A threat actor is targeting organizations in Italy, using USB flash drives to spread sophisticated malware capable of hijacking cryptocurrency.
In a report on Tuesday, cybersecurity firm Mandiant said the unidentified actor (codenamed UNC4900) hid infectious code on legitimate websites like Ars Technica, GitHub, GitLab, and Vimeo. This code, which was “completely benign” when isolated from the other malware components, didn’t pose a direct threat to the users of these sites, even when they clicked on them.
“The legitimate services abused by UNC4990 (including Ars Technica, GitHub, GitLab, and Vimeo) didn’t involve exploiting any known or unknown vulnerabilities in these sites, nor did any of these organizations have anything misconfigured to allow for this abuse,” Mandiant noted.
The financially motivated threat actor is targeting users across various sectors, including health, transportation, construction, and logistics. While some of the targeted organizations are based in Europe and the U.S., the primary focus appears to be on Italian organizations.
USB Drives Used to Spread Advanced Malware
The attack begins when a user clicks a harmless-looking “LNK” file placed on a USB device by the threat actor. Clicking this file triggers a PowerShell code script, leading to the download of two sinister tools — “EMPTYSPACE” and “QUIETBOARD.”
“EMPTYSPACE” (also known as BrokerLoader and VETTA Loader) is a downloader that fetches malicious code from a remote server. The other, “QUIETBOARD,” is a multifaceted backdoor capable of various operations like altering crypto wallet addresses, spreading the malware further, taking screenshots, and gathering system data on the victim’s machine.
Initially, the actor’s infectious code was hosted on Github, the report said. Mandiant discovered that the actor later placed their malicious code on Vimeo. The encoded payload was hidden within the description of a video related to Pink Floyd, uploaded in March 2023. The video has since been removed from the video hosting platform.
After the Vimeo video was removed, the threat actor switched to using Ars Technica, a well-known tech news forum, as their new Command and Control (C2) remote channel. They hid malicious code in the image URL of a user who joined the Ars Technica forum in November 2023. Ars Technica removed this photo in December 2023.
How to Protect Your Device From Malicious USBs
Threat actors have been using USBs to spread malware for many years. And, it’s not just USB devices you need to be wary of. In April 2023, the FBI warned against using free USB charging stations at airports and hotels, as cybercriminals install malware through public charging stations to access devices plugged in for charging.
There are various ways to protect your device from USB-borne threats, including:
- Exercising caution with USB devices, especially those of unknown origin. You can disable autorun on computers can prevent the automatic execution of malicious scripts.
- Keeping your software and operating system up-to-date. Regular updates can close security loopholes that might be exploited by malware.
- Monitoring your systems for signs of intrusion, like unexpected PowerShell activity.
For more news, follow us on X (Twitter), Threads, and Mastodon!
