USBWorm is a malware component associated with Transparent Tribe / APT36 (also referred to in the content as PROJECTM, MYTHIC LEOPARD, ProjectM, Mythic Leopard, and Earth Karkaddan) and used in Crimson RAT operations. The content describes it as more than a simple USB infector: it can infect removable media for lateral movement, steal files of interest from removable drives, and download and execute the Crimson Thin Client from a remote Crimson server. It is part of the broader Crimson malware framework, whose client components include Thin Client, Main Client, USB Driver, USB Worm, Pass Logger, KeyLogger, and Remover.
The reported infection chain for related Transparent Tribe campaigns commonly begins with spear-phishing emails delivering malicious Microsoft Office documents with VBA macros. Those macros drop an encoded ZIP under %ALLUSERPROFILE% and extract an executable identified as the Crimson Thin Client. USBWorm itself is described as infecting removable media by hiding legitimate directories and placing copies of itself using the same directory names with hidden attributes and a folder-like icon to trick users into executing it. Persistence is established by copying itself to a configured directory and creating a Run key at HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. One observed USBWorm-related path was C:\ProgramData\Dacr\macrse.exe, used for saving a payload received from C2 when invoking the usbwrm command.
Its theft functionality targets documents on removable media, specifically files with extensions .pdf, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pps, .ppsx, and .txt. The content also states that newer Crimson RAT variants included a command to load usbworm, indicating support for lateral movement through removable media such as USB devices. Transparent Tribe activity described in the supporting content primarily targeted Indian military, defense, government, and education sectors, with additional focus on Afghanistan. Kaspersky telemetry cited in the content reported more than 1,000 distinct victims across 27 countries from June 2019 to June 2020, with most detections related to USBWorm.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It’s a surprise that the Crimson RAT variant embedded a command for loading the malware usbworm. Which means it can do lateral movment through removable media like usb.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm payload that can be loaded by Crimson RAT to spread laterally via removable media such as USB devices.
A removable-media worm used to propagate via USB drives by hiding real directories and replacing them with malware copies using folder-like icons to trick execution. It steals documents from removable media (e.g., .pdf/.doc/.xls/.ppt/.txt), maintains a local list of stolen filenames, and can bootstrap new infections by contacting a Crimson Server to download/execute the Crimson Thin Client when run on an uninfected host. Persists via HKCU Run key.
Module used to download/execute files, spread via removable devices, and steal files of interest (including from hosts disconnected from the internet).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.