Real-world descriptions of how a group, tool or campaign used a technique.
47 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1120 Peripheral Device Discovery |
MalwareQuietSieve | QuietSieve can identify and search removable drives for specific file name extensions. |
| T1120 Peripheral Device Discovery |
MalwareStuxnet | Stuxnet enumerates removable drives for infection. |
| T1120 Peripheral Device Discovery |
MalwareSharpDisco | SharpDisco has dropped a plugin to monitor external drives to `C:\Users\Public\It3.exe`. |
| T1120 Peripheral Device Discovery |
MalwareCrimson | Crimson has the ability to discover pluggable/removable drives to extract files from. |
| T1120 Peripheral Device Discovery |
MalwareDynoWiper | DynoWiper has enumerated and overwritten files on all removeable and fixed drives. |
| T1120 Peripheral Device Discovery |
MalwareTurian | Turian can scan for removable media to collect data. |
| T1120 Peripheral Device Discovery |
MalwareMachete | Machete detects the insertion of new devices by listening for the WM_DEVICECHANGE window message. |
| T1120 Peripheral Device Discovery |
MalwarePrikormka | A module in Prikormka collects information on available printers and disk drives. |
| T1120 Peripheral Device Discovery |
MalwareFlawedAmmyy | FlawedAmmyy will attempt to detect if a usable smart card is current inserted into a card reader. |
| T1120 Peripheral Device Discovery |
MalwareWastedLocker | WastedLocker can enumerate removable drives prior to the encryption process. |
| T1120 Peripheral Device Discovery |
MalwareAcidPour | AcidPour includes functionality to identify MMC and SD cards connected to the victim device. |
| T1120 Peripheral Device Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can monitor for removable drives. |
| T1120 Peripheral Device Discovery |
MalwareRagnar Locker | Ragnar Locker may attempt to connect to removable drives and mapped network drives. |
| T1120 Peripheral Device Discovery |
MalwareBlackEnergy | BlackEnergy can gather very specific information about attached USB devices, to include device instance ID and drive geometry. |
| T1120 Peripheral Device Discovery |
MalwareObliqueRAT | ObliqueRAT can discover pluggable/removable drives to extract files from. |
| T1120 Peripheral Device Discovery |
MalwareDarkWatchman | DarkWatchman can list signed PnP drivers for smartcard readers. |
| T1120 Peripheral Device Discovery |
MalwarePlugX | PlugX can identify removable media attached to compromised hosts. |
| T1120 Peripheral Device Discovery |
MalwareDustySky | DustySky can detect connected USB devices. |
| T1120 Peripheral Device Discovery |
MalwareMongall | Mongall can identify removable media attached to compromised hosts. |
| T1120 Peripheral Device Discovery |
MalwareLockBit 3.0 | LockBit 3.0 has the ability to discover external storage devices. |
| T1120 Peripheral Device Discovery |
MalwareSVCReady | SVCReady can check for the number of devices plugged into an infected host. |
| T1120 Peripheral Device Discovery |
MalwareFerocious | Ferocious can run |
| T1120 Peripheral Device Discovery |
MalwareUSBferry | USBferry can check for connected USB devices. |
| T1120 Peripheral Device Discovery |
MalwareWannaCry | WannaCry contains a thread that will attempt to scan for new attached drives every few seconds. If one is identified, it will encrypt the files on the attached device. |
| T1120 Peripheral Device Discovery |
MalwareBandook | Bandook can detect USB devices. |
| T1120 Peripheral Device Discovery |
MalwareT9000 | T9000 searches through connected drives for removable storage devices. |
| T1120 Peripheral Device Discovery |
MalwareAttor | Attor has a plugin that collects information about inserted storage devices, modems, and phone devices. |
| T1120 Peripheral Device Discovery |
MalwareNightClub | NightClub has the ability to monitor removable drives. |
| T1120 Peripheral Device Discovery |
MalwareCrutch | Crutch can monitor for removable drives being plugged into the compromised machine. |
| T1120 Peripheral Device Discovery |
MalwareRTM | RTM can obtain a list of smart card readers attached to the victim. |
| T1120 Peripheral Device Discovery |
MalwareMoonWind | MoonWind obtains the number of removable drives from the victim. |
| T1120 Peripheral Device Discovery |
MalwareLockBit 2.0 | LockBit 2.0 has the ability to identify mounted external storage devices. |
| T1120 Peripheral Device Discovery |
MalwareZebrocy | Zebrocy enumerates information about connected storage devices. |
| T1120 Peripheral Device Discovery |
MalwareCadelspy | Cadelspy has the ability to steal information about printers and the documents sent to printers. |
| T1120 Peripheral Device Discovery |
MalwareUSBStealer | USBStealer monitors victims for insertion of removable drives. When dropped onto a second victim, it also enumerates drives connected to the system. |
| T1120 Peripheral Device Discovery |
MalwareTajMahal | TajMahal has the ability to identify connected Apple devices. |
| T1120 Peripheral Device Discovery |
MalwareRamsay | Ramsay can scan for removable media which may contain documents for collection. |
| T1120 Peripheral Device Discovery |
MalwareFunnyDream | The FunnyDream FilepakMonitor component can detect removable drive insertion. |
| T1120 Peripheral Device Discovery |
MalwareROADSWEEP | ROADSWEEP can identify removable drives attached to the victim's machine. |
| T1120 Peripheral Device Discovery |
MalwarenjRAT | njRAT will attempt to detect if the victim system has a camera during the initial infection. njRAT can also detect any removable drives connected to the system. |
| T1120 Peripheral Device Discovery |
MalwareHIUPAN | HIUPAN has checked periodically for removable drives and installs itself when a drive is detected. |
| T1120 Peripheral Device Discovery |
MalwareHeyoka Backdoor | Heyoka Backdoor can identify removable media attached to victim's machines. |
| T1120 Peripheral Device Discovery |
MalwareBADNEWS | BADNEWS checks for new hard drives on the victim, such as USB devices, by listening for the WM_DEVICECHANGE window message. |
| T1120 Peripheral Device Discovery |
MalwareQakBot | QakBot can identify peripheral devices on targeted systems. |
| T1120 Peripheral Device Discovery |
MalwarejRAT | jRAT can map UPnP ports. |
| T1120 Peripheral Device Discovery |
MalwareINC Ransomware | INC Ransomware can identify external USB and hard drives for encryption and printers to print ransom notes. |
| T1120 Peripheral Device Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can list connected devices. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.