Peripheral Device Discovery, Technique T1120 - Enterprise (original) (raw)

S1167

AcidPour

AcidPour includes functionality to identify MMC and SD cards connected to the victim device.[3]

S0045

ADVSTORESHELL

ADVSTORESHELL can list connected devices.[4]

G0007

APT28

APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim.[5]

G0067

APT37

APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices. [6]

S0438

Attor

Attor has a plugin that collects information about inserted storage devices, modems, and phone devices.[7]

G0135

BackdoorDiplomacy

BackdoorDiplomacy has used an executable to detect removable media, such as USB flash drives.[8]

S0128

BADNEWS

BADNEWS checks for new hard drives on the victim, such as USB devices, by listening for the WM_DEVICECHANGE window message.[9][10]

S0234

Bandook

Bandook can detect USB devices.[11]

S0089

BlackEnergy

BlackEnergy can gather very specific information about attached USB devices, to include device instance ID and drive geometry.[12]

S0454

Cadelspy

Cadelspy has the ability to steal information about printers and the documents sent to printers.[13]

S1149

CHIMNEYSWEEP

CHIMNEYSWEEP can monitor for removable drives.[14]

S0115

Crimson

Crimson has the ability to discover pluggable/removable drives to extract files from.[15][16]

S0538

Crutch

Crutch can monitor for removable drives being plugged into the compromised machine.[17]

S0673

DarkWatchman

DarkWatchman can list signed PnP drivers for smartcard readers.[18]

S0062

DustySky

DustySky can detect connected USB devices.[19]

S9038

DynoWiper

DynoWiper has enumerated and overwritten files on all removeable and fixed drives.[20]

G0020

Equation

Equation has used tools with the functionality to search for specific information about the attached hard drive that could be used to identify and overwrite the firmware.[21]

S0679

Ferocious

Ferocious can run GET.WORKSPACE in Microsoft Excel to check if a mouse is present.[22]

S0381

FlawedAmmyy

FlawedAmmyy will attempt to detect if a usable smart card is current inserted into a card reader.[23]

S1044

FunnyDream

The FunnyDream FilepakMonitor component can detect removable drive insertion.[24]

G0047

Gamaredon Group

Gamaredon Group tools have contained an application to check performance of USB flash drives. Gamaredon Group has also used malware to scan for removable drives.[25][26][27]

S1027

Heyoka Backdoor

Heyoka Backdoor can identify removable media attached to victim's machines.[28]

S1230

HIUPAN

HIUPAN has checked periodically for removable drives and installs itself when a drive is detected.[29][30]

S1139

INC Ransomware

INC Ransomware can identify external USB and hard drives for encryption and printers to print ransom notes.[31]

S0283

jRAT

jRAT can map UPnP ports.[32]

S1199

LockBit 2.0

LockBit 2.0 has the ability to identify mounted external storage devices.[33]

S1202

LockBit 3.0

LockBit 3.0 has the ability to discover external storage devices.[34]

S0409

Machete

Machete detects the insertion of new devices by listening for the WM_DEVICECHANGE window message.[35]

S1026

Mongall

Mongall can identify removable media attached to compromised hosts.[28]

S0149

MoonWind

MoonWind obtains the number of removable drives from the victim.[36]

S1090

NightClub

NightClub has the ability to monitor removable drives.[37]

S0385

njRAT

njRAT will attempt to detect if the victim system has a camera during the initial infection. njRAT can also detect any removable drives connected to the system.[38][39]

S0644

ObliqueRAT

ObliqueRAT can discover pluggable/removable drives to extract files from.[40]

G0049

OilRig

OilRig has used tools to identify if a mouse is connected to a targeted system.[41]

C0012

Operation CuckooBees

During Operation CuckooBees, the threat actors used the fsutil fsinfo drives command as part of their advanced reconnaissance.[42]

C0014

Operation Wocao

During Operation Wocao, threat actors discovered removable disks attached to a system.[43]

S0013

PlugX

PlugX can identify removable media attached to compromised hosts.[44]

S0113

Prikormka

A module in Prikormka collects information on available printers and disk drives.[45]

S0650

QakBot

QakBot can identify peripheral devices on targeted systems.[46]

S0686

QuietSieve

QuietSieve can identify and search removable drives for specific file name extensions.[47]

S0481

Ragnar Locker

Ragnar Locker may attempt to connect to removable drives and mapped network drives.[48]

S0458

Ramsay

Ramsay can scan for removable media which may contain documents for collection.[49][50]

S1150

ROADSWEEP

ROADSWEEP can identify removable drives attached to the victim's machine.[14]

S0148

RTM

RTM can obtain a list of smart card readers attached to the victim.[51][52]

S1089

SharpDisco

SharpDisco has dropped a plugin to monitor external drives to C:\Users\Public\It3.exe.[37]

S0603

Stuxnet

Stuxnet enumerates removable drives for infection.[53]

S1064

SVCReady

SVCReady can check for the number of devices plugged into an infected host.[54]

S0098

T9000

T9000 searches through connected drives for removable storage devices.[55]

S0467

TajMahal

TajMahal has the ability to identify connected Apple devices.[56]

G0139

TeamTNT

TeamTNT has searched for attached VGA devices using lspci.[57]

S0647

Turian

Turian can scan for removable media to collect data.[8]

G0010

Turla

Turla has used fsutil fsinfo drives to list connected drives.[58]

S0452

USBferry

USBferry can check for connected USB devices.[59]

S0136

USBStealer

USBStealer monitors victims for insertion of removable drives. When dropped onto a second victim, it also enumerates drives connected to the system.[60]

G1017

Volt Typhoon

Volt Typhoon has obtained victim's screen dimension and display device information.[61]

S0366

WannaCry

WannaCry contains a thread that will attempt to scan for new attached drives every few seconds. If one is identified, it will encrypt the files on the attached device.[62]

S0612

WastedLocker

WastedLocker can enumerate removable drives prior to the encryption process.[63]

S0251

Zebrocy

Zebrocy enumerates information about connected storage devices.[64]