HomeTechHackers can tap USB...

Hackers can tap USB devices in new attacks, researcher warns

(Reuters) – USB devices such as keyboards, thumb-drives and mice can be used to hack into personal computers in a potential new class of attacks that evade all known security protections, a top computer researcher revealed on Thursday.

Karsten Nohl, chief scientist with Berlin’s SR Labs, noted that hackers could load malicioussoftware onto tiny, low-cost computer chips that control functions of USB devices but which have no built-in shields against tampering with their code.

“You cannot tell where the virus came from. It is almost like a magic trick,” said Nohl, whose research firm is known for uncovering major flaws in mobile phone technology.

The finding shows that bugs in software used to run tiny electronics components that are invisible to the average computer user can be extremely dangerous when hackers figure out how to exploit them. Security researchers have increasingly turned their attention to uncovering such flaws.

Nohl said his firm has performed attacks by writing malicious code onto USB control chips used in thumb drives and smartphones. Once the USB device is attached to a computer, the malicious software can log keystrokes, spy on communications and destroy data, he said.

Computers do not detect the infections when tainted devices are inserted because anti-virus programs are only designed to scan for software written onto memory and do not scan the “firmware” that controls the functioning of those devices, he said.

Nohl and Jakob Lell, a security researcher at SR Labs, will describe their attack method at next week’s Black Hat hacking conference in Las Vegas, in a presentation titled: “Bad USB – On Accessories that Turn Evil.”

Thousands of security professionals gather at the annual conference to hear about the latest hacking techniques, including ones that threaten the security of business computers,consumer electronics and critical infrastructure.

Nohl said he would not be surprised if intelligence agencies, like the National Security Agency, have already figured out how to launch attacks using this technique.

Last year, he presented research at Black Hat on breakthrough methods for remotely attacking SIM cards on mobile phones. In December, documents leaked by former NSA contractor Edward Snowden demonstrated that the U.S. spy agency was using a similar technique for surveillance, which it called “Monkey Calendar.”

An NSA spokeswoman declined to comment.

SR Labs tested the technique by infecting controller chips made by major Taiwanese manufacturer, Phison Electronics Corp, and placing them in USB memory drives and smartphones running Google Inc’s Android operating system.

Alex Chiu, an attorney with Phison, told Reuters via email that Nohl had contacted the company about his research in May.

“Mr. Nohl did not offer detailed analysis together with work product to prove his finding,” Chiu said. “Phison does not have ground to comment (on) his allegation.”

Chiu said that “from Phison’s reasonable knowledge and belief, it is hardly possible to rewrite Phison’s controller firmware without accessing our confidential information.”

Similar chips are made by Silicon Motion Technology Corp and Alcor Micro Corp. Nohl said his firm did not test devices with chips from those manufacturers.

Google did not respond to requests for comment. Officials with Silicon Motion and Alcor Micro could not immediately be reached.

Nohl believed hackers would have a “high chance” of corrupting other kinds of controller chips besides those made by Phison, because their manufacturers are not required to secure software. He said those chips, once infected, could be used to infect mice, keyboards and other devices that connect via USB.

“The sky is the limit. You can do anything at all,” he said.

In his tests, Nohl said he was able to gain remote access to a computer by having the USB instruct the computer to download a malicious program with instructions that the PC believed were coming from a keyboard. He was also able to change what are known as DNS network settings on a computer, essentially instructing the machine to route Internet traffic through malicious servers.

Once a computer is infected, it could be programmed to infect all USB devices that are subsequently attached to it, which would then corrupt machines that they contact.

“Now all of your USB devices are infected. It becomes self-propagating and extremely persistent,” Nohl said. “You can never remove it.”

Christof Paar, a professor of electrical engineering at Germany’s University of Bochum who reviewed the findings, said he believed the new research would prompt others to take a closer look at USB technology, and potentially lead to the discovery of more bugs. He urged manufacturers to improve protection of their chips to thwart attacks.

“The manufacturer should make it much harder to change the software that runs on a USB stick,” Paar said.

(Additional reporting by Michael Gold in Taipei; Editing by Richard ValdmanisRichard Chang and Bernadette Baum)

- A word from our sponsors -

spot_img

Most Popular

LEAVE A REPLY

Please enter your comment!
Please enter your name here

More from Author

Cheta Nwanze: Failed visa Marriages

by Cheta Nwanze The 1990 film Green Card told a relatively innocent...

Digital Marketing for Attorneys

In the competitive landscape of legal services, personal injury and medical...

- A word from our sponsors -

spot_img

Read Now

“No Victor, No Vanquished” — Angbazo calls for unity after Nasarawa ADC Governorship Primary win

LAFIA — Retired General Nuhu Angbazo has emerged victorious from the Africa Democratic Congress, ADC, governorship primaries in Nasarawa State, calling on all party faithful to sheathe their swords and rally behind a common vision for the state's development. In a press statement issued shortly after his victory...

Lazarus Angbazo: The Countries that will lead the AI Economy are being decided right Now — By Their PowerGrids

Nigeria has enough installed generation to power a mid-sized country. The grid delivers less than half of it. Around the world, the race to build AI-ready power infrastructure is already underway — and the decisions African governments and investors make in the next eighteen months will determine...

Cheta Nwanze: Failed visa Marriages

by Cheta Nwanze The 1990 film Green Card told a relatively innocent story: a French immigrant and an American woman enter a marriage of convenience so he can stay in the US. They barely know each other. They hope never to see each other again after the deal...

Digital Marketing for Attorneys

In the competitive landscape of legal services, personal injury and medical malpractice attorneys are finding themselves overshadowed by competitors who dominate online visibility. The root of this issue lies in the digital presence that many firms lack. While traditional word-of-mouth referrals still hold value, the digital age...

Lazarus Angbazo: The global power industry is leaving Africa behind

 Dr. Lazarus AngbazoThe nascent AI revolution is not just driving electricity consumption and massive demand for additional capacity—it is reshaping how power is built, maintained, and delivered. For Africa, the real risk is no longer just insufficient capacity—it is also losing control and ability to manage the capacity it...

Bunmi Onabanjo-Kuku: The first thing you feel when you land in Nigeria

By Bunmi Onabanjo-Kuku The first thing you feel when you land in a country is not its culture, not its cuisine, not its people. It is its airport. That threshold, the space between the jet bridge and the city beyond, tells you everything a nation believes about itself...

Dr. Lazarus Angbazo: Why a fractured world strengthens the case for African Infrastructure

How inflation, energy insecurity, power scarcity, and geopolitical fragmentation are reshaping the risk-return case for African infrastructure By Dr. Lazarus Angbazo At a recent global infrastructure summit, the prevailing mood among institutional investors was unmistakable. Faced with surging capital requirements for energy transition, grid expansion, and digital infrastructure in Europe and...

Aliko Dangote to launch what could become Africa’s largest initial public offering to raise $5 billion from investors

Nigeria’s biggest local investor, Aliko Dangote, is moving ahead with plans to launch what could become Africa’s largest initial public offering, as Dangote Petroleum Refinery & Petrochemicals prepares to raise up to $5 billion from investors. The share sale is expected to open as early as May, with...

Criminal networks have turned Nigeria’s telecom towers into open-air warehouses for theft, looting

Criminal networks have turned Nigeria’s telecom towers into open-air warehouses for theft, looting 656 critical power assets across 14 states in 2025 alone and keeping up the pace in early 2026. The Nigerian Communications Commission (NCC) data showed the haul included 152 generators and 504 batteries stolen from...

Paul Yirenkyi: A call for Caution Needed, President Tinubu and the INEC-ADC Crisis

I have seen enough cycles of tension and resolution to recognise when restraint must prevail over confrontation. The current standoff between the Independent National Electoral Commission (INEC) and the African Democratic Congress (ADC) is one such moment. In early April 2026, INEC withdrew recognition of the Senator...

Nigeria’s opposition landscape appears increasingly fractured, disorganised and strategically weakened

10 months until the 2027 general elections, Nigeria’s opposition landscape appears increasingly fractured, disorganised and strategically weakened. Although no fewer than 21 political parties have been registered by the Independent National Electoral Commission (INEC) to participate in the polls, developments within the parties, including internal crises, litigations and other destabilising factors, may...

Power shortages weaken Nigeria’s business activity 

Nigeria’s business environment continued to expand in March 2026 but slowed as rising input costs and power supply deficits weighed on performance, according to the latest Business Confidence Monitor (BCM) report by the Nigerian Economic Summit Group (NESG). The report indicates that the Current Business Performance Index declined...