USB Rubber Ducky attacks explained: Keystroke injection, evasion, and defense
ID: 1eb7a98f-e5c0-5ddb-a5bc-cdbd502f9fa1
STIX ID: report--1eb7a98f-e5c0-5ddb-a5bc-cdbd502f9fa1
Feed Name: ThreatLocker Blog
Threat Score
The report explains how USB Rubber Ducky devices masquerade as keyboards to inject keystrokes that can launch PowerShell and other interpreters to exfiltrate data or deploy ransomware while evading traditional signature and behavior-based detection; it emphasizes defensive controls (application allowlisting, ringfencing, device restrictions and blocking unnecessary PowerShell) and describes how ThreatLocker mitigates these attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
