LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1091: Replication Through Removable Media

Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and executes. In the case of Lateral Movement, this may occur through modification of executable files stored on removable media or by copying malware and renaming it to look like a legitimate file to trick users into executing it on a separate system. In the case of Initial Access, this may occur through manual manipulation of the media, modification of systems used to initially format the media, or modification to the media's firmware itself.

Mobile devices may also be used to infect PCs with malware if connected via USB.[1] This infection may be achieved using devices (Android, iOS, etc.) and, in some instances, USB charging cables.[2][3] For example, when a smartphone is connected to a system, it may appear to be mounted similar to a USB-connected disk drive. If malware that is compatible with the connected system is on the mobile device, the malware could infect the machine (especially if Autorun features are enabled).

EnterpriseT1091TechniqueObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Replication Through Removable Media matters because it gives adversaries a path into or across Windows environments that may not depend on email, internet access, or normal network connectivity. USB drives, external media, smartphones, and even charging cables can become a bridge between trusted and untrusted systems, including disconnected or air-gapped networks. For leaders, the business issue is not just malware on a USB device; it is whether operational, classified, lab, manufacturing, or recovery environments have defensible controls and evidence around removable media use.

Executive priority

Treat this as a resilience and governance control area, especially where Windows systems interact with sensitive operations, third parties, travel workflows, shared workstations, or disconnected networks. Executives should ask whether the organization can prove which removable devices are allowed, where Autorun-like behavior is disabled or controlled, whether endpoint behavior prevention is active, and whether incident responders can reconstruct file and process activity after media insertion. The number of ATT&CK relationships to threat groups and malware families indicates this is a well-represented behavior in ATT&CK reporting, but local risk should be based on actual removable media use, critical asset exposure, and telemetry maturity.

Technical view

For SOC, detection engineering, and IR teams, validate coverage around Windows removable media insertion followed by suspicious file creation, file modification on removable drives, renamed executables, and process execution from removable paths. The supplied ATT&CK object has no official detection text, but the related detection strategy DET0301, Removable Media Execution Chain Detection via File and Process Activity, supports focusing on the chain of device connection, file activity, and process activity rather than on device presence alone. Investigations should correlate media events with endpoint process lineage, executable launch paths, user context, and subsequent lateral movement or initial access indicators. Relationship context includes multiple groups and Windows malware families using this technique, so detections should be behavior-based rather than limited to known tool names such as PlugX, Agent.btz, USBStealer, Flame, njRAT, Ursnif, or others listed in ATT&CK relationships.

Likely telemetry

  • Windows endpoint device insertion and removable storage events
  • File creation, modification, rename, and execution events on removable media paths
  • Process creation telemetry with command line, parent process, user, working directory, and image path
  • Endpoint security alerts for suspicious process behavior or execution from external media
  • Autorun or removable media policy configuration evidence

Detection direction

  • Validate whether the SOC can correlate removable media insertion with file/process activity, not just alert on USB usage.
  • Tune for execution from removable paths, newly written executables or scripts on removable drives, files renamed to resemble legitimate documents or utilities, and unusual parent-child process relationships after media insertion.
  • Account for legitimate administrative, engineering, medical, manufacturing, or field-support workflows that may require removable media; use allowlists and business context to reduce false positives.
  • Prioritize monitoring on Windows systems connected to sensitive, disconnected, or operationally critical environments where removable media may bridge trust zones.
  • Review blind spots where endpoint agents do not log external device events, where mobile devices mount as storage, where charging cables or peripheral devices are not inventoried, or where air-gapped systems lack centralized telemetry.

Mitigation priorities

  • First, establish and enforce removable hardware usage policy through M1034 Limit Hardware Installation: restrict unauthorized external drives, peripherals, driver installation, and unapproved hardware use.
  • Disable or remove unnecessary features that enable automatic execution or unnecessary removable media interaction, consistent with M1042 Disable or Remove Feature or Program.
  • Apply M1040 Behavior Prevention on Endpoint to block or contain suspicious process and file behavior associated with execution from removable media.
  • Define exceptions for approved business workflows, and ensure exceptions are documented, time-bound where possible, and auditable.
  • For disconnected or high-criticality Windows environments, pair technical restrictions with operational procedures for scanning, handling, and approving removable media before use.
Additional notes and limits

This technique is mapped to Enterprise ATT&CK T1091 and the Windows platform, with tactics of Initial Access and Lateral Movement. The object describes removable media, modified files on media, user deception through legitimate-looking filenames, Autorun-related execution, and mobile devices connected over USB as possible infection paths. ATT&CK relationships show mitigation coverage from M1034, M1040, and M1042, detection strategy DET0301, and use by multiple groups and software entries. Those relationships support prioritizing behavior-based controls and telemetry validation, but they do not by themselves prove current activity in any specific environment.

MITRE provides no official detection text for this technique in the supplied object. This take is limited to the supplied STIX fields, external references, and relationships, and does not assert active exploitation, customer exposure, or guaranteed detection. Local conclusions require environment-specific evidence: removable media policy, Windows configuration, endpoint telemetry quality, exception handling, and the actual business need for removable devices.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Replication Through Removable Media

Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and executes. In the case of Lateral Movement, this may occur through modification of executable files stored on removable media or by copying malware and renaming it to look like a legitimate file to trick users into executing it on a separate system. In the case of Initial Access, this may occur through manual manipulation of the media, modification of systems used to initially format the media, or modification to the media's firmware itself.

Mobile devices may also be used to infect PCs with malware if connected via USB.[1] This infection may be achieved using devices (Android, iOS, etc.) and, in some instances, USB charging cables.[2][3] For example, when a smartphone is connected to a system, it may appear to be mounted similar to a USB-connected disk drive. If malware that is compatible with the connected system is on the mobile device, the malware could infect the machine (especially if Autorun features are enabled).

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0047: Gamaredon Group

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns.[1][2][3][4][5]

In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers. [6][5]

GroupEnterprise

G1014: LuminousMoth

LuminousMoth is a Chinese-speaking cyber espionage group that has been active since at least October 2020. LuminousMoth has targeted high-profile organizations, including government entities, in Myanmar, the Philippines, Thailand, and other parts of Southeast Asia. Some security researchers have concluded there is a connection between LuminousMoth and Mustang Panda based on similar targeting and TTPs, as well as network infrastructure overlaps.[1][2]

GroupEnterprise

G1007: Aoqin Dragon

Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013. Aoqin Dragon has primarily targeted government, education, and telecommunication organizations in Australia, Cambodia, Hong Kong, Singapore, and Vietnam. Security researchers noted a potential association between Aoqin Dragon and UNC94, based on malware, infrastructure, and targets.[1]

GroupEnterprise

G0012: Darkhotel

Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.[1][2][3]

GroupEnterprise

G0129: Mustang Panda

Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam. [1][2][3][4][5][6][7][8][9][10][11][12][13]

GroupEnterprise

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]

GroupEnterprise

G0007: APT28

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2] This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13]

APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[5] In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[14] Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

GroupEnterprise

G0081: Tropic Trooper

Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. Tropic Trooper focuses on targeting government, healthcare, transportation, and high-tech industries and has been active since 2011.[1][2][3]

MalwareEnterprise

S0143: Flame

Flame is a sophisticated toolkit that has been used to collect information since at least 2010, largely targeting Middle East countries. [1]

Windows
MalwareEnterprise

S0028: SHIPSHAPE

SHIPSHAPE is malware developed by APT30 that allows propagation and exfiltration of data over removable devices. APT30 may use this capability to exfiltrate data across air-gaps. [1]

MalwareEnterprise

S0132: H1N1

H1N1 is a malware variant that has been distributed via a campaign using VBA macros to infect victims. Although it initially had only loader capabilities, it has evolved to include information-stealing functionality. [1]

Windows
MalwareEnterprise

S0603: Stuxnet

Stuxnet was the first publicly reported malware to specifically target industrial control systems devices. Stuxnet is a large and complex malware that utilized multiple behaviors, including numerous zero-day vulnerabilities, a sophisticated Windows rootkit, and network infection routines.[1][2][3][4] Stuxnet was discovered in 2010, with some components being used as early as November 2008.[1]

Windows
MalwareEnterprise

S1130: Raspberry Robin

Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024. The malware is notable for spreading via infected USB devices containing a malicious LNK object that, on execution, retrieves remote hosted payloads for installation. Raspberry Robin has been widely used against various industries and geographies, and as a precursor to information stealer, ransomware, and other payloads such as SocGholish, Cobalt Strike, IcedID, and Bumblebee.[1][2][3] The DLL componenet in the Raspberry Robin infection chain is also referred to as "Roshtyak."[4] The name "Raspberry Robin" is used to refer to both the malware as well as the threat actor associated with its use, although the Raspberry Robin operators are also tracked as Storm-0856 by some vendors.[5]

Windows
MalwareEnterprise

S0092: Agent.btz

Agent.btz is a worm that primarily spreads itself via removable devices such as USB drives. It reportedly infected U.S. military networks in 2008. [1]

Windows
MalwareEnterprise

S0385: njRAT

njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.[1]

Windows
MalwareEnterprise

S0452: USBferry

USBferry is an information stealing malware and has been used by Tropic Trooper in targeted attacks against Taiwanese and Philippine air-gapped military environments. USBferry shares an overlapping codebase with YAHOYAH, though it has several features which makes it a distinct piece of malware.[1]

Windows
Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.3
Created
Modified
Raw hash
82633a9eda748fb9...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.3Current bundle82633a9eda74…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Exploiting Smartphone USB

    Zhaohui Wang & Angelos Stavrou. (n.d.). Exploiting Smart-Phone USB Connectivity For Fun And Profit. Retrieved May 25, 2022.

    Open source URL
  2. [2]
    Windows Malware Infecting Android

    Lucian Constantin. (2014, January 23). Windows malware tries to infect Android devices connected to PCs. Retrieved May 25, 2022.

    Open source URL
  3. [3]
    iPhone Charging Cable Hack

    Zack Whittaker. (2019, August 12). This hacker’s iPhone charging cable can hijack your computer. Retrieved May 25, 2022.

    Open source URL
  4. [4]
    Kaspersky Flame

    Gostev, A. (2012, May 28). The Flame: Questions and Answers. Retrieved March 1, 2017.

    Open source URL
  5. [5]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  6. [6]
    2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA

    Golo Muhr, Joshua Chung. (2025, May 15). Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign. Retrieved August 4, 2025.

    Open source URL
  7. [7]
    Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024

    Lenart Bermejo, Sunny Lu, Ted Lee. (2024, September 9). Earth Preta Evolves its Attacks with New Malware and Strategies. Retrieved August 4, 2025.

    Open source URL
  8. [8]
    SymantecCarbonBlack_ShuckwormUSB_Apr2025

    Threat Hunter Team, Symantec and Carbon Black. (2025, April 10). Shuckworm Targets Foreign Military Mission Based in Ukraine. Retrieved July 23, 2025.

    Open source URL
  9. [9]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  10. [10]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  11. [11]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  12. [12]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  13. [13]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  14. [14]
    DustySky

    ClearSky. (2016, January 7). Operation DustySky. Retrieved January 8, 2016.

    Open source URL
  15. [15]
    Cisco H1N1 Part 2

    Reynolds, J.. (2016, September 14). H1N1: Technical analysis reveals new capabilities – part 2. Retrieved November 17, 2024.

    Open source URL
  16. [16]
    Microsoft Disable Autorun

    Microsoft. (n.d.). How to disable the Autorun functionality in Windows. Retrieved April 20, 2016.

    Open source URL
  17. [17]
    TechNet Removable Media Control

    Microsoft. (2007, August 31). https://technet.microsoft.com/en-us/library/cc771759(v=ws.10).aspx. Retrieved April 20, 2016.

    Open source URL
  18. [18]
    Kaspersky Darkhotel

    Kaspersky Lab's Global Research and Analysis Team. (2014, November). The Darkhotel APT A Story of Unusual Hospitality. Retrieved November 12, 2014.

    Open source URL
  19. [19]
    Nicolas Falliere, Liam O Murchu, Eric Chien February 2011

    Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024.

    Open source URL
  20. [20]
    Avira Mustang Panda January 2020

    Hamzeloofard, S. (2020, January 31). New wave of PlugX targets Hong Kong | Avira Blog. Retrieved April 13, 2021.

    Open source URL
  21. [21]
    TrendMicro RaspberryRobin 2022

    Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.

    Open source URL
  22. [22]
    RedCanary RaspberryRobin 2022

    Lauren Podber and Stef Rand. (2022, May 5). Raspberry Robin gets the worm early. Retrieved May 17, 2024.

    Open source URL
  23. [23]
    win10_asr

    Microsoft. (2021, July 2). Use attack surface reduction rules to prevent malware infection. Retrieved June 24, 2021.

    Open source URL
  24. [24]
    ThreatExpert Agent.btz

    Shevchenko, S.. (2008, November 30). Agent.btz - A Threat That Hit Pentagon. Retrieved April 8, 2016.

  25. [25]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  26. [26]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  27. [27]
    TrendMicro Tropic Trooper May 2020

    Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020.

    Open source URL
  28. [28]
    FireEye APT28

    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.

    Open source URL
  29. [29]
    Microsoft SIR Vol 19

    Anthe, C. et al. (2015, October 19). Microsoft Security Intelligence Report Volume 19. Retrieved December 23, 2015.

  30. [30]
    Secureworks IRON TWILIGHT Active Measures March 2017

    Secureworks CTU. (2017, March 30). IRON TWILIGHT Supports Active Measures. Retrieved February 28, 2022.

    Open source URL
  31. [31]
    Kaspersky Transparent Tribe August 2020

    Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved September 2, 2021.

    Open source URL
  32. [32]
    FBI Flash FIN7 USB

    The Record. (2022, January 7). FBI: FIN7 hackers target US companies with BadUSB devices to install ransomware. Retrieved January 14, 2022.

    Open source URL
  33. [33]
    Gemini_FIN7_Jan2022

    Gemini Advisory. (2022, January 13). FIN7 Uses Flash Drives to Spread Remote Access Trojan. Retrieved May 14, 2025.

    Open source URL
  34. [34]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  35. [35]
    Trend Micro Qakbot May 2020

    Mendoza, E. et al. (2020, May 25). Qakbot Resurges, Spreads through VBS Files. Retrieved September 27, 2021.

    Open source URL
  36. [36]
    Mandiant Suspected Turla Campaign February 2023

    Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.

    Open source URL
  37. [37]
    ESET Sednit USBStealer 2014

    Calvet, J. (2014, November 11). Sednit Espionage Group Attacking Air-Gapped Networks. Retrieved January 4, 2017.

  38. [38]
    SANS Conficker

    Burton, K. (n.d.). The Conficker Worm. Retrieved February 18, 2021.

    Open source URL
  39. [39]
    Trend Micro Conficker

    Trend Micro. (2014, March 18). Conficker. Retrieved February 18, 2021.

    Open source URL
  40. [40]
    TrendMicro Ursnif Mar 2015

    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

    Open source URL
  41. [41]
    TrendMicro Ursnif File Dec 2014

    Caragay, R. (2014, December 11). Info-Stealing File Infector Hits US, UK. Retrieved June 5, 2019.

    Open source URL
  42. [42]
    Exploiting Smartphone USB

    Zhaohui Wang & Angelos Stavrou. (n.d.). Exploiting Smart-Phone USB Connectivity For Fun And Profit. Retrieved May 25, 2022.

    Open source URL
  43. [43]
    Exploiting Smartphone USB

    Zhaohui Wang & Angelos Stavrou. (n.d.). Exploiting Smart-Phone USB Connectivity For Fun And Profit. Retrieved May 25, 2022.

    Open source URL
  44. [44]
    Windows Malware Infecting Android

    Lucian Constantin. (2014, January 23). Windows malware tries to infect Android devices connected to PCs. Retrieved May 25, 2022.

    Open source URL
  45. [45]
    Windows Malware Infecting Android

    Lucian Constantin. (2014, January 23). Windows malware tries to infect Android devices connected to PCs. Retrieved May 25, 2022.

    Open source URL
  46. [46]
    iPhone Charging Cable Hack

    Zack Whittaker. (2019, August 12). This hacker’s iPhone charging cable can hijack your computer. Retrieved May 25, 2022.

    Open source URL
  47. [47]
    iPhone Charging Cable Hack

    Zack Whittaker. (2019, August 12). This hacker’s iPhone charging cable can hijack your computer. Retrieved May 25, 2022.

    Open source URL
  48. [48]
    mitre-attackT1091
    Open source URL
  49. [49]
    mitre-attackT1091
    Open source URL
  50. [50]
    mitre-attackT1091
    Open source URL
  51. [51]
    Kaspersky Flame

    Gostev, A. (2012, May 28). The Flame: Questions and Answers. Retrieved March 1, 2017.

    Open source URL
  52. [52]
    FireEye APT30

    FireEye Labs. (2015, April). APT30 AND THE MECHANICS OF A LONG-RUNNING CYBER ESPIONAGE OPERATION. Retrieved November 17, 2024.

    Open source URL
  53. [53]
    2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA

    Golo Muhr, Joshua Chung. (2025, May 15). Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign. Retrieved August 4, 2025.

    Open source URL
  54. [54]
    Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024

    Lenart Bermejo, Sunny Lu, Ted Lee. (2024, September 9). Earth Preta Evolves its Attacks with New Malware and Strategies. Retrieved August 4, 2025.

    Open source URL
  55. [55]
    SymantecCarbonBlack_ShuckwormUSB_Apr2025

    Threat Hunter Team, Symantec and Carbon Black. (2025, April 10). Shuckworm Targets Foreign Military Mission Based in Ukraine. Retrieved July 23, 2025.

    Open source URL
  56. [56]
    DOJ Affidavit Search and Seizure PlugX December 2024

    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.

    Open source URL
  57. [57]
    Bitdefender LuminousMoth July 2021

    Botezatu, B and etl. (2021, July 21). LuminousMoth - PlugX, File Exfiltration and Persistence Revisited. Retrieved October 20, 2022.

    Open source URL
  58. [58]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  59. [59]
    Forcepoint Monsoon

    Settle, A., et al. (2016, August 8). MONSOON - Analysis Of An APT Campaign. Retrieved September 22, 2016.

    Open source URL
  60. [60]
    SentinelOne Aoqin Dragon June 2022

    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

    Open source URL
  61. [61]
    DustySky

    ClearSky. (2016, January 7). Operation DustySky. Retrieved January 8, 2016.

    Open source URL
  62. [62]
    Cisco H1N1 Part 2

    Reynolds, J.. (2016, September 14). H1N1: Technical analysis reveals new capabilities – part 2. Retrieved November 17, 2024.

    Open source URL
  63. [63]
    Microsoft Disable Autorun

    Microsoft. (n.d.). How to disable the Autorun functionality in Windows. Retrieved April 20, 2016.

    Open source URL
  64. [64]
    TechNet Removable Media Control

    Microsoft. (2007, August 31). https://technet.microsoft.com/en-us/library/cc771759(v=ws.10).aspx. Retrieved April 20, 2016.

    Open source URL
  65. [65]
    Kaspersky Darkhotel

    Kaspersky Lab's Global Research and Analysis Team. (2014, November). The Darkhotel APT A Story of Unusual Hospitality. Retrieved November 12, 2014.

    Open source URL
  66. [66]
    Nicolas Falliere, Liam O Murchu, Eric Chien February 2011

    Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024.

    Open source URL
  67. [67]
    Avira Mustang Panda January 2020

    Hamzeloofard, S. (2020, January 31). New wave of PlugX targets Hong Kong | Avira Blog. Retrieved April 13, 2021.

    Open source URL
  68. [68]
    RedCanary RaspberryRobin 2022

    Lauren Podber and Stef Rand. (2022, May 5). Raspberry Robin gets the worm early. Retrieved May 17, 2024.

    Open source URL
  69. [69]
    TrendMicro RaspberryRobin 2022

    Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.

    Open source URL
  70. [70]
    win10_asr

    Microsoft. (2021, July 2). Use attack surface reduction rules to prevent malware infection. Retrieved June 24, 2021.

    Open source URL
  71. [71]
    ThreatExpert Agent.btz

    Shevchenko, S.. (2008, November 30). Agent.btz - A Threat That Hit Pentagon. Retrieved April 8, 2016.

  72. [72]
    Fidelis njRAT June 2013

    Fidelis Cybersecurity. (2013, June 28). Fidelis Threat Advisory #1009: "njRAT" Uncovered. Retrieved June 4, 2019.

    Open source URL
  73. [73]
    Trend Micro njRAT 2018

    Pascual, C. (2018, November 27). AutoIt-Compiled Worm Affecting Removable Media Delivers Fileless Version of BLADABINDI/njRAT Backdoor. Retrieved June 4, 2019.

    Open source URL
  74. [74]
    TrendMicro Tropic Trooper May 2020

    Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020.

    Open source URL
  75. [75]
    FireEye APT28

    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.

    Open source URL
  76. [76]
    Microsoft SIR Vol 19

    Anthe, C. et al. (2015, October 19). Microsoft Security Intelligence Report Volume 19. Retrieved December 23, 2015.

  77. [77]
    Secureworks IRON TWILIGHT Active Measures March 2017

    Secureworks CTU. (2017, March 30). IRON TWILIGHT Supports Active Measures. Retrieved February 28, 2022.

    Open source URL
  78. [78]
    Kaspersky Transparent Tribe August 2020

    Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved September 2, 2021.

    Open source URL
  79. [79]
    FBI Flash FIN7 USB

    The Record. (2022, January 7). FBI: FIN7 hackers target US companies with BadUSB devices to install ransomware. Retrieved January 14, 2022.

    Open source URL
  80. [80]
    Gemini_FIN7_Jan2022

    Gemini Advisory. (2022, January 13). FIN7 Uses Flash Drives to Spread Remote Access Trojan. Retrieved May 14, 2025.

    Open source URL
  81. [81]
    Eset Ramsay May 2020

    Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.

    Open source URL
  82. [82]
    Trend Micro Qakbot May 2020

    Mendoza, E. et al. (2020, May 25). Qakbot Resurges, Spreads through VBS Files. Retrieved September 27, 2021.

    Open source URL
  83. [83]
    Mandiant Suspected Turla Campaign February 2023

    Hawley, S. et al. (2023, February 2). Turla: A Galaxy of Opportunity. Retrieved May 15, 2023.

    Open source URL
  84. [84]
    Microsoft SIR Vol 19

    Anthe, C. et al. (2015, October 19). Microsoft Security Intelligence Report Volume 19. Retrieved December 23, 2015.

  85. [85]
    TrendMicro Tropic Trooper May 2020

    Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.