Skip to content

T1039 Data from Network Shared Drive

Adversaries may search network shares on computers they have compromised to find files of interest. Sensitive data can be collected from remote systems via shared network drives (host shared directory, network file server, etc.) that are accessible from the current system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information.

Item Value
ID T1039
Tactics TA0009
Platforms Linux, Windows, macOS
Version 1.3
Created 31 May 2017
Last Modified 30 March 2023

Procedure Examples

ID Name Description
G0007 APT28 APT28 has collected files from network shared drives.6
S0128 BADNEWS When it first starts, BADNEWS crawls the victim’s mapped drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt.4
G0060 BRONZE BUTLER BRONZE BUTLER has exfiltrated files stolen from file shares.11
C0015 C0015 During C0015, the threat actors collected files from network shared drives prior to network encryption.12
G0114 Chimera Chimera has collected data of interest from network shares.7
S0050 CosmicDuke CosmicDuke steals user files from network shared drives with file extensions and keywords that match a predefined list.1
S0554 Egregor Egregor can collect any files found in the enumerated drivers before sending it to its C2 channel.2
G0117 Fox Kitten Fox Kitten has searched network shares to access sensitive documents.5
G0047 Gamaredon Group Gamaredon Group malware has collected Microsoft Office documents from mapped network drives.8
G0045 menuPass menuPass has collected data from remote systems by mounting network shares with net use and using Robocopy to transfer data.9
S0458 Ramsay Ramsay can collect data from network drives and stage it for exfiltration.3
G0054 Sowbug Sowbug extracted Word documents from a file server on a victim network.10


ID Data Source Data Component
DS0017 Command Command Execution
DS0022 File File Access
DS0033 Network Share Network Share Access
DS0029 Network Traffic Network Connection Creation