Calvet, J. (2014, November 11). Sednit Espionage Group Attacking Air-Gapped Networks. Retrieved January 4, 2017.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1020 Automated Exfiltration |
MalwareUSBStealer | USBStealer automatically exfiltrates collected files via removable media when an infected device connects to an air-gapped victim machine after initially being connected to an internet-enabled victim machine. |
| T1025 Data from Removable Media |
MalwareUSBStealer | Once a removable media device is inserted back into the first victim, USBStealer collects data from it that was exfiltrated from a second victim. |
| T1027.013 Encrypted/Encoded File |
MalwareUSBStealer | Most strings in USBStealer are encrypted using 3DES and XOR and reversed. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareUSBStealer | USBStealer mimics a legitimate Russian program called USB Disk Security. |
| T1052.001 Exfiltration over USB |
MalwareUSBStealer | USBStealer exfiltrates collected files via removable media from air-gapped victims. |
| T1070.004 File Deletion |
MalwareUSBStealer | USBStealer has several commands to delete files associated with the malware from the victim. |
| T1070.006 Timestomp |
MalwareUSBStealer | USBStealer sets the timestamps of its dropper files to the last-access and last-write timestamps of a standard Windows library chosen on the system. |
| T1074.001 Local Data Staging |
MalwareUSBStealer | USBStealer collects files matching certain criteria from the victim and stores them in a local directory for later exfiltration. |
| T1083 File and Directory Discovery |
MalwareUSBStealer | USBStealer searches victim drives for files matching certain extensions (“.skr”,“.pkr” or “.key”) or names. |
| T1091 Replication Through Removable Media |
MalwareUSBStealer | USBStealer drops itself onto removable media and relies on Autorun to execute the malicious file when a user opens the removable media on another system. |
| T1092 Communication Through Removable Media |
MalwareUSBStealer | USBStealer drops commands for a second victim onto a removable media drive inserted into the first victim, and commands are executed when the drive is inserted into the second victim. |
| T1119 Automated Collection |
MalwareUSBStealer | For all non-removable drives on a victim, USBStealer executes automated collection of certain files for later exfiltration. |
| T1120 Peripheral Device Discovery |
MalwareUSBStealer | USBStealer monitors victims for insertion of removable drives. When dropped onto a second victim, it also enumerates drives connected to the system. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareUSBStealer | USBStealer registers itself under a Registry Run key with the name "USB Disk Security." |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.