logo

USB Rubber Ducky attacks explained: Keystroke injection, evasion, and defense

ID: 1eb7a98f-e5c0-5ddb-a5bc-cdbd502f9fa1

STIX ID: report--1eb7a98f-e5c0-5ddb-a5bc-cdbd502f9fa1

Feed Name: ThreatLocker Blog

Threat Score
70/100

Date Published: 2026-03-31

Date Updated: 2026-05-01

...
...

The report explains how USB Rubber Ducky devices masquerade as keyboards to inject keystrokes that can launch PowerShell and other interpreters to exfiltrate data or deploy ransomware while evading traditional signature and behavior-based detection; it emphasizes defensive controls (application allowlisting, ringfencing, device restrictions and blocking unnecessary PowerShell) and describes how ThreatLocker mitigates these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.