MITRE ATT&CK Technique
T1020Automated Exfiltration
- First Reported
- Jul 22, 2026
- Latest Reported
- Sep 9, 2026
Official Description
Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.(Citation: ESET Gamaredon June 2020)
When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as [Exfiltration Over C2 Channel](https://attack.mitre.org/techniques/T1041) and [Exfiltration Over Alternative Protocol](https://attack.mitre.org/techniques/T1048).
When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as [Exfiltration Over C2 Channel](https://attack.mitre.org/techniques/T1041) and [Exfiltration Over Alternative Protocol](https://attack.mitre.org/techniques/T1048).
- Tactics
- Exfiltration
- Platforms
- Linux, macOS, Network Devices, Windows
- MITRE Version
- 1.3
- Last Modified
- May 12, 2026
Sub-techniques (1)
Reported Context (3)
- The extensions automatically collect and transmit data when targeted application state becomes available. Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
- Embedded extension logic automatically transmitted captured recovery phrases, keyrings, credentials, or clipboard contents. Socket Links 77 Firefox Extensions to Crypto Wallet and Credential Theft
- Workflow loops automatically uploaded new lines from collected result files, including a final collection stage. Compromised GitHub Actions Repositories Fuel cPanel/WHM Exploitation and Credential Theft
CVE (1)
Malware (3)
People (2)
MITRE ATT&CK (28)
Vendors (6)
Products (21)
Tools (2)
Industries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.