DETECTION OVERVIEW
Risk Factors
Any file uploaded by an Rclone client to the MEGA cloud storage service should be investigated. Ransomware malware and threat groups have been known to exfiltrate data with Rclone to MEGA. The impact of this activity on a business can be devastating, especially if sensitive or business-critical files are stolen or if a high ransom is paid.
Kill Chain
Risk Score
88
Ransomware is a type of malicious software, or malware, that can encrypt and exfiltrate files. Attackers later demand a ransom to recover or prevent the release of sensitive data. Ransomware variants such as Conti have been known to upload stolen files to the MEGA, a cloud storage service with a historical association with malware. The ransomware takes advantage of open-source file management tools such as Rclone to upload stolen files to MEGA. Advanced persistent threat (APT) groups, such as Karakurt, have also been known to upload files with Rclone to MEGA.
Investigate file uploads to unusual cloud storage services such as MEGA