USB-Borne Malware Poses Increased Cyber Threat

Aug. 19, 2022
2022 Honeywell Industrial Cybersecurity USB Threat Report finds industrial control systems are increasingly in the sights of cyber attackers.

According to a report released by Honeywell, the threat of USB-borne malware continues to be a serious concern. Data from the 2022 Honeywell Industrial Cybersecurity USB Threat Report indicates that 52% of threats were specifically designed to utilize removable media, up from 32% the previous year and more than double the 19% reported in the 2020 study, clearly indicating that the threats designed to use removable media have reached a dangerously high level.

Now in its fourth year, the Honeywell Industrial Cybersecurity USB Threat Report shows a clear trend: cybersecurity threats continue to be more prominent and more potent. According to the report, threats designed to establish remote access capabilities remained steady at 51%, while the number of threats designed specifically to target industrial control systems increased slightly year over year, up from 30% to 32%. At the same time, the malware was more capable of causing a disruption to industrial control systems, climbing to 81% compared to 79% the previous year.

The current report was based on aggregated cybersecurity threat data from hundreds of industrial facilities globally during a 12-month period. Along with USB attacks, the research highlights that Trojans remain a top concern because of their potential to cause severe disruption to industrial infrastructure, comprising 76% of the malware detected.

"This year's report indicates that adversaries are deliberately leveraging removable media as an initial attack vector to establish remote connectivity, exfiltrate data, and establish command and control," says Jeff Zindel, vice president and general manager, Honeywell connected enterprise cybersecurity, in a press release from the company. "It's now painfully clear that USB removable media are being used to penetrate industrial/OT environments, and that organizations must adopt formal programs to defend against this type of threat to avoid costly disruptions."

For the fourth year in a row, the threats attempting to enter industrial/OT environments have continued to increase in sophistication and frequency with USB-borne malware clearly being leveraged as part of larger cyberattack campaigns. Hackers are taking advantage of USB removable media to circumvent network defenses and bypass the air gaps upon which many of these facilities depend upon for protection. Continued diligence is necessary to defend against the growing USB threat and strong USB security controls are highly recommended.

Read the news release at www.honeywell.com

Sponsored Recommendations

Keys to Improving Safety in Chemical Processes (PDF)

Many facilities handle dangerous processes and products on a daily basis. Keeping everything under control demands well-trained people working with the best equipment.

Comprehensive Compressed Air Assessments: The 5-Step Process

A comprehensive compressed air audit will identify energy savings in an air system. This paper defines the 5 steps necessary for an effective air audit.

Get Hands-On Training in Emerson's Interactive Plant Environment

Enhance the training experience and increase retention by training hands-on in Emerson's Interactive Plant Environment. Build skills here so you have them where and when it matters...

Managing and Reducing Methane Emission in Upstream Oil & Gas

Measurement Instrumentation for reducing emissions, improving efficiency and ensuring safety.