FORENSIA

ATT&CK · T1052.001 · sub-technique

Exfiltration over USB

Tactics: exfiltration

About

Adversaries may attempt to exfiltrate data over a USB connected physical device. In certain circumstances, such as an air-gapped network compromise, exfiltration could occur via a USB device introduced by a user. The USB device could be used as the final exfiltration point or to hop between otherwise disconnected systems.

Platforms: Linux, Windows, macOSParent: T1052 Exfiltration Over Physical MediumMITRE ATT&CK ↗

Used by actors

2 known groups

Software

5 malware/tools implement this

SPACESHIPAgent.btzRemsecUSBStealerMachete

Corpus indicators tagged with this technique

0 indicators in the corpus carry T1052.001.

No corpus indicators are tagged with this technique yet.