Sub-technique of T1052 Exfiltration Over Physical Medium.View on attack.mitre.org
Adversaries may attempt to exfiltrate data over a USB connected physical device. In certain circumstances, such as an air-gapped network compromise, exfiltration could occur via a USB device introduced by a user. The USB device could be used as the final exfiltration point or to hop between otherwise disconnected systems.
Rules on DetectionCode tagged with T1052.001.
None recorded.
| Used by | Procedure example |
|---|---|
| GroupMustang Panda | Mustang Panda has used a customized PlugX variant which could exfiltrate documents from air-gapped networks. |
| GroupTropic Trooper | Tropic Trooper has exfiltrated data using USB storage devices. |
| Used by | Procedure example |
|---|---|
| MalwareAgent.btz | Agent.btz creates a file named thumb.dd on all USB flash drives connected to the victim. This file contains information about the infected system and activity logs. |
| MalwareMachete | Machete has a feature to copy files from every drive onto a removable drive in a hidden folder. |
| MalwareRemsec | Remsec contains a module to move data from airgapped networks to Internet-connected systems by using a removable USB device. |
| MalwareSPACESHIP | SPACESHIP copies staged data to removable drives when they are inserted into the system. |
| MalwareUSBStealer | USBStealer exfiltrates collected files via removable media from air-gapped victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.