SHIPSHAPE

S0028

Malware.View on attack.mitre.org

About this malware

SHIPSHAPE is malware developed by APT30 that allows propagation and exfiltration of data over removable devices. APT30 may use this capability to exfiltrate data across air-gaps.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1091
Replication Through Removable Media

APT30 may have used the SHIPSHAPE malware to move onto air-gapped networks. SHIPSHAPE targets removable drives to spread to other systems by modifying the drive to use Autorun to execute or by hiding legitimate document files and copying an executable to the folder with the same name as the legitimate document.

T1547.001
Registry Run Keys / Startup Folder

SHIPSHAPE achieves persistence by creating a shortcut in the Startup folder.

T1547.009
Shortcut Modification

SHIPSHAPE achieves persistence by creating a shortcut in the Startup folder.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT30 Open source
    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.