ATT&CKReferencesESET Sednit USBStealer 2014

ESET Sednit USBStealer 2014

Calvet, J. (2014, November 11). Sednit Espionage Group Attacking Air-Gapped Networks. Retrieved January 4, 2017.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1020
Automated Exfiltration
MalwareUSBStealer

USBStealer automatically exfiltrates collected files via removable media when an infected device connects to an air-gapped victim machine after initially being connected to an internet-enabled victim machine.

T1025
Data from Removable Media
MalwareUSBStealer

Once a removable media device is inserted back into the first victim, USBStealer collects data from it that was exfiltrated from a second victim.

T1027.013
Encrypted/Encoded File
MalwareUSBStealer

Most strings in USBStealer are encrypted using 3DES and XOR and reversed.

T1036.005
Match Legitimate Resource Name or Location
MalwareUSBStealer

USBStealer mimics a legitimate Russian program called USB Disk Security.

T1052.001
Exfiltration over USB
MalwareUSBStealer

USBStealer exfiltrates collected files via removable media from air-gapped victims.

T1070.004
File Deletion
MalwareUSBStealer

USBStealer has several commands to delete files associated with the malware from the victim.

T1070.006
Timestomp
MalwareUSBStealer

USBStealer sets the timestamps of its dropper files to the last-access and last-write timestamps of a standard Windows library chosen on the system.

T1074.001
Local Data Staging
MalwareUSBStealer

USBStealer collects files matching certain criteria from the victim and stores them in a local directory for later exfiltration.

T1083
File and Directory Discovery
MalwareUSBStealer

USBStealer searches victim drives for files matching certain extensions (“.skr”,“.pkr” or “.key”) or names.

T1091
Replication Through Removable Media
MalwareUSBStealer

USBStealer drops itself onto removable media and relies on Autorun to execute the malicious file when a user opens the removable media on another system.

T1092
Communication Through Removable Media
MalwareUSBStealer

USBStealer drops commands for a second victim onto a removable media drive inserted into the first victim, and commands are executed when the drive is inserted into the second victim.

T1119
Automated Collection
MalwareUSBStealer

For all non-removable drives on a victim, USBStealer executes automated collection of certain files for later exfiltration.

T1120
Peripheral Device Discovery
MalwareUSBStealer

USBStealer monitors victims for insertion of removable drives. When dropped onto a second victim, it also enumerates drives connected to the system.

T1547.001
Registry Run Keys / Startup Folder
MalwareUSBStealer

USBStealer registers itself under a Registry Run key with the name "USB Disk Security."

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.