SecPod

Learn Search

Search across all Learn content

← Back to Expressions & POVs
Easy Ways to Get Hacked – Part III

Easy Ways to Get Hacked – Part III

Nov 14, 2016By Rini3 min read

USB Scam: An Unsuspicious Attack in Action

Security researchers Karsten Nohl and Jakob Lell at the Black Hat security conference demonstrated how the security of USB devices has been destroyed and how it’s possible to infect any USB device using hidden or unknown malware. They used the malware which they created called the BadUSB to show this. The BadUSB resides in the firmware that controls its basic functions. The attack code can stay out of sight long after the contents of the device’s memory would come into sight to the average user to be removed.

Another malware named USBee can transfer data via USB emissions from air-gapped computers. It turns USB devices already present within the targeted facility into a transmitter without making any modification to the hardware.

Baiting is a form of social engineering that intends to provide access to a target computer or computer network. An attacker leaves a malware-infected device such as a USB stick with malicious content in a place where it is likely to be found by his bait. The person who finds the USB device picks it and inserts it into his or her computer. The malware is unintentionally installed and the system is compromised.

USB risk is not a new fad. Most of us know that it’s not safe to plug an unfamiliar USB into our computers. But given the recent trends, it doesn’t seem like many users are aware that malware can be injected into a computer with just a USB. We also know that it’s not advisable to run executable files from vague USB sticks.

Opening files on a suspicious USB is not any less like opening an email or attachment from an unknown source.

Detect and mitigate USB disseminating malware

Malware distributed through USB sticks poses a severe challenge for security teams due to its complexity to detect and contain. Introducing malware into an organization’s network by tricking users, without their knowledge, is an old trick that still seems to be successful. Last month, USB flash drives were reportedly being left in letterboxes in the Melbourne suburb of Pakenham. Victoria police issued a warning about using these USB devices.

Here are some tips for lowering your chances of unknowingly becoming a victim of this unstable situation:

  • Erasing a USB drive may not be efficient considering the existence of firmware attacks such as BadUSB which would not be prevented.
  • If the source of the USB device is unknown, don’t plug or insert it into your computer.
  • Every organization must keep track of USB drives whenever it is used. If they find untrusted USB drives, they should test it.
  • If employees attend a trade fair, exhibition or conference, provide them with a piece of temporary equipment and if something happens, check if any risk is aroused from that equipment.
  • Turn off autorun to prevent any malware from installing by itself.
  • Treat an abandoned USB with the utmost suspicion. Don’t plug it in. Instead, hand it over to the security team. If a USB stick contains a label “Confidential – from the company”, check with the concerned department if they have sent across any such USB sticks.

The strongest defense against baiting is employee education and training. An organization must have a strong security culture where company security is a core part of their individual employee work task. Companies should educate every employee about social engineering techniques including possible baiting schemes and train them to recognize, prevent, respond to these attacks.

– Rini Thomas

Featured Posts

Open The Most Effective Vulnerability Assessment Framework What Makes One Effective
The Most Effective Vulnerability Assessment Framework What Makes One Effective

Point of View

The Most Effective Vulnerability Assessment Framework What Makes One Effective

No single named standard makes a vulnerability assessment framework effective. This piece covers NIST, ISO, and CIS Controls, then breaks down what actually separates a working framework from a checklist, coverage, risk based prioritization, cadence, ownership, and a feedback loop.

Sep 11, 2026

Open Threat and Vulnerability Assessment How Risk Actually Gets Calculated
Threat and Vulnerability Assessment How Risk Actually Gets Calculated

Point of View

Threat and Vulnerability Assessment How Risk Actually Gets Calculated

A vulnerability alone doesn't tell the whole risk story. This piece breaks down how a threat and vulnerability assessment pairs technical weaknesses with real attacker context, walks through the six step process, and covers frameworks like NIST 800-30 and ISO 27005.

Sep 11, 2026

Open Vulnerability Assessment Services: What to Look For
Vulnerability Assessment Services: What to Look For

Point of View

Vulnerability Assessment Services: What to Look For

Choosing a vulnerability assessment provider means asking about actual coverage, scan frequency, and whether findings come with real prioritization or just a CVSS dump. This piece breaks down what strong vulnerability assessment services include, red flags to avoid, and questions to ask before signing.

Sep 11, 2026

Open Agentic AI Vulnerability Assessment What Changes and What Does Not
Agentic AI Vulnerability Assessment What Changes and What Does Not

Point of View

Agentic AI Vulnerability Assessment What Changes and What Does Not

Agentic AI is expanding what a vulnerability assessment needs to cover, autonomous agents bring their own credentials, tool access, and memory, adding a genuinely new asset class alongside servers and endpoints. It's also compressing attacker timelines and introducing risk categories like goal hijacking and tool misuse that don't map to a traditional CVE. But the core discipline hasn't changed: the same lifecycle of scoping, scanning, prioritizing, and remediating still applies, human judgment still drives prioritization, and accountability still sits with the people who deployed the agent, not the agent itself.

Sep 9, 2026