Technique.View on attack.mitre.org
Adversaries may search connected removable media on computers they have compromised to find files of interest. Sensitive data can be collected from any removable media (optical disk drive, USB memory, etc.) connected to the compromised system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information.
Some adversaries may also use Automated Collection on removable media.
Rules on DetectionCode tagged with T1025.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Process Executed From Removable Media | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 13 |
| Windows USBSTOR Registry Key Modification | Anomaly | NULL | Sysmon EventID 12, Sysmon EventID 13 |
| Windows WPDBusEnum Registry Key Modification | Anomaly | NULL | Sysmon EventID 12, Sysmon EventID 13 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT28 | An APT28 backdoor may collect the entire contents of an inserted USB device. |
| GroupGamaredon Group | A Gamaredon Group file stealer has the capability to steal data from newly connected logical volumes on a system, including USB drives. |
| GroupOilRig | OilRig has used Wireshark’s usbcapcmd utility to capture USB traffic. |
| GroupTurla | Turla RPC backdoors can collect files from USB thumb drives. |
| Used by | Procedure example |
|---|---|
| MalwareAppleSeed | AppleSeed can find and collect data from removable media devices. |
| MalwareAria-body | Aria-body has the ability to collect data from USB devices. |
| MalwareBADNEWS | BADNEWS copies files with certain extensions from USB devices to |
| MalwareCosmicDuke | CosmicDuke steals user files from removable media with file extensions and keywords that match a predefined list. |
| MalwareCrimson | Crimson contains a module to collect data from removable drives. |
| MalwareCrutch | Crutch can monitor removable drives and exfiltrate files matching a given extension list. |
| MalwareExplosive | Explosive can scan all .exe files located in the USB drive. |
| MalwareFLASHFLOOD | FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on removable media and copies them to a staging area. The default file types copied would include data copied to the drive by SPACESHIP. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.