Recently multiple news outlets have had articles with stories about organisations that have been targeted to receive USB memory sticks or other mobile media. According to these articles, these USB devices have been prepared with malicious content to infect the user’s computer with ransomware. The malicious USB sticks contain several attack components. One is the manipulated hardware that performs the so-called “BadUSB” attack, in which a USB storage device simultaneously also acts as an input device emulating a keyboard and sends commands to the computer to manipulate it. Another is files containing multiple strains of ransomware as well as attack tools. The many articles quote warnings and advisories from both law enforcement and CERT organisations as sources.

bad usb
Picture: "BadUSB device created by sysctl staff for testing of Impex security controls"

Many of the articles contain recommendations similar to the example below: “These recommendations include a call on individuals and organisations not to insert USB drives from unknown sources, even if they’re addressed to you or your organisation. In addition, if the USB drive comes from a company or a person one is not familiar with, or does not trust, it is recommended that one contacts the source to confirm they actually sent the USB drive.”

Some people and some organisations can adhere to this recommendation. For others it is not as easy. It is often hard for some organisations to not accept USB devices or mobile media (e.g. SD-cards) from third parties. We can give some real-world examples of organisations where handling unknown media sources is happening all the time. Media outlets need to get information from anonymous sources. Government agencies that need to accept input, in analogue or digital form, from the general public. Municipality services need to exchange information with its citizens. Also, most big organisations have groups of people (lawyers, communications staff, IT staff, etc) that exchange information with third parties where you have not been able to establish a long-standing relationship or trust at the point when some media device is used to transfer PowerPoint files, PDFs, updated software or other files. These are all examples of situations where there are organisations that need some other way to protect themselves against malicious devices and infected files on these devices.

inside a bad usb
Picture: "Inside a BadUSB device created by sysctl staff"

Impex is a solution that would be very helpful in situations like this. It is a perfect protection, both to check for the presence of infected files and to transfer those checked files from the unknown device onto a local, and trusted, device that in a later stage can be transferred to other systems. Impex is also protected against the type of attacks described in the articles, the “BadUSB” attack. The hardening of the Impex station makes it immune to this attack. Impex is perfect when you need to protect against devices received from the general public, from third parties.

Contact us at Sysctl to get more information on how we can help you protect your organisation against unknown devices or malicious files.

References

Ransomware warning: Cyber criminals are mailing out USB drives that install malware

FIN7 Mails Malicious USB Sticks to Drop Ransomware

Press Statement: New Ransomware Attacking Organisational Networks Discovered