HomeSecurityHackers distribute USB malware via websites

Hackers distribute malicious USB software via websites

Financially motivated hackers using USB devices for initial infection have been found to abuse legitimate online platforms, such as GitHub, Vimeo, and Ars Technica, to host encrypted payloads embedded in seemingly innocent content.

See also: Microsoft: Adds a USB4 troubleshooting page to Windows 11
Hackers

Attackers by placing them in user profiles on tech news website forums or in video descriptions on media hosting platforms.

These payloads pose no threat to users visiting these websites, as they are plain text. However, when embedded in the campaign attack chain, they are critical for downloading and executing malware in attacks.

The hackers responsible for this campaign are tracked by Mandiant as UNC4990 and have been active since 2020, primarily targeting users in Italy.

The attack begins when victims double-click a malicious LNK shortcut file on a USB drive. It is not known how the malicious USB devices reach the targeted victims to initiate the attack chain.

When the shortcut is executed, a PowerShell script named explorer.ps1, which decodes a payload that corresponds to a URL used to download and install the malware named 'EMPTYSPACE'.

These intermediate payloads are alphanumerics that are converted to a URL to download the next payload: EMPTYSPACE.

The UNC4990 hackers tried several approaches to hosting intermediate payloads, initially using encoded text files on GitHub and GitLab and later switching to abusing Vimeo and Ars Technica to host Base64-encoded and AES-encrypted string payloads.

See also: Microsoft is testing 80Gbps USB Support and Copilot in Windows 11

USB malware

According to Mandiant, the attackers are not exploiting a vulnerability on these sites, but are simply using normal site features, such as an About on an Ars Technica forum profile or a video description on Vimeo, to secretly host the obfuscated payload without anyone suspecting it.

Furthermore, these payloads do not directly threaten visitors to the abused websites, as they are simply harmless text strings, and all cases recorded by Mandiant have been removed from the affected intermediary platforms.

The advantageous practice of hosting loads on legitimate and trusted platforms is that they are considered trusted by security systems, reducing the likelihood of being flagged as suspicious.

Additionally, threat actors benefit from resilient content delivery platforms and enjoy resistance to degaussing.

Embedding payloads inside legitimate content and mixing them with large volumes of legitimate traffic makes it harder to detect and remove the malicious code. Even then, attackers can easily re-inject it into a different platform that supports publicly visible comments or profiles.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: We test the new Apple Pencil with USB-C

How can one protect themselves from USB malware payloads?

To protect yourself from USB malware payloads, you should first be careful with the USBs you use. Do not use USB sticks that you find or whose origin you do not know.

Additionally, use security software that provides real-time protection and includes malware. This could help you discover and remove any malware attacks before they cause damage.

Additionally, disable autorun on your computer. Many USB malware payloads rely on autorun to infect a computer.

Finally, keep your operating system and security software up to date. Updates often include fixes for vulnerabilities that malware can exploit.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS