Replication Through Removable Media

T1091

Technique.View on attack.mitre.org

About this technique

Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and executes. In the case of Lateral Movement, this may occur through modification of executable files stored on removable media or by copying malware and renaming it to look like a legitimate file to trick users into executing it on a separate system. In the case of Initial Access, this may occur through manual manipulation of the media, modification of systems used to initially format the media, or modification to the media's firmware itself.

Mobile devices may also be used to infect PCs with malware if connected via USB. This infection may be achieved using devices (Android, iOS, etc.) and, in some instances, USB charging cables. For example, when a smartphone is connected to a system, it may appear to be mounted similar to a USB-connected disk drive. If malware that is compatible with the connected system is on the mobile device, the malware could infect the machine (especially if Autorun features are enabled).

Detection rules5

Rules on DetectionCode tagged with T1091.

Sigma1

Splunk4

RuleTypeRiskData source
Windows Process Executed From Removable MediaAnomalyNULLSysmon EventID 1 AND Sysmon EventID 13
Windows Replication Through Removable MediaTTPNULLSysmon EventID 11
Windows USBSTOR Registry Key ModificationAnomalyNULLSysmon EventID 12, Sysmon EventID 13
Windows WPDBusEnum Registry Key ModificationAnomalyNULLSysmon EventID 12, Sysmon EventID 13

Groups8

Software20

Campaigns0

None recorded.

Procedure examples28

Groups8

Used byProcedure example
GroupAoqin Dragon

Aoqin Dragon has used a dropper that employs a worm infection strategy using a removable device to breach a secure network environment.

GroupAPT28

APT28 uses a tool to infect connected USB devices and transmit itself to air-gapped computers when the infected USB device is inserted.

GroupDarkhotel

Darkhotel's selective infector modifies executables stored on removable media as a method of spreading across computers.

GroupFIN7

FIN7 actors have mailed USB drives to potential victims containing malware that downloads and installs various backdoors, including in some cases for ransomware operations. Additionally, FIN7 has used malicious USBs that acted as virtual keyboards to install malware and txt files that decode to PowerShell commands.

GroupGamaredon Group

Gamaredon Group has replicated to removable media by leveraging the User Assist Reg Key and creating LNKs on all network and removable drives available on the infected host.

GroupLuminousMoth

LuminousMoth has used malicious DLLs to spread malware to connected removable USB drives on infected machines.

GroupMustang Panda

Mustang Panda has used a customized PlugX variant which could spread through USB connections.

GroupTropic Trooper

Tropic Trooper has attempted to transfer USBferry from an infected USB device by copying an Autorun function to the target machine.

Software20

Used byProcedure example
MalwareAgent.btz

Agent.btz drops itself onto removable media devices and creates an autorun.inf file with an instruction to run that file. When the device is inserted into another system, it opens autorun.inf and loads the malware.

MalwareANDROMEDA

ANDROMEDA has been spread via infected USB keys.

MalwareCHOPSTICK

Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic.

MalwareConficker

Conficker variants used the Windows AUTORUN feature to spread through USB propagation.

MalwareCrimson

Crimson can spread across systems by infecting removable media.

MalwareDustySky

DustySky searches for removable media and duplicates itself onto it.

MalwareFlame

Flame contains modules to infect USB sticks and spread laterally to other Windows systems the stick is plugged into using Autorun functionality.

MalwareH1N1

H1N1 has functionality to copy itself to removable media.

View all 20 software examples

References3

  1. Exploiting Smartphone USB Open source
    Zhaohui Wang & Angelos Stavrou. (n.d.). Exploiting Smart-Phone USB Connectivity For Fun And Profit. Retrieved May 25, 2022.
  2. Windows Malware Infecting Android Open source
    Lucian Constantin. (2014, January 23). Windows malware tries to infect Android devices connected to PCs. Retrieved May 25, 2022.
  3. iPhone Charging Cable Hack Open source
    Zack Whittaker. (2019, August 12). This hacker’s iPhone charging cable can hijack your computer. Retrieved May 25, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.