HomeSecurityFBI: Hackers sending malicious USB drives via USPS

FBI: Hackers sending malicious USB drives via USPS

Hackers from the FIN7 cybercrime group have targeted several businesses with malicious USB devices that act as keyboards when plugged into a computer. The injected commands download and execute a JavaScript backdoor associated with this hacker.

In a warning on Thursday, the FBI is warning organizations and security professionals about this tactic adopted by FIN7 to deliver the GRIFFON malware.

The attack is a variation of the “lost USB” ruse that penetration testers have been using for several years in their assessments quite successfully, and one incident was analyzed by Trustwave researchers

A cybersecurity company customer received a package, supposedly from Best Buy, containing a $50 rewards gift card. Inside the envelope was a USB drive that claimed to contain a list of products eligible for purchase using the gift card.

However, this is not a one-off incident.

The FBI warns that FIN7 has sent these packages to many businesses (retail, restaurants, hotels) where they target employees in human resources, IT departments, or management.

“Recently, the FIN7.1 cyber group, known for targeting such businesses via phishing emails,has used an additional tactic of sending USB devices via the United States Postal Service (USPS). The packages sometimes include items such as teddy bears or gift cards to employees of targeted companies who work in the Human Resources, Information Technology (IT), or Executive Management (EM) departments,” the FBI warning states.

The FBI says the malicious module is configured to emulate keystrokes that launch a PowerShell command to retrieve malware from servers controlled by the attacker. The USB device then communicates with domains or IP addresses in Russia.

The days when USB flash drives were just for storage are long gone. Several development boards (Teensy, Arduino) are now available for programming to emulate a human interface device (HID) such as keyboards and mice and trigger a predefined set of keystrokes to drop malicious payloads. These are called HID or USB drive-by attacks which are easy to carry out and do not cost much.

Trustwave analyzed this malicious USB activity and found two PowerShell commands that resulted in a fake error and ultimately the execution of third-stage JavaScript that can collect system information and download other malware.

To better summarize the attack flow, the researchers created the following image, which clarifies the stages of compromise that led to the development of malware of the attacker's choice.

FBI: Hackers sending malicious USB drives via USPS

The FBI alert states that after the identification phase, the hacker begins to move laterally, seeking admin.

FIN7 uses multiple tools to achieve its goal. The list includes Metasploit, Cobalt Strike, PowerShell scripts, Carbanak malware, Griffon backdoor, Boostwrite malware dropper, and RdfSniffer module with remote access.

BadUSB attacks, first demonstrated by security researcher Karsten Nohl in 2014, are now common in penetration testing , and there are many alternatives these days. The most flexible ones sell for around $100.

FIN7 went with a simple and cheap version, however, costing between $5-$14, depending on the vendor and the country of shipment. The FBI notes in its warning that the microcontroller is an ATMEGA24U, while the one Trustwave is looking at had an ATMEGA32U4.

However, both variants were printed on the “HW-374” circuit board and are identified as an Arduino Leonardo, which is specifically programmed to function as a keyboard/mouse. Customization of the buttons and mouse movements is possible using the Arduino IDE.

Connecting unknown USB devices to a workstation is a well-known security risk, but it is still ignored by many users.

Organizations can take precautions against attacks via malicious USB drives by only allowing access to devices that are verified based on their hardware ID and denying access to all others.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS