Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1091 Replication Through Removable Media |
MalwareStuxnet | Stuxnet can propagate via removable media using an autorun.inf file or the CVE-2010-2568 LNK vulnerability. |
| T1091 Replication Through Removable Media |
MalwareUrsnif | Ursnif has copied itself to and infected removable drives for propagation. |
| T1091 Replication Through Removable Media |
MalwareCrimson | Crimson can spread across systems by infecting removable media. |
| T1091 Replication Through Removable Media |
MalwareAgent.btz | Agent.btz drops itself onto removable media devices and creates an autorun.inf file with an instruction to run that file. When the device is inserted into another system, it opens autorun.inf and loads the malware. |
| T1091 Replication Through Removable Media |
MalwareRaspberry Robin | Raspberry Robin has historically used infected USB media to spread to new victims. |
| T1091 Replication Through Removable Media |
MalwareConficker | Conficker variants used the Windows AUTORUN feature to spread through USB propagation. |
| T1091 Replication Through Removable Media |
MalwarePlugX | PlugX has copied itself to infected removable drives for propagation to other victim devices. |
| T1091 Replication Through Removable Media |
MalwareDustySky | DustySky searches for removable media and duplicates itself onto it. |
| T1091 Replication Through Removable Media |
MalwareUSBferry | USBferry can copy its installer to attached USB storage devices. |
| T1091 Replication Through Removable Media |
MalwareUnknown Logger | Unknown Logger is capable of spreading to USB devices. |
| T1091 Replication Through Removable Media |
MalwareUSBStealer | USBStealer drops itself onto removable media and relies on Autorun to execute the malicious file when a user opens the removable media on another system. |
| T1091 Replication Through Removable Media |
MalwareSHIPSHAPE | APT30 may have used the SHIPSHAPE malware to move onto air-gapped networks. SHIPSHAPE targets removable drives to spread to other systems by modifying the drive to use Autorun to execute or by hiding legitimate document files and copying an executable to the folder with the same name as the legitimate document. |
| T1091 Replication Through Removable Media |
MalwareRamsay | Ramsay can spread itself by infecting other portable executable files on removable drives. |
| T1091 Replication Through Removable Media |
MalwareCHOPSTICK | Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic. |
| T1091 Replication Through Removable Media |
MalwarenjRAT | njRAT can be configured to spread via removable drives. |
| T1091 Replication Through Removable Media |
MalwareHIUPAN | HIUPAN has periodically checked for removable and hot-plugged drives connected to the infected machine, should one be found HIUPAN will propagate to the removeable drives by copying itself and accompanying malware components to a directory to the new drive in a hidden subdirectory `<Drive_Letter>:\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\` and hides any other existing files to ensure UsbConfig.exe is the only visible file on the device. |
| T1091 Replication Through Removable Media |
MalwareANDROMEDA | ANDROMEDA has been spread via infected USB keys. |
| T1091 Replication Through Removable Media |
MalwareQakBot | QakBot has the ability to use removable drives to spread through compromised networks. |
| T1091 Replication Through Removable Media |
MalwareH1N1 | H1N1 has functionality to copy itself to removable media. |
| T1091 Replication Through Removable Media |
MalwareFlame | Flame contains modules to infect USB sticks and spread laterally to other Windows systems the stick is plugged into using Autorun functionality. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.