USBStealer is a Windows espionage malware used to steal data from air-gapped or otherwise isolated environments by abusing removable media as an offline transfer channel. It has been associated with Sednit, also known as APT28 or Sofacy, and has been described as part of that group’s long-running toolkit for targeting governmental, military, and other high-value organizations, particularly in Eastern Europe and geopolitically relevant sectors.
The malware monitors compromised systems for the insertion of removable drives and can enumerate connected drives on secondary systems reached through those devices. It collects files matching attacker-defined criteria from non-removable and removable storage, stages the data locally, and relies on a USB drive being carried between systems to move stolen information across an air gap. In the documented workflow, a removable drive inserted into an initially compromised machine is prepared for transfer; when that drive is later connected to a second victim, USBStealer can collect data there, and when the same media is reinserted into the first machine, the malware retrieves the staged data for later exfiltration to the operator. This makes it a purpose-built tool for covert collection from disconnected networks.
USBStealer also implements persistence on Windows through Registry Run-key autostart and uses defense-evasion measures including masquerading as legitimate software, timestomping of dropper artifacts to blend with normal system files, and cleanup commands to remove malware-related files from a victim. Public reporting places known activity primarily in the mid-2010s, with first versions dating to 2015 and some references to older Sednit air-gap tooling lineage. It is best characterized as a specialized infostealer focused on removable-media-based collection and exfiltration in espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
IdentityKit #1: USBStealer ... Perform espionage against governmental institutions in Eastern Europe.
“...the data stealer for air-gapped machines USBStealer.”
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
Frameworks gather information such as computer name, username, domain name, list of running processes, listing of files in directories, drives and network shares, as well as network configuration information
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
USBStealer, USBCulprit, Retro, USBThief, PlugX and Ramsay, for example, were clearly built to steal specific files.
AppleSeed can find and collect data from removable media devices. APT28 backdoor may collect the entire contents of an inserted USB device. Aria-body has the ability to collect data from USB devices. BADNEWS copies files with certain extensions from USB devices to a predefined directory.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Sednit data stealer designed for air-gapped machines, referenced as part of the group’s historical toolkit.
Stealer malware that copies timestamps from standard Windows libraries onto its dropper files.
Stealer malware that persists by registering itself under a Registry Run key with a deceptive name.
Stealer malware that mimics a legitimate USB security program.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.