According to Honeywell Industrial Cybersecurity 's USB Threat 2020 report , released this week, there is a significant increase in attacks carried out via USB against industrial control systems.

The report includes data from the company’s Secure Media Exchange (SMX) USBover the past twelve months. The data comes from companies operating in the oil and gas, power, chemical, food, marine, buildings, aerospace, paper and construction industries in 60 countries across the Americas, Europe and Asia.
As the data analysis showed, at least one threat was discovered on 45% of industrial websites using the product, a number that represents an increase from the 44% found in the company's previous report in 2018.
Of the malware discovered, 11% was specifically designed to target industrial systems. However, 59% of the malware detected could cause significant problems in the operation of industrial systems, compared to just 26% discovered in the previous survey. However, the 11% figure increases to 28% when ransomware, which is increasingly targeting operational technology (OT) systems, is also taken into account.

Malware found on USB devices can lead to DoS, cause loss of visibility into operations management networks, and destroy or disrupt key system.
The malware that has seen the biggest increase in recent times are trojans, worms, rootkits and viruses. In contrast, there has been a decrease in potentially unwanted applications (PUAs), non-targeted bots, spyware, adware and hacking.
The most prevalent threats observed by the company were RATs, backdoors , and droppers.
As Honeywell stated: “This makes sense: in industrial environments, where network access is difficult, gaining access via USB to establish remote access and download new malware is a good strategy for an attacker.”.
