Netskope Threat Labs

LitterDrifter

ATP Sandbox Adv. Heuristics

LitterDrifter is a worm that spreads through USB drives and uses recycled command and control infrastructure, which Check Point researchers linked to espionage against Russian and Ukrainian targets. Its removable drive propagation and modular design indicate an operator focused on persistent collection rather than ransom demands.

First seen
January 2024
Last seen
October 2026
Alert Name
Script-PowerShell.Dropper.LitterDrifter
Script-WScript.Trojan.LitterDrifter