WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Threat Awareness – New USB Malware Variant Utilizes Novel Method of Obfuscation
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – New USB Malware Variant Utilizes Novel Method of Obfuscation

Author: April Zupan

Created: Thursday, January 26, 2023 - 19:10

Categories: Cybersecurity

Palo Alto Networks published a blog discussing research by its Unit 42 of a newly discovered variant of PlugX malware. This variant has a few unique capabilities, including the ability to hide itself within a USB using a novel technique that’s effective on the current Windows OS and that can only be detected using specialized forensic tools. It then copies all Adobe PDF and Microsoft Word files from the attached machine and spreads to any other removable drives (e.g., floppy, thumb, or flash) connected to the system. While PlugX has been used for years by many groups believed to be sponsored by the Chinese government, cybercrime groups, including ransomware, have also adopted it. Utilities that allow USBs within the environment are encouraged to tightly control and monitor their usage.  Read more at Palo Alto Networks.

Related post from WaterISAC: OT/ICS Security – USB Storage Devices are Still a Universal Threat to Industrial Operations

Related Resources

(TLP:CLEAR) WaterISAC’s Quarterly Water Sector Incident Summary, January to March 2026 – Executive Summary

Jun 23, 2026 in Cybersecurity, Intelligence, Physical Security
Members Only

(TLP:AMBER) WaterISAC’s Quarterly Water Sector Incident Summary, January to March 2026

Jun 23, 2026 in Cybersecurity, Intelligence, Physical Security
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar