The USB Keyboard We're Never Allowed to Plug In
Adam Savage’s Tested
0:00 Hey everybody, Adam Savage here and today
0:02 in partnership with our friends at Threat Locker,
0:04 we are taking another look at malicious devices hiding in plain sight.
0:09 They have brought to the cave examples
0:11 of compromised hardware that they've encountered in the field
0:14 and we're going to get a look and a demonstration of how they actually work.
0:19 Last time we did a video,
0:21 we were talking about the threat vector of USB drives and just
0:25 how much nefarious stuff they can pack into such an innocuous thing.
0:30 But now you guys have come back with a different
0:31 threat vector that's even hiding more in plain sight.
0:35 Absolutely.
0:35 So we're going to talk about keyboards.
0:37 We're going to talk about cameras.
0:38 I'm going to use the OMG cable to make
0:41 that camera start recording you on a continuous loop.
0:44 So uh this is just a cable, isn't it?
0:47 This is a phone charger.
0:48 So,
0:49 this is a phone charger.
0:50 And how does this give you access to the camera?
0:53 So, so this here has a Wi-Fi antenna built into it.
0:56 Um, it has a keyboard built into it.
0:58 So, we can pretty much do anything on a computer
1:00 that this is plugged into as if we were at the computer.
1:03 It comes in different colors, shapes, sizes, can look like an iPhone cable.
1:06 It will actually charge your phone so it functions fully.
1:10 So bad actors can create a cable that looks completely innocuous but has
1:15 a working computer inside that only wants to compromise me and all my data.
1:20 Yes.
1:20 And it will charge your phone.
1:21 It will function.
1:22 So if they switch your phone cable, you would never know any difference.
1:25 I This is why I So I consider it a reasonable practice.
1:28 I never plug my phone into anybody else's charging cable.
1:31 Is that a good security?
1:33 That's a really good practice.
1:34 Just make sure you treat your phone cable like
1:37 it's sacred because if someone comes and just swaps it,
1:43 it actually works great for me because my phone cable is
1:44 Apple and it's white and it's filthy and you can only Yeah,
1:48 that's what you want to keep it really really dirty.
1:50 If suddenly your cable gets clean one day, throw it away.
1:53 Okay, so talk to me about how this threat vector works.
1:56 Okay, so this is basically a keyboard.
1:58 Looks like a regular keyboard branded.
2:00 They come in different models,
2:01 but when we plug this in, this essentially will log all keys.
2:05 And it has the same thing, a wireless antenna built into it.
2:07 So, oh, into the cable.
2:09 Into the cable or into the keyboard.
2:11 Yeah.
2:12 So, so once I plug this in, Kwan could connect
2:14 to this and capture my keystrokes from sitting outside the office.
2:19 Okay.
2:19 So, IT departments are famously cranky about you bringing in your own hardware.
2:24 This is the greatest argument they have about why that's bad.
2:27 Yeah, absolutely.
2:28 is that they you could bring a keyboard from home,
2:31 plug it in, and it could have hidden antenna built
2:33 into it that allows somebody to see all your keystrokes.
2:36 Or if you want to be a really sophisticated attacker,
2:38 and we think about most businesses,
2:40 the a sophisticated attacker isn't going to go mail them a $150 keyboard.
2:44 It's not that nice and hope they plug it in
2:46 and hope they plug it in.
2:47 However, when you think about someone who's trying to get into, say,
2:50 big companies like Tesla,
2:51 they're willing to do a lot more cuz the reward is much bigger.
2:54 And and there was a story where someone had offered
2:56 a Tesla employee $500,000 to plug in a USB device.
2:59 So if you think they're willing to offer that, just think how
3:02 hard it would be to intercept a delivery and switch the keyboard out.
3:07 Not that hard at all.
3:09 No.
3:09 If you're willing that one through if you
3:12 wanted to if you're willing to pay someone $500,000,
3:15 it doesn't seem like it's particularly
3:17 difficult to switch somebody's keyboard out.
3:18 And this will give you full visibility
3:21 of everything they're typing on their computer.
3:23 Can we watch that happen?
3:24 Can we watch this happen?
3:25 Okay, so we're going to plug this one in.
3:27 Oh my god, this is terrifying.
3:29 Well, you don't think of keyboards as that famous way into your data.
3:36 Okay.
3:36 And uh well, essentially what Kieran's going to do is he's
3:38 going to connect to this as if it's a Wi-Fi device.
3:42 So he can see this here.
3:43 So he could be the threat actor in another building next door.
3:46 Uh just taking a look at what this is telling him.
3:50 So we can see here.
3:50 So I I can say comes up.
3:58 No way.
3:59 Oh my gosh.
4:05 Um what possible protection is there against a device like this?
4:11 This it really comes back down to we have
4:13 to assume the user is going to be compromised.
4:15 So obviously normal protections are making sure you source
4:17 things and you know where it comes from but we
4:19 have to assume the device or the or the password
4:22 the thing the user knows is compromised.
4:24 So it comes back down to you have you knowing the password shouldn't be enough.
4:28 So if I logged into my if I logged
4:30 into my Office 365 account from here right now.
4:32 Yeah.
4:34 Um
4:34 K would have my password.
4:35 He would not be able to get into my account from anywhere
4:38 else in the world because he wouldn't have one of my devices.
4:41 And that it comes back down to zero trust.
4:43 to make sure we're validating the computer
4:44 and the phone because there are always
4:46 going to be ways that the user will give you their password, their credentials.
4:50 Maybe through chipping you a keyboard,
4:52 but maybe just calling you and saying, "You're in the IT department.
4:54 Can I get your password?"
4:55 So, this is the polar opposite of security through obscurity where
4:58 you just hope that you're not very interesting to a bad actor.
5:01 This is making the assumption that every device you're going to plug
5:05 in is somehow going to compromise you and working around that with permissions.
5:10 Absolutely.
5:10 every every device, every piece of software you run,
5:13 whether you download a game, whether you're running Zoom.
5:14 I mean, think about all of the cyber attacks we've seen with common software,
5:18 Microsoft Office, Exchange, Solar Winds, uh Zoom,
5:20 all of these have had massive vulnerabilities.
5:23 So, when you build your security,
5:25 assuming that you have a bad actor already
5:28 in or accessible to some of your system,
5:31 then you win because it means yes, they get something,
5:33 but they can't get any more than that.
5:35 Um, this just occurred to me while you were
5:37 talking because I realized that actually being a security company,
5:39 you are a very highly I would imagine a highly valued target for bad actors.
5:44 Absolutely.
5:44 We're terrified of this stuff.
5:47 And so, uh, how I'm just curious about your level
5:52 of of of comfort like you build this stuff.
5:57 Are you up every night worrying about bad actors coming at you guys?
6:01 So, I'm up every night regardless.
6:03 So, so I I I think what we do
6:05 is make sure that everything has checks and balances.
6:07 So, one of the things that scares me is there was
6:10 another Florida security company that hired a North Korean spy by mistake.
6:14 Uh so, we are very conscious about okay,
6:16 even we hire people, how much data do they have access to?
6:20 How far can they go with that data?
6:22 Where if they write code, who's reviewing that code?
6:24 Who's checking that?
6:25 For example, when we do a update,
6:27 it gets validated by three separate departments
6:30 before it can be pushed out.
6:31 Oh wow.
6:32 So we have to have those checks and balances cuz
6:34 we have to assume I mean we're obviously a big target.
6:37 We're protecting federal government, international airports,
6:41 uh lots of critical infrastructure.
6:43 So we would be a very very big target.
6:45 Uh so we have to really be vigilant but we
6:48 also have to assume that everybody in the company is compromised.
6:52 Wow.
6:52 And there has to be a check and balance for what they do.
6:55 Okay.
6:55 So you showed me some keystrokes being logged right
6:58 away but you promised me access to a webcam.
7:00 Okay.
7:00 Okay.
7:00 So, let's get access to a webcam.
7:02 So, I'm going to switch out this keyboard.
7:04 Um I think we we're done with this one.
7:06 Um and we're going to plug in.
7:08 Now, do you like when you're traveling around with that stuff,
7:10 do you ever like some of the stuff is compromised?
7:13 Do you have some secret UV symbol on it?
7:15 So, you know what stuff is?
7:16 That's why we're using the black cable, not the white cable.
7:19 Oh, like black hat hacking and white hat.
7:22 So, because the white cables are what we use to charge our phones.
7:24 The black cables are the bad ones.
7:26 However, some of these devices cannot cross into Canada.
7:29 And I was in the Middle East with some of them and I was like,
7:32 "Am I allowed this in this country?" And the guy was like,
7:34 "No, this is not legal here." And I was like, "Anander, you can fly that home."
7:39 Uh, so, uh, I'm going to plug this one in.
7:42 Now, again, I can charge my phone.
7:43 It's a real But you haven't plugged anything into this cable.
7:46 I It's literally just plugged in so I can charge my phone.
7:49 It's now presented as a Wi-Fi for Kira.
7:52 Oh my gosh.
7:54 And in a few moments, he'll be able to connect to it.
7:57 And he
7:58 this looks like the most unthreatening thing in the world
8:00 is a cable not plugged into anything on the other side.
8:04 And yet here it is.
8:05 And what what Kieran's going to do now is literally send
8:08 a payload same way we did before with with the the USB device.
8:13 But now it's just I'm not touching anything just wirelessly.
8:17 What it goes and I can have payloads saved or I can
8:19 type them and make them at any time completely remote.
8:25 Terrifying.
8:25 And this is a really high use in things like hospitals because
8:28 you going to a do an office you can plug something in.
8:31 Hospitals are high targets for ransomware.
8:33 Tons of Bluetooth going on.
8:34 Tons of Bluetooth.
8:36 Computers often left unattended.
8:38 Patients left in rooms.
8:39 You can you leave one of these in there and you can go in two hours later.
8:43 And of course they're more likely to pay
8:45 ransoms because they you're stealing customer data.
8:48 Oh, that's terrible.
8:49 Yes.
8:49 Cuz every computer has access to all of this patient information.
8:53 Yes.
8:53 Oh my gosh.
8:54 So, we see here now, again, we've left it on the screen so you can see it,
8:56 but we can drag it out the way.
8:58 This camera is now recording you
9:00 really.
9:00 And and it's uploading to our Google and there's no light.
9:02 I don't see any indication that it's recording.
9:05 No indication whatsoever.
9:06 And we have here every 10 seconds it'll upload that video to our Google bucket.
9:11 Uh I can download it here.
9:14 Oh, let's watch.
9:16 We're using Google because Google's less likely to trigger
9:18 talking to a ransomware GOING ON.
9:23 ENDED.
9:25 That's absolutely
9:26 I think you're going to be sweeping this place when we leave, dude.
9:30 And we can make it persistent as well,
9:32 just like the other scripts that we have with the screenshotting.
9:34 So, your camera is set up on your computer.
9:36 Yeah.
9:37 You come back, you log in in the morning,
9:40 I just get a full video.
9:41 I can even pair that with the screenshot.
9:43 So, I can get a screenshot of your computer
9:45 every 10 seconds and the video along with it.
9:48 Oh my gosh.
9:49 Um, what do you say to like I you're at a holiday dinner,
9:53 you're talking to your grandmother, you're telling her about what you're doing,
9:55 and she says, "It sounds like the world is a super dangerous place."
9:58 How do you manage like what do you what do you tell her?
10:02 Um, well, at this point, the the question that normally comes up is,
10:06 "Is my data stolen?" So, your data is already gone.
10:09 Don't worry about it.
10:09 Like, just it's already been stolen.
10:11 Everyone knows everyone knows your medical records.
10:14 Everyone knows your credit.
10:15 just lock I just say just lock your credit report and accept
10:18 the fact that everyone knows every time we went to the doctor.
10:21 That's kind of like as an individual because
10:23 the problem is as individuals we rely on businesses.
10:25 I can talk to businesses and I can
10:26 help businesses make sure they don't get destroyed.
10:29 But you go to a car dealership, you buy a car,
10:32 you don't really have any choice as to how they process you and treat your data.
10:35 You go to the hospital,
10:36 you give them your medical records, you don't have any choice.
10:39 So I will say to people, individuals, I'll say just lock your credit report.
10:42 Unlock it when you want to get credit.
10:44 monitor your credit and just accept that every time you've been to the doctor,
10:47 the it's the whole world knows about it.
10:50 Wow.
10:50 Most people put on Facebook now anyway.
10:51 So, and the method you guys bring to your clients
10:55 is a zero trust environment where you're
10:59 always assuming that every ingress into the computer
11:02 is a is a vector for something bad.
11:05 Yeah.
11:05 And just make it harder like in this case,
11:07 why would PowerShell need to reach out to the internet?
11:09 Just don't let PowerShell reach out to the internet.
11:12 And it would and look, it's still taking the pictures, but it can't upload them.
11:15 And that's the difference between, hey, you actually delivered a payload,
11:18 but it's useless, or you delivered a payload,
11:20 and now you've got a video of me scratching my face all day long,
11:23 which is really not that interesting.
11:25 Enjoy that.
11:28 Yeah.
11:27 Now, you said that um that smaller companies were
11:30 being more highly targeted for ransomware than giant organizations.
11:35 Um that seems like a new development over the last few years.
11:38 Yeah, it's it's got I mean it's I think since 2017
11:41 it really exploded and it's just got worse and worse and worse.
11:44 The payments are getting bigger and bigger and bigger and quite often the bigger
11:48 companies are starting to be sophisticated enough
11:51 that they're they're implementing zero trust controls.
11:53 They're putting things on the network so
11:54 it's getting harder and harder to target them.
11:56 Uh smaller companies have this mentality that who would care about my stuff.
12:00 Right.
12:00 Right.
12:00 I'm just a tire repair shop.
12:02 Right.
12:02 But what they don't realize is you care about it.
12:04 So, if they can take your systems offline,
12:06 encrypt your databases, upload your customer data, you're willing to pay.
12:09 And sometimes it's you'll pay me $20,000 and sometimes it'll
12:12 pay pay me half a million dollars or a million dollars,
12:14 whatever they think they can get.
12:15 They'll take your financial information and then use
12:18 that to estimate how much they can steal from you.
12:20 Peg butchering.
12:21 They're just going to get everything.
12:23 So, and that the first things they'll look at when they get in there is
12:25 find the cyber insurance policy and find out
12:27 how much you have in your bank account.
12:29 OH, NO WAY.
12:30 So once they know those two things,
12:31 they can come in and you'll literally see if you see
12:34 the the negotiations with these hackers to get your data back,
12:37 you'll see, oh, we don't have much money.
12:39 And they'll just send back your bank statement and say, yes, you do.
12:44 That's terrible.
12:45 So, and yes, you do.
12:47 We're only asking for 300,000.
12:49 You have a million in your bank.
12:50 And they'll they'll just apply with that.
12:53 It's a whole business.
12:54 It really is.
12:55 They run it just like a business.
12:56 They run it just like a like an actual business.
12:58 Yeah.
12:58 And I think the report I saw yesterday
13:00 was $1.5 trillion dollars the cost of cyber crime.
13:03 It's currently going and it's only rising.
13:06 It's only rising.
13:06 Every year it rises over and over again.
13:09 And these are some of the cool tools,
13:10 but it's again we're just using a computer here.
13:14 My takeaway from this is the frame why would I be interesting
13:19 to a bad actor is one we should all remove from our brains.
13:23 Again, it comes down to one employee,
13:25 one user doing that and then you've got access to this.
13:27 And you only need one to get into the Oh my god, that's terrifying.
13:31 You got 10 employees, you'll probably get three.
13:35 Like, I mean, that's the reality of it, right?
13:37 I mean, we're a cyber security company.
13:38 We do training with our users every single month,
13:40 and our users still fall for those scams.
13:42 Do you do So, you guys do pen testing,
13:45 penetration testing, and fishing for your clients?
13:48 So, we do penetration No, penetration testing on our own infrastructure.
13:51 Gotcha.
13:52 So because we have to it's part of our compliance
13:54 but I feel like it's a waste sometimes because
13:57 we teach we say look you got fished go
13:59 through training and then next month they get fished again.
14:02 So uh so then we just take away all their access so they
14:05 can only access exactly what they need and nothing else and we accept
14:08 and then they're safe and then so you just eliminating choice.
14:14 Yes.
14:14 Remove the human element as much as possible.
14:16 Right.
14:17 And at the end of the day, most people need to come into their office,
14:19 open the browser, go into Zoom, open the finance software.
14:22 They don't need to be able to do all these things.
14:24 They don't need to be able to upload things in PowerShell.
14:26 It's funny.
14:27 I think of my computer, I think of my laptop because I've had one since 1993.
14:31 I think of it like a Swiss Army knife,
14:32 but I realize that's a poor frame to think about it
14:36 in because this every tool that it can use is a vulnerability.
14:41 Absolutely.
14:41 Wow.
14:41 You guys have really reset my head on this.
14:43 Thank you for taking nefarious screenshots and
14:45 you should probably stop recording now.
14:49 Guys, you really reset my head on this.
14:50 Thank you for this terrifying education.
14:53 I really appreciate it.
14:54 Thank you.