Tick__2019__Tick_Group_Weaponized_Secure_USB_Drives_to_Target_Air-Gapped_Critical_Systems.pdf
ID: f0f8b5ae-2e44-48e1-a4dc-025d140d730a
STIX ID: report--f0f8b5ae-2e44-48e1-a4dc-025d140d730a
Threat Score
55/100
Uploaded: 2026-08-19
Published Date: 2019-10-14
Last Modified Date: 2019-10-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 reports a historic Tick Group operation weaponizing secure USB drives to target air-gapped critical Windows systems. The attackers trojanize legitimate software to drop a loader (SymonLoader) that detects a specific secure USB, extracts a hidden payload, and can install additional modules such as HomamDownloader, illustrating a sophisticated USB-based attack against air-gapped environments, though no active campaign is evidenced.
