Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

3/25/2016
04:30 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

Dangerous New USB Trojan Discovered

'USB Thief' could be used for targeted purposes, researchers at ESET say.

The Internet and the growing interconnectedness of networks have made it incredibly easy for threat actors to deliver and propagate malware. But not all cyber threats are Internet-borne.

Take USB Thief, new malware sample that researchers at security firm ESET recently discovered.  As its name implies, the malware is completely USB-borne, meaning it spreads exclusively through devices that plug into the USB port of computers.

This data-stealing Trojan could be used for targeted attacks on systems disconnected from the Internet. Some obvious examples of air-gapped systems that would fall into this category, and that would be of interest to the authors of USB Thief, would be industrial control systems controlling equipment at critical infrastructure facilities including power plants, nuclear facilities, shipyards, and elsewhere.

Based on the malware sample that ESET analyzed, the only way the malware would propagate is by the attacker installing it on other USB devices, says Bruce Burrell, a security researcher at ESET. "Users might be exposed by finding such sticks and inserting them into their computers."

The highly destructive Stuxnet worm that was used to degrade and destroy hundreds of centrifuges at Iran’s uranium enrichment facility at Natanz a few years ago was, in fact, initially introduced into the systems via an infected USB stick.

ESET did not disclose how it discovered USB Thief. But ESET describes it as very sophisticated, especially for its ability to avoid detection and reverse engineering.

The malware attaches as a plugin or a dynamically linked library (DLL) into the command chain of applications that are typically stored on USB devices, like Firefox, Notepad++, and TrueCrypt, ESET security researcher Tomas Gardon said in the blog post announcing the discovery.

Whenever these applications are executed, the malware runs in the background and steals data without giving users an inkling of what’s going on. Because it exists on a USB stick, the malware leaves no trace of its presence on any computer on which it runs. 

USB Thief’s real difference, though, lies in its self-protecting capabilities, according to Gardon. For starters, each malware sample is tied directly to the specific USB stick on which it is installed. A sample of USB Thief from one USB will not run if it is copied and pasted on another device.

That’s because of the way the authors have ensured that filenames would be different for every instance of USB Thief, Gardon said. Among other things, one of the filenames in the malware execution chain is linked to the file creation time, so any sample that is copied from an original would have a different file creation time and therefore would not work, the security researcher said.

In addition, some of the individual files in the malware are protected via AES128 encryption, where the encryption key is tied to the USB’s unique device ID and the particular disk properties of the device hosting the malware. As a result, the malware will only run on that specific device.

The file-naming techniques and encryption used in USB Thief make it extremely hard to disassemble and to study, Gardon said.

An analysis of USB Thief’s payload shows that it is designed to steal images, documents, and generally all data files on the system as well as the Windows registry tree, a complete list of files from all drives on the system. It then encrypts the stolen data.

The malware does not appear to be very widespread at the moment. But its payload can be easily changed so instead of data stealing it can be used for some other malicious purposes, Gardon said in his post.

 Related Content:

Interop 2016 Las VegasFind out more about security threats at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Click here for pricing information and to register.

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
batye
50%
50%
batye,
User Rank: Apprentice
3/25/2016 | 11:07:42 PM
interesting to know
interesting to know thank you 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/29/2016 | 10:35:41 AM
Re: interesting to know
This is actually not a new news, we have heard that USB device can easily be used to exploit vulnerabilities in the past. We all need to be cautious on that.
bpaddock
50%
50%
bpaddock,
User Rank: Strategist
3/28/2016 | 12:46:38 PM
Use HASHDEEP to detect the resulting stolen data
The program HashDeep has a negative audit mode that would show any additons to the USB stick.
The filename would not mater.  The article does not address where the stolen data file is stored at.
Is it always stored in the same place?

md5deep.sourceforge.net/start-hashdeep.html
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/29/2016 | 10:37:48 AM
Re: Use HASHDEEP to detect the resulting stolen data
I assume there is always a way to see the trace if you analyze the USB drive itself. It is still playing a catch up tough. USB sticks are real danger to businesses.
theb0x
50%
50%
theb0x,
User Rank: Ninja
3/28/2016 | 1:38:18 PM
File Creation Timestamps
It is very easy to tamper with file timestamps. Creation time/date / modified..etc.

 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/29/2016 | 10:39:23 AM
Re: File Creation Timestamps
I agree. File attributes are not real indicators what is happening. They can easily be modified and dynamically changed on the fly.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/29/2016 | 10:33:35 AM
USB port
 

USB port is a powerful way to access a secure network. When an employee finds a USB stick on the parking lot he/she feels lucky and wants to check what is in it. Super effective way of infecting computers and networks. May be it is time to block all USB ports :--))
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
3/29/2016 | 10:42:09 AM
No USB going forward?
I am also not how many of us are using USB sticks these days anymore. I was a heavy users for backups points of view but now I store everything in the cloud and I never need a USB drive on my devices. :--))

 
Jeremseo
50%
50%
Jeremseo,
User Rank: Strategist
4/5/2016 | 10:52:50 AM
USB User
For me I am still a big USB user... I feel it is an old habit, even on work we have clouds, still, USB is my first choice.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/10/2020
Researcher Finds New Office Macro Attacks for MacOS
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/7/2020
Lock-Pickers Face an Uncertain Future Online
Seth Rosenblatt, Contributing Writer,  8/10/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-16145
PUBLISHED: 2020-08-12
Roundcube Webmail before 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document.
CVE-2020-16266
PUBLISHED: 2020-08-12
An XSS issue was discovered in MantisBT before 2.24.2. Improper escaping on view_all_bug_page.php allows a remote attacker to inject arbitrary HTML into the page by saving it into a text Custom Field, leading to possible code execution in the browser of any user subsequently viewing the issue (if CS...
CVE-2020-17372
PUBLISHED: 2020-08-12
SugarCRM before 10.1.0 (Q3 2020) allows XSS.
CVE-2020-17373
PUBLISHED: 2020-08-12
SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection.
CVE-2020-6932
PUBLISHED: 2020-08-12
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the web server.