Exfiltration over USB

T1052.001

Sub-technique of T1052 Exfiltration Over Physical Medium.View on attack.mitre.org

About this technique

Adversaries may attempt to exfiltrate data over a USB connected physical device. In certain circumstances, such as an air-gapped network compromise, exfiltration could occur via a USB device introduced by a user. The USB device could be used as the final exfiltration point or to hop between otherwise disconnected systems.

Detection rules0

Rules on DetectionCode tagged with T1052.001.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups2

Software5

Campaigns0

None recorded.

Procedure examples7

Groups2

Used byProcedure example
GroupMustang Panda

Mustang Panda has used a customized PlugX variant which could exfiltrate documents from air-gapped networks.

GroupTropic Trooper

Tropic Trooper has exfiltrated data using USB storage devices.

Software5

Used byProcedure example
MalwareAgent.btz

Agent.btz creates a file named thumb.dd on all USB flash drives connected to the victim. This file contains information about the infected system and activity logs.

MalwareMachete

Machete has a feature to copy files from every drive onto a removable drive in a hidden folder.

MalwareRemsec

Remsec contains a module to move data from airgapped networks to Internet-connected systems by using a removable USB device.

MalwareSPACESHIP

SPACESHIP copies staged data to removable drives when they are inserted into the system.

MalwareUSBStealer

USBStealer exfiltrates collected files via removable media from air-gapped victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.