Back to blog

USB Drive Phishing: 1 in 2 People Hooked!

B
BlueSecure
Équipe BlueSecure
October 5, 20225 min read
USB Drive Phishing: 1 in 2 People Hooked!

More than 95% of cybersecurity incidents are linked to human error (source: World Economic Forum). This manipulation technique used by cybercriminals is called social engineering, and it aims to persuade users to take action that could compromise the information system.

Furthermore, the rise of digital technology, accelerated by the Covid-19 pandemic, has led to an increase in such incidents. While large companies may once have been considered the primary targets of these attacks, this is no longer the case today. Easy targets because they tend to overlook cyber risks, very small, small and medium-sized businesses are increasingly attracting cyberattackers, who never lack imagination when it comes to deceiving their targets. Email, SMS, QR codes, Wi-Fi access points or USB drives: every means is used in an attempt to access confidential information.

What is USB drive phishing?

USB drive phishing is becoming increasingly widespread. To achieve their goal, hackers place malicious USB drives in strategic locations such as the company car park, entrance hall, employee break area, and more. In short, any public place where a member of the targeted organisation may pass through.

There are three main types of attack:

  • A USB storage drive: This is a standard USB drive containing an apparently harmless file, such as “Salary file.xlsx”, but which includes a malicious script.
  • A USB drive emulating a keyboard: also known as HID (Human Interface Device) spoofing or a Rubber Ducky. In this more sophisticated attack, the device looks exactly like a USB drive, but it actually makes the computer believe that a keyboard is connected. When plugged into a computer, it injects keystrokes to control it and may, for example, allow an attacker to remotely access the victim’s computer.
  • A USB Killer drive: a device that looks like a USB drive but destroys the physical components of any device it is connected to, such as a computer or server. The drive is powered directly by the USB port and stores energy in its capacitors until they reach a certain charge, then releases high-voltage current into the connected device. In 2019, a student who destroyed 60 computers at his university using this method was sentenced to one year in prison.

Simply by connecting a drive, an attacker can therefore launch a multitude of actions that undermine the overall security of the information system. For example:

  • Installing ransomware, which spreads across the network, encrypts data and demands a ransom in exchange for decryption.
  • Retrieving the Wi-Fi key or passwords saved in Chrome.
  • Opening a backdoor: reverse shell, SSH, or installing a tool that enables remote control.
  • Overloading the memory or processor of the affected PC or server in order to paralyse it: also known as a fork bomb.
  • Retrieving Windows passwords and emailing them to the attacker.
  • Disabling the antivirus.
  • Redirecting web traffic…

In short, the possibilities are endless and limited only by the attacker’s imagination.

In our corporate testing campaigns, we observe an average phishing rate of 60% for USB drives deliberately left behind in common areas. This rate can even reach 90% for drives personally addressed to users by post.

Curiosity or the search for the rightful owner are the reasons given by targets to justify inserting an unknown USB drive into their workstation. However, the outcome remains the same: malware has infected the company network.

USB drive phishing

Focus on a USB drive phishing study conducted on a university campus

As part of a study conducted in 2016 by Elie Bursztein (a French cybersecurity researcher at Google), 297 USB drives were scattered across the University of Illinois campus in Urbana-Champaign, United States. He used different types of drives: without labels, with keys, with return labels, marked “confidential” or “exam answers”.
Less than 6 minutes was all it took before the first drive was plugged in. 20% of USB drives were connected within the first hour. In less than 24 hours, 98% of the USB drives had been picked up by participants. In total, 135 of them, or 45%, opened one or more files stored on the USB drives.
Whether motivated by curiosity or altruism, identifying information had very little influence on whether files were opened or USB drives were returned to their owners. In fact, only 54 USB drives, or 18%, were returned to the university’s administrative staff. The figures speak for themselves and demonstrate the significant risk of network infection.

How can you reduce the risks? The BlueSecure solution

As people are the primary risk factor in these attacks, training has become essential. To help you, we offer USB drive phishing simulation campaigns involving the placement of harmless USB drives in common areas such as car parks, break areas or near photocopiers.

We also offer targeted mailings by post. Our USB drives are configured to detect a compromised computer as soon as they are connected, meaning no file needs to be opened. In addition to these tests, we provide educational pages and e-learning courses to raise awareness of social engineering risks.

Feel free to contact us for further information:

CONTACT US

By

B

BlueSecure

Équipe BlueSecure

The BlueSecure team specializes in cybersecurity awareness training and employee security education. With over 10 years of experience, we help organizations protect their most valuable asset: their people.

Share this article