USBFect is a worm that spreads via removable media/USB drives and has been used to propagate the PUBLOAD backdoor across victim environments. Reporting cited here states that USBFect is also referred to as HIUPAN, or is part of the same malware family. In the observed 2025 intrusion activity against a Southeast Asian government organization, Unit 42 assessed that a USB drive containing USBFect was the likely origin of the compromise, after which the malware propagated to multiple endpoints and enabled lateral movement. USBFect was used by the China-linked threat cluster Mustang Panda, also tracked as Stately Taurus, as part of a broader cyberespionage campaign focused on persistent access and data exfiltration. The infection chain associated with USBFect installed malicious components including EVENT.dll (SHA256: 4b29b74798a4e6538f2ba245c57be82953383dc91fe0a91b984b903d12043e92), and related analysis identified the PDB path D:\WorkProject\2023\GJ0215\src\USBInfection\sln\USBFect\Release\USBFect.pdb in an analyzed sample. Supporting reporting describes USBFect as closely related to previously documented HIUPAN malware and notes its role in deploying PUBLOAD, which then supported host information collection and exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mustang Panda notably utilized the USBFect worm to propagate PUBLOAD via infected USB drives, enabling lateral movement and data exfiltration.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Worm used by Mustang Panda to spread PUBLOAD through infected USB drives, facilitating lateral movement and data exfiltration.
A worm that spreads through removable media and is used to propagate PUBLOAD for lateral movement across endpoints.
USB-propagated worm used to spread via removable media and deploy PUBLOAD for lateral movement. It installs components on infected systems, monitors for removable drive insertion, and copies itself to removable media.
The “Stately Taurus” cluster involved tools including HIUPAN, USBFect, PUBLOAD (spread via USB), and CoolClient variants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.