According to a new report from cybersecurity firm Mandiant, USB devices are being used to compromise targets in Southeast Asia.
See also: Symoo: Fake app that automatically creates accounts

USB devices are an initial access vector that is not used as often because it requires physical access to the target device, which can be provided by an employee without their knowledge.
The FBI recently announced that cybercriminals are now mailing Americans USB drives loaded with malware. If these devices are plugged into a computer, they give the criminals access to that person's network.
The new campaign in Southeast Asia began in September 2021, according to a post published Monday by Mandiant Managed Defence.
Researchers have found that the group behind the hack is targeting entities in the Philippines. They believe this group has some connection to China, although they can't say for sure that it is state-sponsored.
See also: GameStop: Data leak was a test, not real
The campaigns conducted by the threat actor – tracked as UNC4191 – “impacted a range of public and private sector entities primarily in Southeast Asia and are expanding to the US, Europe and APJ [Asia Pacific Japan],” the researchers said.
The systems targeted by UNC4191 were located in the Philippines, even though the organizations themselves were based elsewhere.
After initial infection via USB devices, hackers use signed binaries to load malware onto target computers.
Mandiant has discovered three new malware families, known as MISTCLOAK, DARKDEW, and BLUEHAZE.

These provide a reverse shell to the victim's system, giving the UNC4191 hackers backdoor access. The malware then replicated itself by infecting any new removable drives connected to the compromised computers, allowing the malware to spread even to air-gapped systems.
See also: Hackers stole 'tens of thousands' of euros from Carndonagh Traders Association
The researchers said that since the malware is still evolving, they may have only detected the later stages of its proliferation.
The campaign aims to illegally access public and private entities with the aim of obtaining information that will benefit China's political and commercial interests.
Based on the number of compromised systems located in that country and identified by Mandiant, it appears that the main targets of the operation are in the Philippines.
Source of information: therecord.media
