Cyber Security

Beware! Hackers Deliver USB Devices Containing Malware Using Best Buy Gift Cards

Hackers distribute malicious USB devices as a gift card from Best Buy for its loyal customers as an attempt to trick the victim’s in using the device.

Letter with USB

Trustwave found such a letter through their client and analyze the USB device further by plugging in air-gapped computers.

BadUSB Device

By observing the serial numbers and other information embedded in the device such as the serial number “HW-374” and by checking in Google researchers found a “BadUSB Leonardo USB ATMEGA32U4” for sale on shopee[.]tw website.

Advertised in website

The USB device contains an Arduino microcontroller ATMEGA32U4 designed to work as a USB keyboard. Once it gets injected in the device it injects various malicious PowerShell commands.

Then it PowerShell commands download a JScript command and save it as prada.txt which is the third level payload.

The JScript is obfuscated and its primary function is to register the infected host with the command and control (C&C) server with a unique ID.

The JScript function is to gather the system information from the infected host. It gathers all the information about the affected host and sends it to the C&C server.

Following are the information it collects

Data Collected
  • Username
  • Hostname
  • User’s System Privilege
  • Uses WMI query to get the:
  • Process owner
  • Domain name
  • Computer model
  • Operating system information
  • OS name
  • OS build
  • OS version
  • Memory capacity
  • Free memory available
  • OS registered user
  • OS registered organization
  • OS serial number
  • Last boot uptime
  • Install date
  • OS architecture
  • OS product type
  • Language code
  • Time zone
  • Number of users
  • Desktop monitor type
  • Desktop resolution
  • UAC level privilege
  • Office and Adobe acrobat installation
  • List of running Processes (including PID)
  • Whether the infected host is running in a virtualized environment

After processing every command the JScript sleeps for two minutes and then gets the new command from the C&C server.

Here is the full attack chain.

Infection Chain
  1. BadUSB distributed through gift cards.
  2. BadUSB plugged in with the Laptop
  3. Get’s recognized as a trusted USB device.
  4. Types in the PowerShell command.
  5. Executes stage 2 PowerShell script.
  6. Malware get’s installed in the system.
  7. Unpacks JScript command and save it as prada.txt
  8. Executes malware.

The USB devices are often used by security professionals for conducting physical pentests, these devices are dropped in parking lots or waiting rooms.

Attackers generally use spam email campaigns as a method to distribute malware, but here they have used the USB method to deliver the malware.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago