USBferry

S0452

Malware.View on attack.mitre.org

About this malware

USBferry is an information stealing malware and has been used by Tropic Trooper in targeted attacks against Taiwanese and Philippine air-gapped military environments. USBferry shares an overlapping codebase with YAHOYAH, though it has several features which makes it a distinct piece of malware.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1005
Data from Local System

USBferry can collect information from an air-gapped host machine.

T1016
System Network Configuration Discovery

USBferry can detect the infected machine's network topology using ipconfig and arp.

T1018
Remote System Discovery

USBferry can use net view to gather information about remote systems.

T1049
System Network Connections Discovery

USBferry can use netstat and nbtstat to detect active network connections.

T1057
Process Discovery

USBferry can use tasklist to gather information about the process running on the infected system.

T1059.003
Windows Command Shell

USBferry can execute various Windows commands.

T1083
File and Directory Discovery

USBferry can detect the victim's file or folder list.

T1087.001
Local Account

USBferry can use net user to gather information about local accounts.

T1091
Replication Through Removable Media

USBferry can copy its installer to attached USB storage devices.

T1120
Peripheral Device Discovery

USBferry can check for connected USB devices.

T1218.011
Rundll32

USBferry can execute rundll32.exe in memory to avoid detection.

Groups that use it1

Campaigns0

None recorded.

References1

  1. TrendMicro Tropic Trooper May 2020 Open source
    Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.