TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

Attacking Air-Gap-Segregated Computers

2018-09-05 · Read original ↗

ATT&CK techniques detected

3 predictions
T1091Replication Through Removable Media
96%
"of highly - valuable intellectual property, and the supervisory control and data acquisition ( scada ) systems that control water and power systems. cryptocurrencies like bitcoin and ethereum also make use of air - gapped storage systems called cold wallets to securely store the …"
T1091Replication Through Removable Media
80%
"gapped targets. 7 another way to compromise an air - gapped system is to “ pre - penetrate ” it before it ends up in the air gap by sabotaging it ’ s supply chain. it ’ s not unusual for an advanced attacker to study their victim and determine their technical infrastructure. then…"
T1052.001Exfiltration over USB
58%
"it. exfiltrating from the air gap assuming the mission isn ’ t destruction ( stuxnet ) or ransomware, then the real trick is getting the stolen data out. if the attacker used a usb stick to get the malware in, they could use the same method to get it out. the infamous leaker chel…"

Summary

Computers disconnected from the wire can still be compromised using advanced, off-the-shelf tools.