Restic Backup Tool Exfiltration to Cloud Object Storage

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-28
Updated
2026-09-28

ATT&CK techniques

Collection → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Impact

What it detects

This rule detects the restic backup utility or its environment variables being used together with a cloud object storage endpoint such as Backblaze B2 or Wasabi. Huntress observed operators abusing restic, sometimes renamed to dns.exe, to back up and exfiltrate victim data to attacker-controlled buckets. Pairing backup tooling with third-party object storage destinations indicates data theft rather than sanctioned backup.

Related detections9 linkedT1567.002 — drag to rearrange
Malicious Data Exfiltration via Backblaze B2 CLI
Malicious Data Exfiltration via Restic Remote Backup
Malicious Data Exfiltration to MEGA via Rclone
Suspicious Rclone Data Exfiltration with Include Filter
Suspicious Rclone Data Exfiltration to Mega Cloud Storage (via process_creation)
Suspicious CloudScout hxkz_zip Exfiltration Archive Creation via File System
Possible Gamaredon Dead-Drop C2 via Telegraph and GoFile Web Services
Suspicious Data Exfiltration via Rclone Remote Copy
Suspicious Data Exfiltration via rclone
Restic Backup Tool Exfiltration to Cloud Object Storage
Pivot detection · T1567.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.