Data from Removable Media

T1025

Technique.View on attack.mitre.org

About this technique

Adversaries may search connected removable media on computers they have compromised to find files of interest. Sensitive data can be collected from any removable media (optical disk drive, USB memory, etc.) connected to the compromised system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information.

Some adversaries may also use Automated Collection on removable media.

Detection rules3

Rules on DetectionCode tagged with T1025.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk3

RuleTypeRiskData source
Windows Process Executed From Removable MediaAnomalyNULLSysmon EventID 1 AND Sysmon EventID 13
Windows USBSTOR Registry Key ModificationAnomalyNULLSysmon EventID 12, Sysmon EventID 13
Windows WPDBusEnum Registry Key ModificationAnomalyNULLSysmon EventID 12, Sysmon EventID 13

Groups4

Software20

Campaigns0

None recorded.

Procedure examples24

Groups4

Used byProcedure example
GroupAPT28

An APT28 backdoor may collect the entire contents of an inserted USB device.

GroupGamaredon Group

A Gamaredon Group file stealer has the capability to steal data from newly connected logical volumes on a system, including USB drives.

GroupOilRig

OilRig has used Wireshark’s usbcapcmd utility to capture USB traffic.

GroupTurla

Turla RPC backdoors can collect files from USB thumb drives.

Software20

Used byProcedure example
MalwareAppleSeed

AppleSeed can find and collect data from removable media devices.

MalwareAria-body

Aria-body has the ability to collect data from USB devices.

MalwareBADNEWS

BADNEWS copies files with certain extensions from USB devices to
a predefined directory.

MalwareCosmicDuke

CosmicDuke steals user files from removable media with file extensions and keywords that match a predefined list.

MalwareCrimson

Crimson contains a module to collect data from removable drives.

MalwareCrutch

Crutch can monitor removable drives and exfiltrate files matching a given extension list.

MalwareExplosive

Explosive can scan all .exe files located in the USB drive.

MalwareFLASHFLOOD

FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on removable media and copies them to a staging area. The default file types copied would include data copied to the drive by SPACESHIP.

View all 20 software examples

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.