machine-inferred link
- ALPHV/BlackCat machine-inferred link
- Vice Society machine-inferred link
- NightSpire machine-inferred link
- Kairos machine-inferred link
- 8Base machine-inferred link
- BianLian machine-inferred link
- Karakurt machine-inferred link
- Trigona machine-inferred link
- LockBit machine-inferred link
- Hive machine-inferred link
- Head Mare machine-inferred link
- Akira
- Cinnamon Tempest