Adversaries can perform command and control between compromised hosts on potentially disconnected networks using removable media to transfer commands from system to system.(Citation: ESET Sednit USBStealer 2014) Both systems would need to be compromised, with the likelihood that an Internet-connected system was compromised first and the second through lateral movement by [Replication Through Removable Media](https://attack.mitre.org/techniques/T1091). Commands and files would be relayed from the disconnected system to the Internet-connected system to which the adversary has direct access.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Cross-host C2 via Removable Media Relay
is blocked by Disable or Remove Feature or Program
is blocked by Operating System Configuration
is blocked by Asset Inventories
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Media Use
is blocked by Malicious Code Protection (Anti-Malware)
is blocked by Vulnerability Scanning
Impressum German English