BadUSB
BadUSB is an attack that reprograms a USB device's firmware so it impersonates a keyboard and types malicious commands the moment it is plugged in.
BadUSB is a class of attack in which a USB device's firmware is reprogrammed so the device lies about what it is. A stick that looks like ordinary storage registers itself as a keyboard the moment it is connected, then "types" attacker-chosen commands at superhuman speed — opening a terminal, downloading malware, exfiltrating credentials — all with the privileges of the logged-in user. Because the operating system inherently trusts human interface devices, no file is opened and no autorun prompt appears; conventional antivirus, which scans files rather than keystrokes, has little to inspect.
How it works
The technique was demonstrated publicly by researchers in 2014, who showed that the controller chips in commodity USB devices could be reflashed to impersonate other device classes. Purpose-built attack hardware followed, packaged as innocuous sticks, cables, and adapters. Delivery is classic social engineering: the device arrives as a dropped drive in a parking lot, a conference giveaway, a "replacement" cable left at a hot desk, or a package mailed to a target with a convincing pretext — a baiting play that turns curiosity or helpfulness into code execution. Where a classic USB drop relies on the victim opening a malicious file, BadUSB needs only the physical connection; the payload runs in seconds and the device keeps working as advertised, so victims rarely notice.
How to defend against it
Technical controls come first: disable or allowlist USB device classes through endpoint management, block new HID (keyboard) devices from enrolling without approval, and issue vetted hardware so staff never need mystery peripherals. Then close the human gap the attack actually depends on — teach employees that any found or unsolicited USB device, including cables and chargers, goes to the security team rather than into a port, and rehearse that reflex alongside the physical-layer habits covered in our guide to tailgating, shoulder surfing, and dumpster diving. Measuring who plugs in and who reports is a natural extension of a human risk management program.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo