USBferry is a Windows USB-propagating espionage malware family used by Tropic Trooper to compromise connected and air-gapped systems and steal sensitive documents. Activity has been observed since 2014, including operations against government institutions, military and navy organizations, military hospitals, and a national bank in Taiwan and the Philippines. Targeted information includes defense-, maritime-, and ship-related documents. The malware detects connected USB storage and copies its installer onto removable media, enabling infection of physically isolated systems. When network connectivity is unavailable, it collects host data and copies it to USB storage for subsequent exfiltration through a connected system.
USBferry executes Windows commands to enumerate local accounts, running processes, remote systems, network configuration, and active connections. Multiple versions and components have been identified, including loaders that unpack encrypted payloads and inject a malicious DLL into the Windows Rundll32 process to reduce detection. Tropic Trooper has used less-secured related organizations as stepping stones into more protected environments, including movement from a military hospital into an air-gapped military network.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group employs USBferry, a USB malware that performs different commands on specific targets, maintains stealth in environments, and steals critical data through USB storage.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The group employs USBferry, a USB malware that performs different commands on specific targets, maintains stealth in environments, and steals critical data through USB storage. | The group achieves infection by employing the USB worm infection strategy and ferrying a malware installer via USB into an air-gapped host machine.
This version also changes the malware location and its name to UF, an abbreviation for USBferry.
After the encrypted payload is loaded, the loader injects a malicious DLL into rundll32.exe.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
used built-in Windows commands such as tracert and ping to determine whether the system they are running on has internet connectivity or not.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Frameworks gather information such as computer name, username, domain name, list of running processes, listing of files in directories, drives and network shares, as well as network configuration information
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
The group employs USBferry, a USB malware that performs different commands on specific targets, maintains stealth in environments, and steals critical data through USB storage. | The group achieves infection by employing the USB worm infection strategy and ferrying a malware installer via USB into an air-gapped host machine.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Detects infected machine network topology using ipconfig and arp.
Uses net view to gather information about remote systems.
Malware designed to collect information from air-gapped hosts.
Worm that detects infected machine network topology using ipconfig and arp.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.