<p>Phishing, a prevalent cybercrime using social engineering, threatens individuals and enterprises despite existing protections. This paper addresses BadUSB devices in phishing campaigns, which exploit inherent trust in USB devices to execute malicious actions like keystroke injection. These attacks are particularly dangerous as their malicious code resides in firmware, evading traditional antivirus solutions. While enterprises have adopted phishing awareness training, there remains a significant gap in simulated BadUSB phishing campaigns. Our study employs a multifaceted approach starting with a survey of public awareness and behaviors regarding BadUSB threats. We examine the lifecycle of simulated BadUSB phishing campaigns in enterprise environments, develop a detailed threat model, and propose solutions through ByteBait USB, a comprehensive simulation toolkit. This toolkit features advanced capabilities including long-range communication, motion detection, trajectory tracking, and efficient power management, creating a realistic simulation environment. To our knowledge, this represents one of the first efforts to develop a BadUSB simulation toolkit, complementing existing resources for simulating phishing emails and websites. The proposed toolkit has been validated through real-world simulations, demonstrating its effectiveness in enhancing security awareness against sophisticated USB-based threats.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

ByteBait USB: a robust simulation toolkit for badUSB phishing campaign

  • Wenhao Li,
  • Selvakumar Manickam,
  • Yung-Wey Chong,
  • Yongqing He,
  • Ho Yean Li,
  • Binyong Li

摘要

Phishing, a prevalent cybercrime using social engineering, threatens individuals and enterprises despite existing protections. This paper addresses BadUSB devices in phishing campaigns, which exploit inherent trust in USB devices to execute malicious actions like keystroke injection. These attacks are particularly dangerous as their malicious code resides in firmware, evading traditional antivirus solutions. While enterprises have adopted phishing awareness training, there remains a significant gap in simulated BadUSB phishing campaigns. Our study employs a multifaceted approach starting with a survey of public awareness and behaviors regarding BadUSB threats. We examine the lifecycle of simulated BadUSB phishing campaigns in enterprise environments, develop a detailed threat model, and propose solutions through ByteBait USB, a comprehensive simulation toolkit. This toolkit features advanced capabilities including long-range communication, motion detection, trajectory tracking, and efficient power management, creating a realistic simulation environment. To our knowledge, this represents one of the first efforts to develop a BadUSB simulation toolkit, complementing existing resources for simulating phishing emails and websites. The proposed toolkit has been validated through real-world simulations, demonstrating its effectiveness in enhancing security awareness against sophisticated USB-based threats.