ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1091×

20 examples

TechniqueUsed byProcedure example
T1091
Replication Through Removable Media
MalwareStuxnet

Stuxnet can propagate via removable media using an autorun.inf file or the CVE-2010-2568 LNK vulnerability.

T1091
Replication Through Removable Media
MalwareUrsnif

Ursnif has copied itself to and infected removable drives for propagation.

T1091
Replication Through Removable Media
MalwareCrimson

Crimson can spread across systems by infecting removable media.

T1091
Replication Through Removable Media
MalwareAgent.btz

Agent.btz drops itself onto removable media devices and creates an autorun.inf file with an instruction to run that file. When the device is inserted into another system, it opens autorun.inf and loads the malware.

T1091
Replication Through Removable Media
MalwareRaspberry Robin

Raspberry Robin has historically used infected USB media to spread to new victims.

T1091
Replication Through Removable Media
MalwareConficker

Conficker variants used the Windows AUTORUN feature to spread through USB propagation.

T1091
Replication Through Removable Media
MalwarePlugX

PlugX has copied itself to infected removable drives for propagation to other victim devices.

T1091
Replication Through Removable Media
MalwareDustySky

DustySky searches for removable media and duplicates itself onto it.

T1091
Replication Through Removable Media
MalwareUSBferry

USBferry can copy its installer to attached USB storage devices.

T1091
Replication Through Removable Media
MalwareUnknown Logger

Unknown Logger is capable of spreading to USB devices.

T1091
Replication Through Removable Media
MalwareUSBStealer

USBStealer drops itself onto removable media and relies on Autorun to execute the malicious file when a user opens the removable media on another system.

T1091
Replication Through Removable Media
MalwareSHIPSHAPE

APT30 may have used the SHIPSHAPE malware to move onto air-gapped networks. SHIPSHAPE targets removable drives to spread to other systems by modifying the drive to use Autorun to execute or by hiding legitimate document files and copying an executable to the folder with the same name as the legitimate document.

T1091
Replication Through Removable Media
MalwareRamsay

Ramsay can spread itself by infecting other portable executable files on removable drives.

T1091
Replication Through Removable Media
MalwareCHOPSTICK

Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic.

T1091
Replication Through Removable Media
MalwarenjRAT

njRAT can be configured to spread via removable drives.

T1091
Replication Through Removable Media
MalwareHIUPAN

HIUPAN has periodically checked for removable and hot-plugged drives connected to the infected machine, should one be found HIUPAN will propagate to the removeable drives by copying itself and accompanying malware components to a directory to the new drive in a hidden subdirectory `<Drive_Letter>:\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\` and hides any other existing files to ensure UsbConfig.exe is the only visible file on the device.

T1091
Replication Through Removable Media
MalwareANDROMEDA

ANDROMEDA has been spread via infected USB keys.

T1091
Replication Through Removable Media
MalwareQakBot

QakBot has the ability to use removable drives to spread through compromised networks.

T1091
Replication Through Removable Media
MalwareH1N1

H1N1 has functionality to copy itself to removable media.

T1091
Replication Through Removable Media
MalwareFlame

Flame contains modules to infect USB sticks and spread laterally to other Windows systems the stick is plugged into using Autorun functionality.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.