SPACESHIP — Malware Profile
SPACESHIP is malware developed by APT30 that allows propagation and exfiltration of data over removable devices. APT30 may use this capability to exfiltrate data across air-gaps.
MITRE ATT&CK techniques (6)
- T1052.001 Exfiltration over USB
- T1074.001 Local Data Staging
- T1083 File and Directory Discovery
- T1547.001 Registry Run Keys / Startup Folder
- T1547.009 Shortcut Modification
- T1560.003 Archive via Custom Method