ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1120×

47 examples

TechniqueUsed byProcedure example
T1120
Peripheral Device Discovery
MalwareQuietSieve

QuietSieve can identify and search removable drives for specific file name extensions.

T1120
Peripheral Device Discovery
MalwareStuxnet

Stuxnet enumerates removable drives for infection.

T1120
Peripheral Device Discovery
MalwareSharpDisco

SharpDisco has dropped a plugin to monitor external drives to `C:\Users\Public\It3.exe`.

T1120
Peripheral Device Discovery
MalwareCrimson

Crimson has the ability to discover pluggable/removable drives to extract files from.

T1120
Peripheral Device Discovery
MalwareDynoWiper

DynoWiper has enumerated and overwritten files on all removeable and fixed drives.

T1120
Peripheral Device Discovery
MalwareTurian

Turian can scan for removable media to collect data.

T1120
Peripheral Device Discovery
MalwareMachete

Machete detects the insertion of new devices by listening for the WM_DEVICECHANGE window message.

T1120
Peripheral Device Discovery
MalwarePrikormka

A module in Prikormka collects information on available printers and disk drives.

T1120
Peripheral Device Discovery
MalwareFlawedAmmyy

FlawedAmmyy will attempt to detect if a usable smart card is current inserted into a card reader.

T1120
Peripheral Device Discovery
MalwareWastedLocker

WastedLocker can enumerate removable drives prior to the encryption process.

T1120
Peripheral Device Discovery
MalwareAcidPour

AcidPour includes functionality to identify MMC and SD cards connected to the victim device.

T1120
Peripheral Device Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can monitor for removable drives.

T1120
Peripheral Device Discovery
MalwareRagnar Locker

Ragnar Locker may attempt to connect to removable drives and mapped network drives.

T1120
Peripheral Device Discovery
MalwareBlackEnergy

BlackEnergy can gather very specific information about attached USB devices, to include device instance ID and drive geometry.

T1120
Peripheral Device Discovery
MalwareObliqueRAT

ObliqueRAT can discover pluggable/removable drives to extract files from.

T1120
Peripheral Device Discovery
MalwareDarkWatchman

DarkWatchman can list signed PnP drivers for smartcard readers.

T1120
Peripheral Device Discovery
MalwarePlugX

PlugX can identify removable media attached to compromised hosts.

T1120
Peripheral Device Discovery
MalwareDustySky

DustySky can detect connected USB devices.

T1120
Peripheral Device Discovery
MalwareMongall

Mongall can identify removable media attached to compromised hosts.

T1120
Peripheral Device Discovery
MalwareLockBit 3.0

LockBit 3.0 has the ability to discover external storage devices.

T1120
Peripheral Device Discovery
MalwareSVCReady

SVCReady can check for the number of devices plugged into an infected host.

T1120
Peripheral Device Discovery
MalwareFerocious

Ferocious can run GET.WORKSPACE in Microsoft Excel to check if a mouse is present.

T1120
Peripheral Device Discovery
MalwareUSBferry

USBferry can check for connected USB devices.

T1120
Peripheral Device Discovery
MalwareWannaCry

WannaCry contains a thread that will attempt to scan for new attached drives every few seconds. If one is identified, it will encrypt the files on the attached device.

T1120
Peripheral Device Discovery
MalwareBandook

Bandook can detect USB devices.

T1120
Peripheral Device Discovery
MalwareT9000

T9000 searches through connected drives for removable storage devices.

T1120
Peripheral Device Discovery
MalwareAttor

Attor has a plugin that collects information about inserted storage devices, modems, and phone devices.

T1120
Peripheral Device Discovery
MalwareNightClub

NightClub has the ability to monitor removable drives.

T1120
Peripheral Device Discovery
MalwareCrutch

Crutch can monitor for removable drives being plugged into the compromised machine.

T1120
Peripheral Device Discovery
MalwareRTM

RTM can obtain a list of smart card readers attached to the victim.

T1120
Peripheral Device Discovery
MalwareMoonWind

MoonWind obtains the number of removable drives from the victim.

T1120
Peripheral Device Discovery
MalwareLockBit 2.0

LockBit 2.0 has the ability to identify mounted external storage devices.

T1120
Peripheral Device Discovery
MalwareZebrocy

Zebrocy enumerates information about connected storage devices.

T1120
Peripheral Device Discovery
MalwareCadelspy

Cadelspy has the ability to steal information about printers and the documents sent to printers.

T1120
Peripheral Device Discovery
MalwareUSBStealer

USBStealer monitors victims for insertion of removable drives. When dropped onto a second victim, it also enumerates drives connected to the system.

T1120
Peripheral Device Discovery
MalwareTajMahal

TajMahal has the ability to identify connected Apple devices.

T1120
Peripheral Device Discovery
MalwareRamsay

Ramsay can scan for removable media which may contain documents for collection.

T1120
Peripheral Device Discovery
MalwareFunnyDream

The FunnyDream FilepakMonitor component can detect removable drive insertion.

T1120
Peripheral Device Discovery
MalwareROADSWEEP

ROADSWEEP can identify removable drives attached to the victim's machine.

T1120
Peripheral Device Discovery
MalwarenjRAT

njRAT will attempt to detect if the victim system has a camera during the initial infection. njRAT can also detect any removable drives connected to the system.

T1120
Peripheral Device Discovery
MalwareHIUPAN

HIUPAN has checked periodically for removable drives and installs itself when a drive is detected.

T1120
Peripheral Device Discovery
MalwareHeyoka Backdoor

Heyoka Backdoor can identify removable media attached to victim's machines.

T1120
Peripheral Device Discovery
MalwareBADNEWS

BADNEWS checks for new hard drives on the victim, such as USB devices, by listening for the WM_DEVICECHANGE window message.

T1120
Peripheral Device Discovery
MalwareQakBot

QakBot can identify peripheral devices on targeted systems.

T1120
Peripheral Device Discovery
MalwarejRAT

jRAT can map UPnP ports.

T1120
Peripheral Device Discovery
MalwareINC Ransomware

INC Ransomware can identify external USB and hard drives for encryption and printers to print ransom notes.

T1120
Peripheral Device Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can list connected devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.