USB drive malware is on the rise, so watch out

A collection of USB drives.
Image Credit: Flickr (Image credit: Pixabay)

Despite an increase in cloud adoption, physical storage drives are once again responsible for hosting malware, new resarch has claimed.

Cybersecurity experts at Mandiant recorded a spike in USB-based incidents during the first half of 2023, with a threefold increase in the number of attacks using USB drives to steal secrets.

Previously, Mandiant had recorded somewhat isolated attacks concentrated on the Philippines, but attacks now look to be spreading globally.

USB malware attacks on the rise

For many, USB drives have had their day. In years gone by, as their popularity soared, cybercriminals capitalized on security weaknesses to spread malware through external drives. Today, attackers have had to become more sophisticated, but it looks like some are reverting to the good old USB drive.

The SNOWYDRIVE malware is one such modern-day example, which gives attackers the ability to remotely issue system commands via a backdoor on the host system. Attributable to UNC4698, the campaign looks to be targeting the oil and gas industries in Asia.

The second, which Mandiant describes as “the most prevalent USB-based cyber espionage attack using USB flash drives,” looks to be targeting both the public and private sectors. Deploying SOGU malware, the attacker seeks to steal sensitive information across the construction, engineering, business services, government, health, transportation, and retail industries in Europe, Asia, and the United States. Analysts have attributed this attack to TEMP.Hex, a China-linked cyber espionage actor.

With attentions turning away from USB-based attacks in favor of protecting victims from more sophisticated attacks, turning back to spreading malware via USB drives could prove fruitful for attackers who are currently great success bypassing many security measures.

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
AI business data center
Cybercriminals are using virtual hard drives to drop RATs in phishing attacks
Android phone malware
Over 25 new malware variants created every single hour as smart device cyberattacks more than double in 2024
Fraud
Hackers are tricking victims into scam-yourself attacks with fake tutorials, CAPTCHAs, and updates
Hands typing on a keyboard surrounded by security icons
Infostealers on the rise: the latest concern for organizational defenses
NordVPN
US hit with over 1.9 billion malware threats last year - here's how to stay safe
An American flag flying outside the US Capitol building against a blue sky
US military and defense contractors hit with Infostealer malware
Latest in Pro
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
Hands typing on a keyboard surrounded by security icons
Your passwords aren't the key to protecting your online identity, your email address is
HP Series 7 Pro 734pm during our review
I reviewed HP's Series 7 Pro 734pm and I'm obsessed with the sheer connectivity of this widescreen monitor
Latest in News
An operator fires a saw blade from a weapon
Call of Duty: Black Ops 6 Season 3 gets two-week delay, will now release in April
Apple iPad A16
Apple's new entry-level iPad ups the performance for the same price, but doesn't support Apple Intelligence
iPad Air M3
Apple updates iPad Air with powerful M3 chip and pairs it with Pro-level Magic Keyboard
Samsung Galaxy Z Flip 6 in blue
The Samsung Galaxy Z Flip 7 might improve on its predecessor in one crucial way
Nvidia RTX 5070 Founders Edition GPU shown against a green and black backdrop
Nvidia RTX 5070 early pricing hints at plenty of GPUs at the MSRP – but I’ll believe it when I see it
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop