[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fB_tuuJm823nNStJ_7Gn4jrFl57Ua2NyfSi5DE7h1kDc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"804f9c16-9323-403a-bc7e-a0ae5e098def","usb-based-malware-campaign-exploits-social-engineering-and-poor-removable-media-controls","55a01be9-4ad7-4fbd-9a21-aed32b2a7fd6","USB-Based Malware Campaign Exploits Social Engineering and Poor Removable Media Controls","The BRUSHWORM campaign successfully infiltrated a South Asian financial institution by combining social engineering with USB-based malware propagation. The attackers used convincing filenames like 'Salary Slips.exe' and 'Important.exe' to trick employees into executing malicious files from infected USB drives. This incident highlights how threat actors exploit human psychology and inadequate removable media security controls to bypass technical defenses. The attack's success demonstrates that even sophisticated organizations remain vulnerable when employees lack proper security awareness training and when systems permit unrestricted execution of files from removable media.","**Immediate actions:**\n- Block execution of files from USB drives through Group Policy or endpoint protection\n- Conduct emergency security awareness training focused on recognizing suspicious file attachments\n- Deploy endpoint detection and response (EDR) solutions to monitor for USB-based threats\n\n**Long-term improvements:**\n- Implement comprehensive security awareness training programs with regular phishing simulations\n- Establish strict removable media policies requiring approval and scanning before use\n- Configure application whitelisting to prevent execution of unauthorized executables\n\n**Detection measures:**\n- Monitor for suspicious process execution from removable media locations\n- Set up alerts for files with deceptive naming patterns or double extensions\n- Implement behavioral analysis to detect unusual USB device activity",[12,13,14,15,16],"CIS Control 8","CIS Control 2","NIST SC-41","NIST AT-2","NIST SI-3","published","2026-04-04T17:07:05.77872+00:00","2026-04-04T17:07:05.638+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fx.com\u002Felasticseclabs\u002Fstatus\u002F2040459383549637106","salary-slips-exe-dont-delete-exe-important-exe-these-are-the-filenames-brushworm","\"Salary Slips.exe.\" \"Dont Delete.exe.\" \"Important.exe.\"\n\nThese are the filenames BRUSHWORM copies...",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":32,"name":33,"slug":34,"description":35,"color":36},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[38],{"id":39,"date":40,"edition":41,"title":42,"audio_url":43},"edda011c-96e5-44cd-84a1-4425f5f970d6","2026-04-05","morning","ThreatNoir Weekend Brief — April 5","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-05\u002Fthreatnoir-morning-brief-2026-04-05.mp3"]