Computers at the International Atomic Energy Agency (IAEA) were infected by Universal Serial Bus (USB) malware,...
By submitting your email address, you agree to receive emails regarding relevant topic offers from TechTarget and its partners. You can withdraw your consent at any time. Contact TechTarget at 275 Grove Street, Newton, MA.
but I heard that these malware attacks did not infect networks/systems but steal data directly from USB devices. Can you please explain how this attack works and the best ways to thwart similar attacks?
Infecting systems over the network has almost become passé given the releases from Edward Snowden around the NSA using Bluetooth and other methods to compromise systems and steal data. Defending against these sorts of attacks is eventually going to require a Faraday cage and no communications interconnects whatsoever. Even common criminals nowadays are using Bluetooth in skimmers on gas pumps to steal credit card data.
In the IAEA attack, it appears that only those computers in a public meeting area were infected with malware that reportedly compromised data on any USB drives that connected to the computers. While visitors and staff in this area might have had a reasonable expectation that these systems were secure, they were mistaken. Other devices that were not in open spaces do not appear to have been affected.
To protect the USB drives in your enterprise from a similar attack, advise employees to only use known secure computers or their own system or, if only a public computer is available, use a thumb drive with no other information on it other than the data needed for a particular presentation for that day.
Additionally, there are many USB drives available that have software that runs a sandbox or protects against infected systems. Alternately, enterprises could set up a VPN to a secure terminal server with two-factor authentication to minimize the chances of data being copied to the local system and compromised.
Ask the Expert!
Want to ask Nick Lewis a question about enterprise threats? Submit your question now via email! (All questions are anonymous.)
Dig Deeper on Malware, Viruses, Trojans and Spyware
Related Q&A from Nick Lewis
Latentbot malware has layers of obfuscation that makes it hard to detect. Expert Nick Lewis explains how its process works, beginning with a phishing...continue reading
A hard to detect type of Linux malware, Rekoobe, can download files to user systems. Expert Nick Lewis explains the malware's key functionality and ...continue reading
Pro POS, a new type of POS malware, has simple operations and is easy to obtain. How was it so successful against businesses? Expert Nick Lewis ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.