Close Menu
Tactical AmericansTactical Americans
  • Home
  • Guns
  • Knives
  • Gear
  • News
  • Videos
  • Community

Subscribe to Updates

Get the latest tactical, firearms and many more news and updates directly to your inbox.

What's Hot

Nine Inmates — Including Accused Murderers — Are on the Loose in New Orleans After Escaping Jail

May 16, 2025 10:07 pm

‘Profound Heartbreak’: First Descents Announces Sudden Death of ‘Beloved’ CEO

May 16, 2025 9:18 pm

Ky. Man Allegedly Bit Cat's Ear Off, Then Hid Under Blankets When Cops Came: Police

May 16, 2025 9:06 pm
Facebook X (Twitter) Instagram
Friday, May 16, 2025 10:12 pm EDT
Trending
  • Nine Inmates — Including Accused Murderers — Are on the Loose in New Orleans After Escaping Jail
  • ‘Profound Heartbreak’: First Descents Announces Sudden Death of ‘Beloved’ CEO
  • Ky. Man Allegedly Bit Cat's Ear Off, Then Hid Under Blankets When Cops Came: Police
  • US Army’s Impact on Fashion
  • Save Up to 30% on Outdoor Gear During the REI Anniversary Sale
  • Melania Trump statue sawed off at ankles and stolen from Slovenian hometown
  • 749 Cartons of Cigarettes Worth Nearly $60,000 Confiscated from Cruise Passengers in California
  • National Parks Open for Mining? BLM Paves Way for Mineral Rights Claims on Public Land
  • Privacy
  • Advertise
  • Contact
Facebook X (Twitter) Instagram Pinterest VKontakte
Tactical AmericansTactical Americans
  • Home
  • Guns
  • Knives
  • Gear
  • News
  • Videos
  • Community
Newsletter
Tactical AmericansTactical Americans
Home » Hackers using malware to steal data from USB flash drives
News

Hackers using malware to steal data from USB flash drives

Jack BogartBy Jack BogartApr 20, 2025 10:23 am1 ViewsNo Comments
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp
Hackers using malware to steal data from USB flash drives
Share
Facebook Twitter LinkedIn Pinterest Email

Cybercriminals are constantly finding new ways to steal your data. As people become more aware of common threats like phishing links, fake websites, fraudulent emails and impersonation scams, attackers are becoming more creative in their approach.

One of the newer methods they are using involves targeting USB flash drives. It may seem surprising that they would focus on something as simple as a flash drive, but the data it holds can be valuable. 

Plus, flash drives can be used to spread malware to other devices.

STAY PROTECTED & INFORMED! GET SECURITY ALERTS & EXPERT TECH TIPS — SIGN UP FOR KURT’S THE CYBERGUY REPORT NOW

Why target USB flash drives?

USB drives are ubiquitous in workplaces, especially in environments with air-gapped systems or restricted internet access, such as those in government and energy sectors. This makes them an easy target for data theft and malware propagation. Often, these drives store sensitive files that are not available on networked systems. 

WHAT IS ARTIFICIAL INTELLIGENCE (AI)?

When infected, USB drives can spread malware not just within a single organization but also across multiple entities if shared. These attacks don’t rely on network vulnerabilities, allowing them to bypass traditional security tools. 

flash drive hacker 2

200 MILLION SOCIAL MEDIA RECORDS LEAKED IN MAJOR X DATA BREACH 

How hackers are targeting your USB drives

As reported by Kaspersky’s Securelist, a cybersecurity research platform, hackers are using USB drives to spread malware in ways that can easily bypass traditional security systems. One group, known as GOFFEE, kicks off its attacks with targeted phishing emails. These emails often carry infected RAR files or Office documents with harmful macros. Once opened, they install sneaky programs like PowerModul and PowerTaskel on the victim’s system.

These tools don’t just sit around. They lay the groundwork for more attacks. PowerModul, in particular, plays a big role. It’s a PowerShell script introduced in 2024 that talks to a command-and-control (C2) server. From there, it can download and run other tools, including two especially dangerous ones, FlashFileGrabber and USB Worm.

FlashFileGrabber is made to steal data from USB drives. It can either save stolen files locally or send them back to the hacker’s server. Then there’s USB Worm, which infects any USB drive it finds with PowerModul, turning that drive into a tool for spreading malware to other systems.

What makes this method effective is that USB drives are often shared between people and offices. That physical movement allows the malware to spread even without an internet connection. The malware hides original files on the USB and replaces them with malicious scripts disguised as normal-looking shortcuts. When someone clicks one of these, they unknowingly trigger the infection.

flash drive hacker 3

MALWARE EXPOSES 3.9 BILLION PASSWORDS IN HUGE CYBERSECURITY THREAT

4 practical ways to stay safe from USB-targeted attacks

1. Don’t plug in unknown USB drives: It might sound obvious, but this is one of the most common ways malware spreads. If you find a USB drive lying around or someone gives you one you weren’t expecting, avoid plugging it into your system. Attackers often rely on human curiosity to get the malware onto your machine.

2. Be extra cautious with email attachments: GOFFEE’s campaigns often begin with phishing emails carrying malicious RAR files or Office documents with macros. Always double-check the sender’s address and never open unexpected attachments, especially if they ask you to “enable macros” or come from unknown contacts. When in doubt, confirm through a different channel.

3. Avoid clicking on suspicious links and use strong antivirus software: Many attacks like GOFFEE’s start with emails that look legitimate but contain malicious links. These links might lead you to fake login pages or silently download malware that sets the stage for USB-targeting tools like PowerModul.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices.

4. Scan USB drives before use: The USB Worm infects USB drives by hiding original files and planting malicious scripts disguised as shortcuts, which trigger PowerModul when clicked. FlashFileGrabber also steals files silently from USBs, often going unnoticed. Always scan USB drives with updated antivirus software before opening any files. Use a reputable security tool to check for hidden scripts, unusual shortcuts or unexpected executables. If files appear renamed or hidden, don’t click them until verified safe. 

DATA REMOVAL DOES WHAT VPNS DON’T: HERE’S WHY YOU NEED BOTH 

Kurt’s key takeaway

Cybercriminals thrive where convenience meets oversight. However, it’s worth considering why USBs remain such a soft target. They’re not just storage but a cultural artifact of workplaces, especially in high-stakes sectors like energy or government, where offline data transfer feels safer than the cloud. But that trust is a blind spot. Attackers like GOFFEE don’t need zero days because they can exploit human habits such as sharing drives, skipping scans and clicking without thinking.

How often do you plug in a USB drive without scanning it first? Let us know by writing us at Cyberguy.com/Contact

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter

Ask Kurt a question or let us know what stories you’d like us to cover

Follow Kurt on his social channels

Answers to the most asked CyberGuy questions:

New from Kurt:

Copyright 2025 CyberGuy.com.  All rights reserved.

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Nine Inmates — Including Accused Murderers — Are on the Loose in New Orleans After Escaping Jail

Ky. Man Allegedly Bit Cat's Ear Off, Then Hid Under Blankets When Cops Came: Police

Melania Trump statue sawed off at ankles and stolen from Slovenian hometown

749 Cartons of Cigarettes Worth Nearly $60,000 Confiscated from Cruise Passengers in California

Remains near Taylor Swift’s beach mansion unrelated to serial killer: police

Breakup Texts Between Diddy and Cassie Revealed in Court: 'Needed You to Love Me'

Arlington, Virginia blocks police coordination with ICE in move slammed by AG

During Cassie's Testimony, Her Husband Had to Leave the Courtroom: Here's Why

ICC prosecutor in Netanyahu arrest case steps aside over alleged sex assault accusation

Add A Comment
Leave A Reply Cancel Reply

Editors Picks

‘Profound Heartbreak’: First Descents Announces Sudden Death of ‘Beloved’ CEO

May 16, 2025 9:18 pm

Ky. Man Allegedly Bit Cat's Ear Off, Then Hid Under Blankets When Cops Came: Police

May 16, 2025 9:06 pm

US Army’s Impact on Fashion

May 16, 2025 8:23 pm

Save Up to 30% on Outdoor Gear During the REI Anniversary Sale

May 16, 2025 8:18 pm

Subscribe to Updates

Get the latest tactical, firearms and many more news and updates directly to your inbox.

Latest News

Melania Trump statue sawed off at ankles and stolen from Slovenian hometown

By Jack Bogart

749 Cartons of Cigarettes Worth Nearly $60,000 Confiscated from Cruise Passengers in California

By Jack Bogart

National Parks Open for Mining? BLM Paves Way for Mineral Rights Claims on Public Land

By news
Tactical Americans
Facebook X (Twitter) Instagram Pinterest YouTube
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact
Copyright © 2025 Tactical Americans. Created by Sawah Solutions.

Type above and press Enter to search. Press Esc to cancel.