USBferry is a Windows malware family used in cyberespionage operations to bridge air-gapped or otherwise physically isolated environments through removable media. It is associated with Tropic Trooper and has been used against government, military, naval, healthcare, transportation, high-technology, and related organizations, with reporting linking notable activity to targets in Taiwan and the Philippines. Its operational objective is intelligence collection, particularly theft of sensitive defense-, maritime-, and government-related documents from networks that may lack direct internet connectivity.
USBferry is designed to propagate and operate via USB storage devices, enabling movement of malware into isolated systems and extraction of collected data back out through the same medium. Multiple versions have been observed, including variants that monitor for connected USB devices, copy installer components to removable media, and improve stealth by executing within rundll32.exe memory space. The malware can load encrypted payload components, execute Windows commands, and use signed Windows binaries for proxy execution to reduce detection.
Its functionality includes host and network reconnaissance, such as enumerating running processes, local accounts, remote systems, active network connections, and local network topology. Observed behaviors include use of native Windows utilities to gather process information, inspect network configuration and ARP data, identify reachable systems, and detect attached USB devices. In environments with network access, USBferry can attempt to communicate outward and collect data from the target host. In disconnected environments, it stages stolen information onto removable media for later exfiltration when the device is reintroduced to a connected system.
USBferry is best characterized as an espionage-focused USB-borne collection platform for Windows environments, optimized for stealthy operation and data theft in segmented and air-gapped networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group employs USBferry, a USB malware that performs different commands on specific targets, maintains stealth in environments, and steals critical data through USB storage.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The group employs USBferry, a USB malware that performs different commands on specific targets, maintains stealth in environments, and steals critical data through USB storage. | The group achieves infection by employing the USB worm infection strategy and ferrying a malware installer via USB into an air-gapped host machine.
This version also changes the malware location and its name to UF, an abbreviation for USBferry.
After the encrypted payload is loaded, the loader injects a malicious DLL into rundll32.exe.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
used built-in Windows commands such as tracert and ping to determine whether the system they are running on has internet connectivity or not.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Frameworks gather information such as computer name, username, domain name, list of running processes, listing of files in directories, drives and network shares, as well as network configuration information
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
“actors used the following commands… to enumerate user accounts: net user >> %temp%\download; net user /domain >> %temp%\download … APT1 used the commands net localgroup, net user, and net group to find accounts… APT32 enumerated administrative users using the commands net localgroup administrators … OilRig has run net user, net user /domain, net group "domain admins" /domain …”
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
The group employs USBferry, a USB malware that performs different commands on specific targets, maintains stealth in environments, and steals critical data through USB storage. | The group achieves infection by employing the USB worm infection strategy and ferrying a malware installer via USB into an air-gapped host machine.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Detects infected machine network topology using ipconfig and arp.
Malware designed to collect information from air-gapped hosts.
Worm that detects infected machine network topology using ipconfig and arp.
Worm malware that uses tasklist to gather process information from infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.