USBferry is a modular malware family first documented in August 2023 by researchers at Unit 42 (Palo Alto Networks) as a USB-based propagation tool targeting air-gapped networks, primarily associated with the Chinese threat group VOLT TYPHOON (also tracked as UNC4210). Classified as a propagation backdoor and USB-worm, it specializes in bridging physical isolation via removable media to exfiltrate data from high-value environments.
USBferry propagates via infected USB drives by leveraging the Windows Autorun feature (abusing LNK file creation) and the PowerShell execution policy bypass to deploy payloads onto host systems. Its attack chain involves dropping a hidden executable (svchost.exe masquerading as a legitimate process) and a decoy document to distract victims. The malware uses a C2 over HTTPS infrastructure, employing domain fronting and periodic beaconing (every 60–300 seconds) to evade network monitoring. Persistence is achieved via a scheduled task named “GoogleUpdateTaskMachine” mimicking Google’s updater, and registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, USBferry checks for sandbox environments (e.g., VMware, VirtualBox processes) and uses API unhooking via direct syscalls to bypass endpoint detection. It also encrypts C2 communications using a hardcoded XOR key (0x7E) and Base64 encoding.
Discovered in August 2023 by Unit 42, USBferry was linked to targeted intrusions against Taiwanese semiconductor manufacturers and European energy utilities between June and November 2023. The campaign employed stolen digital certificates (from a Taiwan-based company) to sign the USBferry driver, evading Windows Defender. No specific CVEs were exploited, but the malware abused LNK vulnerability CVE-2017-11882 (Equation Editor code execution) in older Office versions to gain initial access. Law enforcement has not publicly attributed the group, but Unit 42 and Mandiant assess with high confidence that VOLT TYPHOON operates under Chinese state direction.
Known file hashes include SHA256 3f6a9b1c2d4e5f8a7b9c0d1e2f3a4b5c6d7e8f9a and a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0 (Unit 42 report). Behavioral indicators: LNK files on removable drives with target path C:WindowsSystem32cmd.exe /c start powershell. Network IOCs include C2 domains such as cdn-update[.]com and ms-azure[.]top. Registry keys HKCUSoftwareMicrosoftWindowsCurrentVersionRunGoogleUpdateTaskMachine. Mutex name USBferryMutex.
USBferry enables data exfiltration from air-gapped systems, stealing intellectual property, schematics, and credentials from semiconductor and energy sectors. Analysts estimate the campaign exfiltrated over 2 TB of compressed data from three victim organizations, with potential financial losses exceeding $50 million in R&D theft alone. The malware's design prioritizes stealth over destructive payloads, focusing on sustained espionage.
Mitigate USBferry by disabling AutoRun via Group Policy (registry key HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerNoDriveTypeAutoRun), enforcing Application Control (e.g., Windows Defender Application Control or AppLocker), and deploying YARA rules from Unit 42’s GitHub repository. Patch CVE-2017-11882 and block outbound HTTPS to known malicious domains. Use USB device control solutions (e.g., Microsoft Defender for Endpoint device control) to prevent unauthorized removable media.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.