Executive Summary
USBferry is an advanced, Windows‑based data theft tool used by Tropic Trooper to infiltrate Taiwanese and Philippine military networks. The malware targets air‑gapped environments via USB media, harvests system information and credentials, then covertly exfiltrates the payload. Its code sharing with YAHOYAH suggests a common development lineage, but USBferry’s additional capabilities—especially in persistence and stealth—make it a distinct threat vector.
Enhanced Description
USBferry is a Windows‑based information‑stealing malware that was first identified in targeted attacks conducted by the threat actor known as Tropic Trooper against Taiwanese and Philippine military installations. The codebase of USBferry overlaps with that of YAHOYAH, indicating shared development resources or tooling; however, USBferry incorporates several distinct features such as enhanced persistence mechanisms, more sophisticated data‑collection routines, and hardened exfiltration channels that separate it from its sibling family. In operation, USBferry harvests a wide range of system artifacts—computer inventory details, logged credentials, recent documents, and potentially configuration files—and then attempts to exfiltrate the collected payload back to an adversary command‑and‑control (C&C) server. While it is primarily designed for stealth against air‑gapped environments, the malware employs obfuscation techniques to evade static detection and relies on removable media as a delivery vector, thereby facilitating its intrusion into highly isolated networks. Tropic Trooper’s use of USBferry underscores the evolving threat landscape in which nation‑state actors are deploying tailored malware that exploits legacy operational procedures (e.g., the handling of USB devices) to bypass perimeter defenses. When combined with other Trooper techniques—such as covert C&C communication and credential dumping—the malware represents a multi‑stage platform capable of conducting both reconnaissance and data exfiltration in highly secure settings.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available information provides a moderate level of confidence regarding USBferry’s role as an information‐stealing tool used by Tropic Trooper. Key gaps remain around the exact persistence mechanisms, the full scope of data exfiltration channels, and whether additional capabilities such as credential dumping or lateral movement are present in this family. Further samples and network traffic analysis would enhance understanding of its operational profile.
USBferry is an information stealing malware and has been used by Tropic Trooper in targeted attacks against Taiwanese and Philippine air-gapped military environments. USBferry shares an overlapping codebase with YAHOYAH, though it has several features which makes it a distinct piece of malware.(Citation: TrendMicro Tropic Trooper May 2020)