• Home
    • What is
    • Computer security
      • Windows security
      • Mac security
      • Linux security
    • Mobile security
      • Android security
      • iOS Security
    • Data security
    • SCCM
    • Reviews
      • Case studies
    • Advertise
    • Contact
      • Privacy Policy
  • Subscribe now

    Loading
  • Home
  • What is
  • Computer security
    • Windows security
    • Mac security
    • Linux security
  • Mobile security
    • Android security
    • iOS Security
  • Data security
  • SCCM
  • Reviews
    • Case studies
  • Advertise
  • Contact
    • Privacy Policy
Home » Computer security Device security Linux security Mac security Windows security

FIN7 actors sent Malicious USB drives to US companies with ransomware

William Marshal Posted On January 8, 2022
0



FIN7 actors

The FBI has identified malicious USB devices that are sent to US companies in recent months with the motive to infect the company networks with malware and further payload drops. The group behind this malicious USB operation is found to be FIN7 actors, the ones behind BlackMatter and Darkside ransomware.

As per the FBI report, several packages with USB drives have been shipped to US companies including defense, insurance and transportation industry. The delivery has been made via United Parcel Service and United States Postal Service. The packages came in two variants, one with US Department of Health and Human Services name on it, with few COVID-19 guidelines and a USB drive.

The other one was disguised as an Amazon Package with gift decorations, thank you message, gift card and USB drive. One common thing between these two packages is that the USB drive was from the LilyGo brand.

FIN7 actors sent USB drives that can install a ransomware

Once the recipients plug-in these USB drives into their devices, a BadUSB attack is initiated. A BadUSB attack is a security attack which infects the devices by reprogramming the USB drive with malicious software. With these malicious programs the actors can download multiple payloads into the device and make them act as a backdoor for further infiltration. Once the actors gain the admin privileges for a system they continue their attack by spreading the malware laterally across the network affecting other peer devices.

After successful lateral distribution the FIN7 actors employed multiple tools to deploy REvil and BlackMatter ransomware. The tools include Cobalt Strike, Metasploit, Carbanak, TIRION, DICELOADER, GRIFFON, and Carbanak.

FIN7 actors
Tactics employed by FIN7 actors in 2018 for infiltering networks, source: FBI

FIN7 actors sent the USB drives to US defense organization

In November 2021, the FIN7 actors sent the USB drives to US defense organization with the Amazon package details mentioned above. It is to be noted that the FBI already have warned US companies in March 2020 regarding FIN7 actors and their intent, so this will be the second alert sent out by the FBI.

The details of the delivery package with images of the LiliGo brand, the COVID-19 guidelines and Amazon thank you message is available in the InfraGard Portal which companies can access after registering themselves for alerts and get a heads up on FIN7 actors and their attacks. The FBI has been warning companies for a long time about FIN7 actors, here is one such detailed modus operandi breakdown from the FBI that was published in 2018.

Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on Facebook, Linkedin, Instagram, Twitter and Reddit.

You can reach out to us via Twitter or Facebook, for any advertising requests.

Share the article with your friends


BadUSB attack FIN7FIN7 actorsFIN7 badusb attackFIN7 cybercriminals


Author

William Marshal

William has been one of the key contributors to 'The Cybersecurity Times' with 9.5 years of experience in the cybersecurity journalism. Apart from writing, he also like hiking, skating and coding.

Leave A Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • Subscribe to our newsletter

    Loading
  • Windows security

    • Top 9 Best Log Management Tools for 2025
      September 20, 2025
    • Top 4 Remote Support Tools for 2025- Best Remote Support...
      September 18, 2025
    • Top 5 Best Unified Endpoint Management (UEM) Software...
      September 12, 2025
    • Top 5 Threat Intelligence Tools For 2025
      July 25, 2025
    • Top 5 Best Microsoft Intune Alternatives to Consider...
      July 23, 2025


  • About us

    Our vision is to deliver the trending and happening cyber events to the enthusiasts.

    We believe in delivering educational and quality content for hassle-free understanding of the subject.

  • Subscribe to our newsletter

    Loading
  • Follow us

  • Advertise with us

    You can reach us via Facebook, Linkedin, or Twitter for advertising purposes.


© The Cybersecurity Times 2022. All rights reserved.
Press enter/return to begin your search