T1092Techniquecommand-and-controlagent-callable

T1092Communication Through Removable Media

Platforms: Linux · macOS · Windows

ATT&CK version: v19.1

What it is

Adversaries can perform command and control between compromised hosts on potentially disconnected networks using removable media to transfer commands from system to system.(Citation: ESET Sednit USBStealer 2014) Both systems would need to be compromised, with the likelihood that an Internet-connected system was compromised first and the second through lateral movement by [Replication Through Removable Media](https://attack.mitre.org/techniques/T1091). Commands and files would be relayed from the disconnected system to the Internet-connected system to which the adversary has direct access.

ATT&CK tactics· 1

Command And Control

References

  1. https://attack.mitre.org/techniques/T1092
  2. http://www.welivesecurity.com/2014/11/11/sednit-espionage-group-attacking-air-gapped-networks/
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.