Rare BadUSB Attack Detected In The Wild Against US Hospitality Provider

A US hospitality provider has recently been the target of an incredibly rare BadUSB attack, ZDNet has learned from cyber-security firm Trustwave.

The attack happened after the company received an envelope containing a fake BestBuy gift card, along with a USB thumb drive.

The receiving company was told to plug the USB thumb drive into a computer to access a list of items the gift card could be used for.

BadUSB letter
Image: Trustwave

But in reality, the USB thumb drive was what security experts call a "BadUSB" -- a USB thumb drive that actually functions as a keyboard when connected to a computer, where it emulates keypresses to launch various automated attacks.

Trustwave, who couldn't reveal the target company's name for confidentiality reasons, said the victim recognized the attempted hack and called it in to investigate the incident.

In a report published today and shared with ZDNet, Trustwave said that once they plugged the BadUSB into a test workstation, the BadUSB triggered a series of automated keypresses that launched a PowerShell command.

This Powershell command downloaded a bulkier PowerShell script from an internet site and then installed malware on the test machine -- a JScript-based bot.

badusb-attack.png
Image: Trustwave

"At the time of the analysis, we did not found a similar strain of malware," Phil Hay, Senior Research Manager at Trustwave, told ZDNet in an email yesterday.

"The malware is unknown to us. It is also hard to say if it is custom-built, but it probably is, because it is not wide spread and seems to be targeted," Hay added.

However, the Trustwave researcher also told us that since their initial analysis, a file similar to the malware they analyzed was later uploaded on VirusTotal, a web-based file scanning engine. Per subsequent analysis from Facebook and Kaspersky researchers, the file is believed to be the work of a hacking group known as FIN7.

It is unclear who uploaded this file, or if it comes from another cyber-security vendor also investigating a BadUSB attack at another victim.

But the lesson here is that someone actually detected a BadUSB attack in the real world. BadUSB attacks were first detailed at the end of the 2000s, and for many years they represented a theoretical attack scenario, something that employees are often warned about, but which has rarely been seen in the wild.

"These sorts of [BadUSB] attacks are often simulated in penetration testing and used during red teaming exercises," Hay told ZDNet. "Seeing these types of attacks in the real world is much more rare."

Last known attack happened two years ago in Eastern Europe

The last known case of a BadUSB attack -- also known as a Bash Bunny attack -- was detailed in December 2018 by Russian cyber-security firm Kaspersky.

At the time, the company said it found BadUSB devices, along with cheap laptops and Raspberry Pi boards, on location at eight banks in Eastern Europe. The banks called Kaspersky to investigate a series of mysterious cyber-heists during which hackers stole tens of millions of dollars.

RECENT NEWS

Reassessing AI Investments: What The Correction In US Megacap Tech Stocks Signals

The recent correction in US megacap tech stocks, including giants like Nvidia, Tesla, Meta, and Alphabet, has sent rippl... Read more

AI Hype Meets Reality: Assessing The Impact Of Stock Declines On Future Tech Investments

Recent declines in the stock prices of major tech companies such as Nvidia, Tesla, Meta, and Alphabet have highlighted a... Read more

Technology Sector Fuels U.S. Economic Growth In Q2

The technology sector played a pivotal role in accelerating America's economic growth in the second quarter of 2024.The ... Read more

Tech Start-Ups Advised To Guard Against Foreign Investment Risks

The US National Counterintelligence and Security Center (NCSC) has advised American tech start-ups to be wary of foreign... Read more

Global IT Outage Threatens To Cost Insurers Billions

Largest disruption since 2017’s NotPetya malware attack highlights vulnerabilities.A recent global IT outage has cause... Read more

Global IT Outage Disrupts Airlines, Financial Services, And Media Groups

On Friday morning, a major IT outage caused widespread disruption across various sectors, including airlines, financial ... Read more