The Lowly USB Drive Remains A Critical Cyberthreat

KnowBe4_USB-2Curtin Franklin at Darkreading correctly observed: "USB thumb drives may be used less frequently than before, but they are still commonly used as infection vectors for a wide variety of malware.

"Small USB sticks can mean big security troubles, according to a new report out today. While USB thumb drives have been overtaken by cloud services as convenient ways to move files from one system to another, they are still commonly used as infection vectors for a wide variety of malware.

"USB threats from malware to miners," published on Kaspersky Labs' SecureList, looks specifically at the threats posed by the pocketable devices. According to the report, the Windows LNK malware family is the top threat, with over 22.7 million attempted WinLNK.Agent infections detected. They affected nearly 900,000 users in 2017 and, so far, just over 700,000 users in an estimated 23 million attacks in 2018.

"USB devices may be less effective at spreading infection than in the past, due to growing awareness of their security weakness and declining use as a business tool, but our research shows they remain a significant risk that users should not underestimate," said Denis Parinov, anti-malware researcher at Kaspersky Lab, said in a prepared statement. 

Because USB sticks continue to get the work of carrying malware done, they have been frequent infection vehicles for malware families dating back as far as five years, according to the report. They are not simply vehicles for malicious nostalgia, though; the report notes that the USB payload can include cryptominers (often piggybacking on Trojans known since at least 2014).

The report concludes with advice for minimizing the chances of malware infection through a USB drive. That includes being careful with unknown USB devices, investing in encrypted USB drives when they are necessary for business use, and putting a plan in place for checking every USB device (and every file on them) for malware prior to the files being transferred to any production machine." Full article at DarkReading

Did you know? On average 45% of your users will plug in USBs...

Find out now what your user’s reactions are to unknown USBs, with KnowBe4's new Free USB Security Test.

You can download our special, "beaconized" file onto any USB drive. Then label the drive with something enticing and drop the drive at an on-site high traffic area. If an employee picks it up, plugs it in their workstation and opens the file, it will "call home" and report the "fail" to your KnowBe4 console. And for Office documents, if the user also enables macros (!), additional data is tracked and geomapped.


How your free 7-day USB Security Test works:

checkmark Fill out the form on the right, and immediately...

checkmark Download "beaconized" Word, Excel or PDF files

checkmark Copy to any USB Drive, label and drop it

checkmark Reports on opens and if macros were enabled

checkmark Takes just a few minutes to setup

This is fun to do. Get your USB Security Test here:

Related Pages: Security Awareness Training

Subscribe To Our Blog

Weak Password Test Contest

Get the latest about social engineering

Subscribe to CyberheistNews