EN
ENNA
RC

Rclone

Featured

⚖️ Dual Use · Go

Rclone is a command-line program to manage files on cloud storage. It supports over 70 cloud storage providers including S3, Google Drive, Dropbox, OneDrive, Azure Blob, and more. While it's a legitimate and extremely useful sysadmin tool, it's frequently observed in ransomware operations and data theft incidents for large-scale exfiltration to attacker-controlled cloud storage. DFIR teams track rclone usage as a key indicator of compromise.

Installation

$ brew install rclone

Use Cases

  • Cloud storage management and synchronization
  • Backup automation to multiple cloud providers
  • Data migration between cloud services
  • Known exfiltration tool in ransomware operations
  • Mounting cloud storage as local filesystem

Tags

cloud-storagesyncexfiltrations3ransomware-adjacent

More in Dual Use