Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware USBferry

USBferry

TLP:CLEAR
Family

AI Analysis

· 2 hours ago

Executive Summary

USBferry is an advanced, Windows‑based data theft tool used by Tropic Trooper to infiltrate Taiwanese and Philippine military networks. The malware targets air‑gapped environments via USB media, harvests system information and credentials, then covertly exfiltrates the payload. Its code sharing with YAHOYAH suggests a common development lineage, but USBferry’s additional capabilities—especially in persistence and stealth—make it a distinct threat vector.

Enhanced Description

USBferry is a Windows‑based information‑stealing malware that was first identified in targeted attacks conducted by the threat actor known as Tropic Trooper against Taiwanese and Philippine military installations. The codebase of USBferry overlaps with that of YAHOYAH, indicating shared development resources or tooling; however, USBferry incorporates several distinct features such as enhanced persistence mechanisms, more sophisticated data‑collection routines, and hardened exfiltration channels that separate it from its sibling family. In operation, USBferry harvests a wide range of system artifacts—computer inventory details, logged credentials, recent documents, and potentially configuration files—and then attempts to exfiltrate the collected payload back to an adversary command‑and‑control (C&C) server. While it is primarily designed for stealth against air‑gapped environments, the malware employs obfuscation techniques to evade static detection and relies on removable media as a delivery vector, thereby facilitating its intrusion into highly isolated networks. Tropic Trooper’s use of USBferry underscores the evolving threat landscape in which nation‑state actors are deploying tailored malware that exploits legacy operational procedures (e.g., the handling of USB devices) to bypass perimeter defenses. When combined with other Trooper techniques—such as covert C&C communication and credential dumping—the malware represents a multi‑stage platform capable of conducting both reconnaissance and data exfiltration in highly secure settings.

Key Capabilities

  • Stealthy data collection of system inventory, documents, and credentials
  • Persistence via registry or scheduled task persistence hooks (inferred from family traits)
  • Exfiltration over encrypted C&C channels
  • Use of removable USB media for initial delivery
  • Basic obfuscation to evade static scanners
  • Potential to stage collected data before exfiltration

ATT&CK Techniques

T1082
T1074
T1041

Recommended Actions

  • Inspect all USB devices entering the network and enforce a strict no‑USB policy for critical systems
  • Deploy endpoint detection that monitors unusual file copy or registry modification activity, especially related to system inventory scripts
  • Implement data loss prevention (DLP) with monitoring of outbound traffic on suspicious ports and protocols
  • Harden C&C detection by blocking known malicious IPs/URLs and employing anomaly-based network monitoring for encrypted exfiltration patterns
  • Perform regular credential audits and enforce multi‑factor authentication in military environments

Suggested Tags

USBferry
Tropic Trooper
InformationStealer
YAHOYAH
Air‑gapped Malware
TaiwaneseMilitary
PhilippineMilitary
RemovableMediaAttack

Confidence Assessment

The available information provides a moderate level of confidence regarding USBferry’s role as an information‐stealing tool used by Tropic Trooper. Key gaps remain around the exact persistence mechanisms, the full scope of data exfiltration channels, and whether additional capabilities such as credential dumping or lateral movement are present in this family. Further samples and network traffic analysis would enhance understanding of its operational profile.

Description

USBferry is an information stealing malware and has been used by Tropic Trooper in targeted attacks against Taiwanese and Philippine air-gapped military environments. USBferry shares an overlapping codebase with YAHOYAH, though it has several features which makes it a distinct piece of malware.(Citation: TrendMicro Tropic Trooper May 2020)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.