USBferry
MITRE ATT&CK: S0452 View on attack.mitre.org
Aliases: USBferry
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:18:43
Targeted industries: defense-and-aerospace government-and-public-sector
Targeted regions: country_code:tw country_code:ph
Context
USBferry is an information stealing malware and has been used by Tropic Trooper in targeted attacks against Taiwanese and Philippine air-gapped military environments. USBferry shares an overlapping codebase with YAHOYAH, though it has several features which makes it a distinct piece of malware.
Detection coverage
- 1 YARA rules
- 141 Sigma rules
Malware & tools used
- Local Account (attack-pattern)
- Remote System Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Replication Through Removable Media (attack-pattern)
- Rundll32 (attack-pattern)
- Data from Local System (attack-pattern)
- Process Discovery (attack-pattern)
- System Network Connections Discovery (attack-pattern)
Used by threat actors
- Tropic Trooper (threat-actor)
Detection rules
- MALPEDIA_Win_Usbferry_Auto (yara-rule)
Reports & references
- Trend Micro — Tech Brief Tropic Trooper S Back Usbferry Attack Targets Air Gapped Environments (report)
- ESET — Eset Jumping The Air Gap Wp (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Usbferry (report)
- Trend Micro — Tropic Troopers Back Usbferry Attack Targets Air Gapped Environments (report)
- MITRE ATT&CK — S0452 (report)