logo

Tick__2019__Tick_Group_Weaponized_Secure_USB_Drives_to_Target_Air-Gapped_Critical_Systems.pdf

ID: f0f8b5ae-2e44-48e1-a4dc-025d140d730a

STIX ID: report--f0f8b5ae-2e44-48e1-a4dc-025d140d730a

Threat Score

55/100

Uploaded: 2026-08-19

Published Date: 2019-10-14

Last Modified Date: 2019-10-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 reports a historic Tick Group operation weaponizing secure USB drives to target air-gapped critical Windows systems. The attackers trojanize legitimate software to drop a loader (SymonLoader) that detects a specific secure USB, extracts a hidden payload, and can install additional modules such as HomamDownloader, illustrating a sophisticated USB-based attack against air-gapped environments, though no active campaign is evidenced.