{"description": "Enterprise techniques used by USBStealer, ATT&CK software S0136 v1.1", "name": "USBStealer (S0136)", "domain": "enterprise-attack", "versions": {"layer": "4.3", "attack": "10", "navigator": "4.5"}, "techniques": [{"score": 1, "techniqueID": "T1119", "showSubtechniques": false, "comment": "For all non-removable drives on a victim, [USBStealer](https://attack.mitre.org/software/S0136) executes automated collection of certain files for later exfiltration.(Citation: ESET Sednit USBStealer 2014)"}, {"score": 1, "techniqueID": "T1020", "showSubtechniques": false, "comment": "[USBStealer](https://attack.mitre.org/software/S0136) automatically exfiltrates collected files via removable media when an infected device is connected to the second victim after receiving commands from the first victim.(Citation: ESET Sednit USBStealer 2014)"}, {"techniqueID": "T1547", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1547.001", "showSubtechniques": true, "comment": "[USBStealer](https://attack.mitre.org/software/S0136) registers itself under a Registry Run key with the name \"USB Disk Security.\"(Citation: ESET Sednit USBStealer 2014)"}, {"score": 1, "techniqueID": "T1092", "showSubtechniques": false, "comment": "[USBStealer](https://attack.mitre.org/software/S0136) drops commands for a second victim onto a removable media drive inserted into the first victim, and commands are executed when the drive is inserted into the second victim.(Citation: ESET Sednit USBStealer 2014)"}, {"score": 1, "techniqueID": "T1025", "showSubtechniques": false, "comment": "Once a removable media device is inserted back into the first victim, [USBStealer](https://attack.mitre.org/software/S0136) collects data from it that was exfiltrated from a second victim.(Citation: ESET Sednit USBStealer 2014)(Citation: Kaspersky Sofacy)"}, {"techniqueID": "T1074", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1074.001", "showSubtechniques": true, "comment": "[USBStealer](https://attack.mitre.org/software/S0136) collects files matching certain criteria from the victim and stores them in a local directory for later exfiltration.(Citation: ESET Sednit USBStealer 2014)(Citation: Kaspersky Sofacy)"}, {"techniqueID": "T1052", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1052.001", "showSubtechniques": true, "comment": "[USBStealer](https://attack.mitre.org/software/S0136) exfiltrates collected files via removable media from air-gapped victims.(Citation: ESET Sednit USBStealer 2014)"}, {"score": 1, "techniqueID": "T1083", "showSubtechniques": false, "comment": "[USBStealer](https://attack.mitre.org/software/S0136) searches victim drives for files matching certain extensions (\u201c.skr\u201d,\u201c.pkr\u201d or \u201c.key\u201d) or names.(Citation: ESET Sednit USBStealer 2014)(Citation: Kaspersky Sofacy)"}, {"techniqueID": "T1070", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1070.004", "showSubtechniques": true, "comment": "[USBStealer](https://attack.mitre.org/software/S0136) has several commands to delete files associated with the malware from the victim.(Citation: ESET Sednit USBStealer 2014)"}, {"score": 1, "techniqueID": "T1070.006", "showSubtechniques": true, "comment": "[USBStealer](https://attack.mitre.org/software/S0136) sets the timestamps of its dropper files to the last-access and last-write timestamps of a standard Windows library chosen on the system.(Citation: ESET Sednit USBStealer 2014)"}, {"techniqueID": "T1036", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1036.005", "showSubtechniques": true, "comment": "[USBStealer](https://attack.mitre.org/software/S0136) mimics a legitimate Russian program called USB Disk Security.(Citation: ESET Sednit USBStealer 2014)"}, {"score": 1, "techniqueID": "T1027", "showSubtechniques": false, "comment": "Most strings in [USBStealer](https://attack.mitre.org/software/S0136) are encrypted using 3DES and XOR and reversed.(Citation: ESET Sednit USBStealer 2014)"}, {"score": 1, "techniqueID": "T1120", "showSubtechniques": false, "comment": "[USBStealer](https://attack.mitre.org/software/S0136) monitors victims for insertion of removable drives. When dropped onto a second victim, it also enumerates drives connected to the system.(Citation: ESET Sednit USBStealer 2014)"}, {"score": 1, "techniqueID": "T1091", "showSubtechniques": false, "comment": "[USBStealer](https://attack.mitre.org/software/S0136) drops itself onto removable media and relies on Autorun to execute the malicious file when a user opens the removable media on another system.(Citation: ESET Sednit USBStealer 2014)"}], "gradient": {"colors": ["#ffffff", "#66b1ff"], "minValue": 0, "maxValue": 1}, "legendItems": [{"label": "used by USBStealer", "color": "#66b1ff"}]}