logo

Hackers push USB malware payloads via news, media hosting sites

ID: 5fbd1b8a-27f8-50f4-8528-c9ec4a9f6a04

STIX ID: report--5fbd1b8a-27f8-50f4-8528-c9ec4a9f6a04

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-01-31

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Mandiant-tracked UNC4990 (active since 2020) operates a financially motivated USB-based infection campaign: victims executing malicious LNK files on removable drives trigger a PowerShell script that fetches intermediary Base64/AES-encoded payloads covertly hosted in benign content on platforms like GitHub, Vimeo, and Ars Technica; these payloads lead to the EMPTYSPACE downloader which installs the QUIETBOARD multi-component backdoor and cryptocurrency miners, enabling remote command execution, USB propagation, clipboard theft for crypto theft, persistence, and information collection, with observed crypto proceeds exceeding $55,000 and primary targeting of users in Italy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.