Malware.View on attack.mitre.org
USBferry is an information stealing malware and has been used by Tropic Trooper in targeted attacks against Taiwanese and Philippine air-gapped military environments. USBferry shares an overlapping codebase with YAHOYAH, though it has several features which makes it a distinct piece of malware.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
USBferry can collect information from an air-gapped host machine. |
| T1016 System Network Configuration Discovery |
USBferry can detect the infected machine's network topology using |
| T1018 Remote System Discovery |
USBferry can use |
| T1049 System Network Connections Discovery |
USBferry can use |
| T1057 Process Discovery |
USBferry can use |
| T1059.003 Windows Command Shell |
USBferry can execute various Windows commands. |
| T1083 File and Directory Discovery |
USBferry can detect the victim's file or folder list. |
| T1087.001 Local Account |
USBferry can use |
| T1091 Replication Through Removable Media |
USBferry can copy its installer to attached USB storage devices. |
| T1120 Peripheral Device Discovery |
USBferry can check for connected USB devices. |
| T1218.011 Rundll32 |
USBferry can execute rundll32.exe in memory to avoid detection. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.