Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1025 Data from Removable Media |
MalwareGravityRAT | GravityRAT steals files based on an extension list if a USB drive is connected to the system. |
| T1025 Data from Removable Media |
MalwareAppleSeed | AppleSeed can find and collect data from removable media devices. |
| T1025 Data from Removable Media |
MalwareCosmicDuke | CosmicDuke steals user files from removable media with file extensions and keywords that match a predefined list. |
| T1025 Data from Removable Media |
MalwareAria-body | Aria-body has the ability to collect data from USB devices. |
| T1025 Data from Removable Media |
MalwareCrimson | Crimson contains a module to collect data from removable drives. |
| T1025 Data from Removable Media |
MalwareMachete | Machete can find, encrypt, and upload files from fixed and removable drives. |
| T1025 Data from Removable Media |
MalwarePrikormka | Prikormka contains a module that collects documents with certain extensions from removable media or fixed drives connected via USB. |
| T1025 Data from Removable Media |
MalwareFLASHFLOOD | FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on removable media and copies them to a staging area. The default file types copied would include data copied to the drive by SPACESHIP. |
| T1025 Data from Removable Media |
MalwareInvisiMole | InvisiMole can collect jpeg files from connected MTP devices. |
| T1025 Data from Removable Media |
MalwareObliqueRAT | ObliqueRAT has the ability to extract data from removable devices connected to the endpoint. |
| T1025 Data from Removable Media |
MalwareRemsec | Remsec has a package that collects documents from any inserted USB sticks. |
| T1025 Data from Removable Media |
MalwareExplosive | Explosive can scan all .exe files located in the USB drive. |
| T1025 Data from Removable Media |
MalwareRover | Rover searches for files on attached removable drives based on a predefined list of file extensions every five seconds. |
| T1025 Data from Removable Media |
MalwareCrutch | Crutch can monitor removable drives and exfiltrate files matching a given extension list. |
| T1025 Data from Removable Media |
MalwareMgBot | MgBot includes modules capable of gathering information from USB thumb drives and CD-ROMs on the victim machine given a list of provided criteria. |
| T1025 Data from Removable Media |
MalwareUSBStealer | Once a removable media device is inserted back into the first victim, USBStealer collects data from it that was exfiltrated from a second victim. |
| T1025 Data from Removable Media |
MalwareTajMahal | TajMahal has the ability to steal written CD images and files of interest from previously connected removable drives when they become available again. |
| T1025 Data from Removable Media |
MalwareRamsay | Ramsay can collect data from removable media and stage it for exfiltration. |
| T1025 Data from Removable Media |
MalwareFunnyDream | The FunnyDream FilePakMonitor component has the ability to collect files from removable devices. |
| T1025 Data from Removable Media |
MalwareBADNEWS | BADNEWS copies files with certain extensions from USB devices to |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.