# T1091 Replication Through Removable Media

> As of 2026-10-05, T1091 (Replication Through Removable Media) appears in 38 tracked threats, first reported 2026-02-16 and most recently 2026-09-18, with linked actors including Gamaredon, APT28, APT36; it most often appears alongside T1082 (System Information Discovery).

- **Tracked threats:** 38 (8 critical, 24 high, 5 medium, 1 low)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-18
- **Threat actors:** 14
- **Detection rules:** 54 (counts only; Blue tier and above)

## Key facts

- **ID:** T1091
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access, Lateral Movement
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1091/

## Activity timeline

T1091 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-18. The busiest month was 2026-06 with 8 reports, and 38 of the 38 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1091 Replication Through Removable Media is catalogued by MITRE ATT&CK under the Initial Access and Lateral Movement tactics in the Enterprise matrix. Threadlinqs maps 38 of 2623 tracked threats (1.4%) to it; by severity that is 8 critical, 24 high, 5 medium, 1 low.

Threats that use T1091 most often also use [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (24 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (21 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (20 threats), [T1083 File and Directory Discovery](https://intel.threadlinqs.com/technique/T1083) (17 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

14 tracked threat actors appear in the threats that use T1091; the most frequent are [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) (4), [APT28](https://intel.threadlinqs.com/actor/APT28) (2), [APT36](https://intel.threadlinqs.com/actor/APT36) (2), [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) (2), [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) (2).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1091.

- [M1034 Limit Hardware Installation](https://attack.mitre.org/mitigations/M1034/)
- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1091, per MITRE ATT&CK.

- Drive — Drive Creation
- File — File Access, File Creation
- Process — Process Creation

## Threat actors using it

- [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon) — 4
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 2
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 2
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 2
- [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) — 2
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [APT42](https://intel.threadlinqs.com/actor/APT42) — 1
- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 1
- [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) — 1
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 1
- [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) — 1

## Tracked threats

The 30 most recent of 38 tracked threats that use T1091.

- [AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and…](https://intel.threadlinqs.com/threat/TL-2026-2559) — medium — 2026-09-18
- [Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…](https://intel.threadlinqs.com/threat/TL-2026-2545) — high — 2026-09-16
- [Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International…](https://intel.threadlinqs.com/threat/TL-2026-2303) — medium — 2026-09-02
- [Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholing](https://intel.threadlinqs.com/threat/TL-2026-2284) — high — 2026-09-01
- [Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM Jackpotting Plot](https://intel.threadlinqs.com/threat/TL-2026-2275) — low — 2026-08-31
- [UniBLEed: Unauthenticated Root RCE Chain Over Bluetooth in Unitree G1 EDU Humanoid Robot (CVE-2026-76639…](https://intel.threadlinqs.com/threat/TL-2026-2196) — critical — 2026-08-28
- [GEEKOM Mini PC Legacy Support Page Distributed Trojanized Realtek LAN Driver Infected with Asruex](https://intel.threadlinqs.com/threat/TL-2026-2059) — medium — 2026-08-18
- [StopAndProtect: Compromised WordPress Sites Used as Malware Distribution Infrastructure for Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-2057) — high — 2026-08-18
- [Pixel 10 VPU Driver mmap Boundary-Check Flaw Enables Root Exploit Chain (CVE-2025-54957)](https://intel.threadlinqs.com/threat/TL-2026-1544) — critical — 2026-07-19
- [GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG…](https://intel.threadlinqs.com/threat/TL-2026-1508) — high — 2026-07-19
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [July 2026 Patch Tuesday: Two Actively Exploited Microsoft Zero-Days (SharePoint EoP CVE-2026-56164, AD FS…](https://intel.threadlinqs.com/threat/TL-2026-1339) — high — 2026-07-14
- [Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)](https://intel.threadlinqs.com/threat/TL-2026-1298) — high — 2026-07-14
- [Counterfeit China-Made USB Drives with Self-Replicating Malware Infect 50+ Japan Ground Self-Defense Force…](https://intel.threadlinqs.com/threat/TL-2026-1240) — high — 2026-07-11
- [Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now…](https://intel.threadlinqs.com/threat/TL-2026-1210) — high — 2026-07-11
- [Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flash](https://intel.threadlinqs.com/threat/TL-2026-1200) — high — 2026-07-11
- [Blackfield (BlackFL) Ransomware Demands $2 Million from Nidec Chaun-Choung Technology Corporation (Nidec…](https://intel.threadlinqs.com/threat/TL-2026-1196) — high — 2026-06-30
- [Gamaredon Expands Ukraine Attacks with PteroSetup Revival and Cloud Service Abuse, Exploiting WinRAR Flaw…](https://intel.threadlinqs.com/threat/TL-2026-1216) — high — 2026-06-29
- [Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2…](https://intel.threadlinqs.com/threat/TL-2026-0968) — high — 2026-06-28
- [usbliter8 — Unpatchable SecureROM Boot-Chain Code Execution on Apple A12/A13 (and S4/S5) SoCs via DWC2 USB…](https://intel.threadlinqs.com/threat/TL-2026-0876) — high — 2026-06-19
- [usbliter8 — checkm8-style unpatchable BootROM/SecureROM exploit for Apple A12/A13 (and S4/S5) devices](https://intel.threadlinqs.com/threat/TL-2026-0871) — high — 2026-06-19
- [usbliter8 — Unpatchable BootROM USB DMA Exploit on Apple A12/A12X/A12Z/A13 and S4/S5 Chips Bypassing Secure…](https://intel.threadlinqs.com/threat/TL-2026-0860) — critical — 2026-06-18
- [CryptoBandits Windows Crypto-Clipper Campaign: USB LNK Worm + Tor Hidden-Service C2…](https://intel.threadlinqs.com/threat/TL-2026-0854) — high — 2026-06-18
- [Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver…](https://intel.threadlinqs.com/threat/TL-2026-0653) — high — 2026-06-02
- [Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US…](https://intel.threadlinqs.com/threat/TL-2026-0612) — high — 2026-05-28
- [DeepLoad Fileless Loader — ClickFix Delivery, APC Injection into LockAppHost.exe, USB .lnk Worm and…](https://intel.threadlinqs.com/threat/TL-2026-0558) — high — 2026-05-22
- [ExifTool macOS Command Injection CVE-2026-3102 — Malicious Image Metadata Triggers system() Sink via…](https://intel.threadlinqs.com/threat/TL-2026-0539) — high — 2026-05-20
- [YellowKey & GreenPlasma — Unpatched Windows BitLocker Bypass & CTFMON LPE Zero-Days With Public PoC…](https://intel.threadlinqs.com/threat/TL-2026-0512) — critical — 2026-05-13
- [ZionSiphon — Ideologically Motivated .NET OT Malware Targeting Israeli Water & Desalination Infrastructure…](https://intel.threadlinqs.com/threat/TL-2026-0458) — critical — 2026-05-05
- [CVE-2026-32202 — Windows Shell Protection Mechanism Failure: NTLM Authentication Coercion via Auto-Parsed…](https://intel.threadlinqs.com/threat/TL-2026-0435) — critical — 2026-04-29

## Related CVEs

CVEs referenced by the tracked threats that use T1091, most frequent first.

- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2025-54957](https://intel.threadlinqs.com/cve/CVE-2025-54957)
- [CVE-2026-21510](https://intel.threadlinqs.com/cve/CVE-2026-21510)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-3102](https://intel.threadlinqs.com/cve/CVE-2026-3102)
- [CVE-2026-32202](https://intel.threadlinqs.com/cve/CVE-2026-32202)
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-57092](https://intel.threadlinqs.com/cve/CVE-2026-57092)
- [CVE-2026-76639](https://intel.threadlinqs.com/cve/CVE-2026-76639)

## Detection coverage

Threadlinqs maintains 54 detection rules mapped to T1091 (SPL 18, KQL 21, Sigma 15). Rule content is available to Blue tier accounts and above; this page shows counts only.

54 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1091
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
