Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 19:50:16 UTC Home > List all groups > List all tools > List all groups using tool USBStealer Tool: USBStealer Names USBStealer Win32/USBStealer USB Stealer Category Malware Type Info stealer Description USBStealer is malware that has used by APT28 since at least 2005 to extract information from air-gapped networks. It does not have the capability to communicate over the Internet and has been used in conjunction with Sedreco. Information MITRE ATT&CK Last change to this tool card: 30 December 2022 Download this tool card in JSON format All groups using tool USBStealer Changed Name Country Observed APT groups Sofacy, APT 28, Fancy Bear, Sednit 2004-Apr 2025 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b78b2cb2-cb57-4f65-aee2-4c0ec0f6667f https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b78b2cb2-cb57-4f65-aee2-4c0ec0f6667f Page 1 of 1