Chinese Spies Infected Dozens of Networks With Thumb Drive Malware

Stu Sjouwerman | Sep 21, 2023

USB Based Ransomware AttackWIRED just published an article that made me both disappointed and surprised at the same time. Security researchers found USB-based Sogu espionage malware spreading within African operations of European and US firms.

Yup, you read that right: USB-based malware.

Here is a quick summary with a link to the full article at WIRED. The upshot? You still need to train your global workforce on the risks of them good 'ol USB sticks...

The cybersecurity firm Mandiant has uncovered a resurgence in USB-based malware attacks led by a China-linked hacker group called UNC53. This group has successfully hacked at least 29 global organizations since last year by social engineering employees into using malware-infected USB drives.

Many of these attacks have originated from the African operations of multinational companies in countries like Egypt, Zimbabwe, and Kenya. The malware used is a decade-old strain known as Sogu, which has been involved in significant cyber-espionage activities in the past.

The campaign is especially effective in regions where USB drives are still commonly used, like Africa. Mandiant found that the malware often spreads from shared computers in places like internet cafés, affecting various sectors including consulting, banking, and government agencies. The malware uses clever tactics to infect machines, even those without internet connections, and communicates with a command-and-control server to steal data.

Mandiant researchers note that this indiscriminate method allows the hackers to cast a wide net, sorting through victims for high-value targets later. The campaign highlights the need for organizations to remain vigilant against all forms of cyber threats, even those considered outdated. This is particularly important for global networks that include operations in developing countries, where older technologies like USB drives are still in use. Train your workforce!

Full article at WIRED: https://www.wired.com/story/china-usb-sogu-malware/

Ready to Build a Security Culture That Lasts?

Stop treating training like a checkbox exercise. Using 15+ years of behavioral data, our AI-powered platform personalizes training for every user to significantly reduce human risk and stop attacks before they start.

Get a Quote

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.