Government and military-linked networks in the Asia-Pacific region were targeted in espionage campaigns that used compromised USB tools to move malware into air-gapped environments and steal sensitive files. Kaspersky reported that a threat cluster dubbed TetrisPhantom infected government systems by trojanizing the legitimate UTetris.exe application used with hardware-encrypted secure USB drives, then using components including AcroShell and XMKR to infect hosts, harvest documents, and spread through connected removable media. The malware reportedly communicated with USB devices at the SCSI level, injected code into legitimate software, and staged exfiltration so stolen data could leave isolated systems once infected drives were later connected to internet-accessible machines.
The activity mirrors earlier reporting on Tropic Trooper, which used the USBferry malware family to penetrate physically isolated military-related networks in Taiwan and the Philippines by abusing removable media and pivoting through less-secured affiliated organizations such as a military hospital. Trend Micro said USBferry supported reconnaissance, persistence, rundll32.exe injection, and covert data theft focused on defense-, ocean-, and ship-related documents. Together with Kaspersky’s broader APT reporting, the incidents show sustained, highly targeted espionage against APAC government and defense entities through weaponized USB ecosystems designed to bypass network isolation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
BleepingComputer reported Kaspersky's findings on the TetrisPhantom espionage campaign, including trojanized UTetris.exe variants used on secure USB drives and deployment of version 1.0 in September-October 2022 and version 2.0 from October 2022 onward.
In its Q3 2023 APT trends report, Kaspersky described the highly targeted APAC government intrusion using secure USB drives, low-level SCSI communication, code injection, and self-replication across air-gapped systems.
Kaspersky reported an early-2023 campaign targeting APAC government entities through compromised hardware-encrypted secure USB drives, enabling malware propagation into air-gapped systems.
Trend Micro said it had tracked this specific Tropic Trooper USBferry campaign since 2018, focused on compromising related organizations to reach protected military networks.
Trend Micro reported that USBferry-related attacks have been active since 2014, using USB media to move malware and steal data from isolated environments.
Trend Micro said Tropic Trooper has been active since at least 2011, conducting espionage against sectors including government, military, healthcare, transportation, and high tech.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcesecurelist.com
Open sourceblog.trendmicro.com
Open sourcepwc.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.