Technique.View on attack.mitre.org
Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and executes. In the case of Lateral Movement, this may occur through modification of executable files stored on removable media or by copying malware and renaming it to look like a legitimate file to trick users into executing it on a separate system. In the case of Initial Access, this may occur through manual manipulation of the media, modification of systems used to initially format the media, or modification to the media's firmware itself.
Mobile devices may also be used to infect PCs with malware if connected via USB. This infection may be achieved using devices (Android, iOS, etc.) and, in some instances, USB charging cables. For example, when a smartphone is connected to a system, it may appear to be mounted similar to a USB-connected disk drive. If malware that is compatible with the connected system is on the mobile device, the malware could infect the machine (especially if Autorun features are enabled).
Rules on DetectionCode tagged with T1091.
| Rule | Level | Log source |
|---|---|---|
| External Disk Drive Or USB Storage Device Was Recognized By The System | low | windows / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Process Executed From Removable Media | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 13 |
| Windows Replication Through Removable Media | TTP | NULL | Sysmon EventID 11 |
| Windows USBSTOR Registry Key Modification | Anomaly | NULL | Sysmon EventID 12, Sysmon EventID 13 |
| Windows WPDBusEnum Registry Key Modification | Anomaly | NULL | Sysmon EventID 12, Sysmon EventID 13 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAoqin Dragon | Aoqin Dragon has used a dropper that employs a worm infection strategy using a removable device to breach a secure network environment. |
| GroupAPT28 | APT28 uses a tool to infect connected USB devices and transmit itself to air-gapped computers when the infected USB device is inserted. |
| GroupDarkhotel | Darkhotel's selective infector modifies executables stored on removable media as a method of spreading across computers. |
| GroupFIN7 | FIN7 actors have mailed USB drives to potential victims containing malware that downloads and installs various backdoors, including in some cases for ransomware operations. Additionally, FIN7 has used malicious USBs that acted as virtual keyboards to install malware and txt files that decode to PowerShell commands. |
| GroupGamaredon Group | Gamaredon Group has replicated to removable media by leveraging the User Assist Reg Key and creating LNKs on all network and removable drives available on the infected host. |
| GroupLuminousMoth | LuminousMoth has used malicious DLLs to spread malware to connected removable USB drives on infected machines. |
| GroupMustang Panda | Mustang Panda has used a customized PlugX variant which could spread through USB connections. |
| GroupTropic Trooper | Tropic Trooper has attempted to transfer USBferry from an infected USB device by copying an Autorun function to the target machine. |
| Used by | Procedure example |
|---|---|
| MalwareAgent.btz | Agent.btz drops itself onto removable media devices and creates an autorun.inf file with an instruction to run that file. When the device is inserted into another system, it opens autorun.inf and loads the malware. |
| MalwareANDROMEDA | ANDROMEDA has been spread via infected USB keys. |
| MalwareCHOPSTICK | Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic. |
| MalwareConficker | Conficker variants used the Windows AUTORUN feature to spread through USB propagation. |
| MalwareCrimson | Crimson can spread across systems by infecting removable media. |
| MalwareDustySky | DustySky searches for removable media and duplicates itself onto it. |
| MalwareFlame | Flame contains modules to infect USB sticks and spread laterally to other Windows systems the stick is plugged into using Autorun functionality. |
| MalwareH1N1 | H1N1 has functionality to copy itself to removable media. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.