Derzeit ist wieder ein #USB Wurm im Umlauf diesmal mit dem Namen #LitterDrifter. Ich finde es spannend das dies immer noch ein Ausbreitungsvector ist und Sinn macht der eigentlich nur noch für #OT Systeme wie Kraftwerke da diese hoffentlich meist gut von anderen Netzen getrennt sind. Vielleicht unterschätze ich aber auch die Nutzung von USB im privaten Bereich 🤷 - via Bruce Schneier - https://www.schneier.com/blog/archives/2023/11/litterdrifter-usb-worm.html #securiy #trojaner #malware
LitterDrifter USB Worm - Schneier on Security

LitterDrifter: Computerwurm breitet sich über USB-Speicher überall aus
https://winfuture.de/news,139734.html #Cybercrime #Malware #Computerwurm #LitterDrifter
LitterDrifter: Russen-Wurm breitet sich über USB-Speicher überall aus

Eine russische Malware-Gruppe, die bisher eigentlich nur durch Angriffe auf Ziele in der Ukraine auffiel, hat einen USB-Wurm losgelassen, der sich inzwischen weltweit ausbreitet. Der Schädling ist inzwischen unter der Bezeichnung LitterDrifter analysiert worden.

WinFuture.de

#USBworm unleashed by Russian state #hackers spreads worldwide | Ars Technica

#LitterDrifter 's means of self-propagation are simple. So why is it spreading so widely?
#usb #worm #russia

https://arstechnica.com/security/2023/11/normally-targeting-ukraine-russian-state-hackers-spread-usb-worm-worldwide/

USB worm unleashed by Russian state hackers spreads worldwide

LitterDrifter's means of self-propagation are simple. So why is it spreading so widely?

Ars Technica
Malware Spotlight - Into the Trash: Analyzing LitterDrifter - Check Point Research

Introduction Gamaredon, also known as Primitive Bear, ACTINIUM, and Shuckworm, is a unique player in the Russian espionage ecosystem that targets a wide variety of almost exclusively Ukrainian entities. While researchers often struggle to uncover evidence of Russian espionage activities, Gamaredon is notably conspicuous. The group behind it conducts large-scale campaigns while still primarily focusing […]

Check Point Research
Unter dem Namen #LitterDrifter verbreitet sich aktuell ein USB-Wurm, der eigentlich für Russland in der Ukraine spionieren soll, in aller Welt. https://winfuture.de/news,139734.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
LitterDrifter: Russen-Wurm breitet sich über USB-Speicher überall aus

Eine russische Malware-Gruppe, die bisher eigentlich nur durch Angriffe auf Ziele in der Ukraine auffiel, hat einen USB-Wurm losgelassen, der sich inzwischen weltweit ausbreitet. Der Schädling ist inzwischen unter der Bezeichnung LitterDrifter analysiert worden.

WinFuture.de

`Unlike viruses, worms typically spread through systems on their own. Because of this, it was only a matter of time before #LitterDrifter started operating outside its intended target — whether this was intentional or not, we'll never truly know. `

https://www.tomshardware.com/software/security-software/russian-made-ukraine-targeting-malware-has-infested-systems-worldwide-spreading-via-usb-stick

Russian-made Ukraine-targeting malware has infested systems worldwide, spreading via USB stick

A worm designed to spy on Ukraine has moved beyond its target country and has been found on systems worldwide.

Tom's Hardware

Flash drive sharing #malware escapes Україна. #Gamaredon fingered as perps.

A worm spread by sharing #USB drives is breaking free, outside of its primary target. An #APT group tied to the Russian #FSB is said to be responsible—apparently it’s part of #Putin’s #cyberwar against #Ukraine.

#LitterDrifter is at least easily detected and blocked. In today’s #SBBlogwatch, we give thanks for small mercies. At @TechstrongGroup’s @SecurityBlvd: https://securityboulevard.com/2023/11/litterdrifter-russian-usb-worm-richixbw/?utm_source=richisoc&utm_medium=social&utm_content=richisoc&utm_campaign=richisoc

‘LitterDrifter’ Russian USB Worm Leaks from Ukraine War Zone

FSB APT USB VBS LNK DLL: WTH? Flash drive sharing malware escapes Україна. Gamaredon fingered as perps.

Security Boulevard
Russian APT Gamaredon uses USB worm LitterDrifter against Ukraine

Russia-linked cyberespionage group Gamaredon has been spotted propagating a worm called LitterDrifter via USB.

Security Affairs

The attack chain involves phishing emails directing victims to a crafted ZIP file exploiting the WinRAR flaw to retrieve a PowerShell script from a remote server on Ngrok.

#Cybersecurity #Russia #Malware #Worm #Ukraine #LitterDrifter #HackerGroup

https://cybersec84.wordpress.com/2023/11/18/litterdrifter-usb-worm-deployed-by-russian-cyber-espionage-group/

LitterDrifter USB Worm Deployed by Russian Cyber Espionage Group

Russian cyber espionage actors linked to the Federal Security Service (FSB) have been identified using a USB-propagating worm named LitterDrifter in targeted attacks against Ukrainian entities, acc…

CyberSec84 | Cybersecurity news.