SPACESHIP

S0035

Malware.View on attack.mitre.org

About this malware

SPACESHIP is malware developed by APT30 that allows propagation and exfiltration of data over removable devices. APT30 may use this capability to exfiltrate data across air-gaps.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1052.001
Exfiltration over USB

SPACESHIP copies staged data to removable drives when they are inserted into the system.

T1074.001
Local Data Staging

SPACESHIP identifies files with certain extensions and copies them to a directory in the user's profile.

T1083
File and Directory Discovery

SPACESHIP identifies files and directories for collection by searching for specific file extensions or file modification time.

T1547.001
Registry Run Keys / Startup Folder

SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder.

T1547.009
Shortcut Modification

SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder.

T1560.003
Archive via Custom Method

Data SPACESHIP copies to the staging area is compressed with zlib. Bytes are rotated by four positions and XOR'ed with 0x23.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT30 Open source
    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.