Skip to content

Hide Navigation Hide TOC

Credential Exfiltration via Fake Backup Verification - ATR-2026-00214 (f2656b8d-ad39-512c-b6e0-d94da8faebd4)

Detects malicious tools that exfiltrate sensitive credentials (SSH keys, AWS credentials, npm tokens) by disguising the theft as legitimate "backup verification" or "integrity checks". The attack pattern concatenates multiple credential files, encodes them, and transmits to external servers.

Cluster A Galaxy A Cluster B Galaxy B Level
ML Supply Chain Compromise (d2cf31e0-a550-4fe0-8fdb-8941b3ac00d9) MITRE ATLAS Attack Pattern Credential Exfiltration via Fake Backup Verification - ATR-2026-00214 (f2656b8d-ad39-512c-b6e0-d94da8faebd4) Agent Threat Rules 1